{
  "schema": "compliance-crosswalk/v1",
  "tool": "complymap",
  "frameworks": [
    {
      "id": "DORA",
      "name": "Digital Operational Resilience Act (Reg. 2022/2554)",
      "controls": [
        { "ref": "Art. 6",  "name": "ICT risk-management framework",     "how": "gap subcommand renders a control-by-control coverage matrix for the ICT-RMF baseline.", "coverage": "evidences" },
        { "ref": "Art. 8",  "name": "Identification of ICT-supported functions", "how": "Reads jfind/v1 findings tagged with asset+function scope; cross-references function inventory.", "coverage": "supports" },
        { "ref": "Art. 18", "name": "Classification & reporting of major ICT-related incidents", "how": "delta subcommand shows which incident-classification controls are DORA-only vs shared with NIS2.", "coverage": "evidences" },
        { "ref": "Art. 24", "name": "Advanced testing (TLPT)",           "how": "Consumes tiberscope scope + plan; treats them as evidence of Art.24 §3 scoping documentation.", "coverage": "supports" }
      ]
    },
    {
      "id": "NIS2",
      "name": "NIS2 Directive (Dir. 2022/2555)",
      "controls": [
        { "ref": "Art. 21 §2(a)", "name": "Policies on risk analysis + information system security", "how": "Gap matrix aligns risk-analysis controls across DORA / NIS2 / ISO 27001.", "coverage": "evidences" },
        { "ref": "Art. 23",       "name": "Reporting obligations",                                   "how": "Cross-walks with DORA Art. 17–19 incident classification.", "coverage": "supports" }
      ]
    },
    {
      "id": "ISO27001",
      "name": "ISO/IEC 27001:2022",
      "controls": [
        { "ref": "A.5.7",  "name": "Threat intelligence",                     "how": "Crosswalk of ISO 27001 A.5.7 to DORA Art. 13 threat-led testing.", "coverage": "supports" },
        { "ref": "A.5.24", "name": "Information security incident management planning", "how": "delta subcommand highlights ISO A.5.24–A.5.30 mapping to DORA Art. 17.", "coverage": "evidences" }
      ]
    }
  ]
}
