Canonical Source Standards Register

CIAO COMMONS — REGISTER
C-AO/REG/SSR/001:2026 PUBLIC
Canonical Source Standards Register
The Authoritative Scope of Normative Reference — Class B Foundational
Date Issued  26 April 2026
Review Date  26 April 2027
Cite as: CIAO Standard. (2026). Canonical Source Standards Register. v1.0. C-AO/REG/SSR/001:2026. www.c-ao.com
🟢 Commons — Public

1. Purpose & Authority

Source-text discipline. This Register lists the source standards the CIAO Standard recognises and maps to; it does not host, reproduce, or distribute the text of any listed standard. All CIAO mappings are expressed as clause references only — members consult their own authorised copies of each source standard for the clause text. CIAO provides the architectural layer above these standards, harmonising their requirements through clause-reference-only mappings, never a substitute for the standards themselves.

The Canonical Source Standards Register is the authoritative scope of normative reference for the CIAO Standard. It defines which source standards CIAO documents may engage. Amendments to CIAO content may engage only standards in this Register; proposals engaging unregistered standards are escalated as Register Addition Requests under the Change Management & Versioning Process.

The Register is an instrument of foundational governance — Class B in the Constitutional hierarchy declared in Constitution Section 7. Its authority arises from the role it plays: every entry in the Register represents the application of the patented multi-framework mapping methodology to that source standard, producing a normalized cross-mapping against the entire CIAO Standard content. A standard not yet in the Register has not yet been compiled into the CIAO mapping fabric; it cannot serve as a normative reference until that compilation is performed.

Each entry below names a source standard the CIAO Standard cites in its mappings. Each entry carries a short code used in inline references; a family classification used to group standards by tradition; the issuing authority; and the primary CAO content domain into which the standard most closely maps. Where a standard genuinely spans two CAO domains, both are listed.

Members configure their applicable source-standards portfolio at the My Source Standards page (login required). Once configured, the Dynamic Selection Engine filters the Standard’s inline references to the member’s selected portfolio. The Register’s authority over what may be referenced is independent of any individual member’s portfolio configuration; portfolio configuration is presentational, the Register’s authority is normative.

2. The Register

Thirty-four source standards are currently in the Register, organised across nine families. Additions follow the source-standard re-issue trigger pathway in the Change Management & Versioning Process.

ISO 27k  (6)

StandardShort CodeAuthorityPrimary CAO Domain
ISO/IEC 27001:2022ISO27001ISO/IECCAO-400
ISO/IEC 27002:2022ISO27002ISO/IECCAO-400
ISO/IEC 27005:2022ISO27005ISO/IECCAO-200
ISO/IEC 27017:2015ISO27017ISO/IECCAO-400
ISO/IEC 27018:2019ISO27018ISO/IECCAO-400, CAO-300
ISO/IEC 27701:2019ISO27701ISO/IECCAO-300

ISO 9k / 22k / 31k  (4)

StandardShort CodeAuthorityPrimary CAO Domain
ISO 22301:2019ISO22301ISOCAO-500
ISO 31000:2018ISO31000ISOCAO-200
ISO 9001:2015ISO9001ISOCAO-100
ISO/IEC 38500:2024ISO38500ISO/IECCAO-100

NIST  (3)

StandardShort CodeAuthorityPrimary CAO Domain
NIST Cybersecurity Framework v2.0NISTCSFNIST (US)CAO-400
NIST SP 800-37 Rev. 2NISTSP80037NIST (US)CAO-200
NIST SP 800-53 Rev. 5NISTSP80053NIST (US)CAO-400

Privacy & Data Protection  (5)

StandardShort CodeAuthorityPrimary CAO Domain
CCPA / CPRA (California)CCPAState of California, USCAO-300, CAO-800
GDPR (EU 2016/679)GDPREuropean UnionCAO-300, CAO-800
PIPEDA (Canada)PIPEDAGovernment of CanadaCAO-300, CAO-800
POPIA (Act 4 of 2013)POPIARepublic of South AfricaCAO-300, CAO-800
UK GDPR & DPA 2018UKGDPRUnited KingdomCAO-300, CAO-800

Cyber & Sector Regulation  (4)

StandardShort CodeAuthorityPrimary CAO Domain
EU DORA (Regulation 2022/2554)DORAEuropean UnionCAO-400, CAO-500
EU NIS2 Directive (2022/2555)NIS2European UnionCAO-400, CAO-800
PCI DSS v4.0PCIDSSPCI Security Standards CouncilCAO-400
SA Cybercrimes Act (No. 19 of 2020)SACYBERRepublic of South AfricaCAO-400, CAO-800

Risk & Continuity  (2)

StandardShort CodeAuthorityPrimary CAO Domain
COSO ERM Framework (2017)COSOERMCommittee of Sponsoring OrganizationsCAO-200
ISO/IEC 27031:2011ISO27031ISO/IECCAO-500

AI & Emerging  (2)

StandardShort CodeAuthorityPrimary CAO Domain
EU AI Act (2024/1689)EUAIACTEuropean UnionCAO-700, CAO-800
ISO/IEC 42001:2023ISO42001ISO/IECCAO-700

International Auditing Standard Methodologies  (4)

StandardShort CodeAuthorityPrimary CAO Domain
ISAE 3402 Type IISAE3402T1IAASBCAO-200
ISAE 3402 Type IIISAE3402T2IAASBCAO-200
SOC 2 Type ISOC2T1AICPACAO-200
SOC 2 Type IISOC2T2AICPACAO-200

Respective Corporate Governance Codes  (4)

StandardShort CodeAuthorityPrimary CAO Domain
G20/OECD Principles of Corporate GovernanceG20OECDOECDCAO-100
King VKINGVIoDSACAO-100
SOX (Sarbanes-Oxley Act)SOXUS SECCAO-100
UK Corporate Governance CodeUKCGCFRC (UK)CAO-100

3. Family Coverage

Family Count Notes
ISO 27k6Information security family — ISO 27001 anchor, plus aligned profiles
ISO 9k / 22k / 31k4General-purpose management system standards
NIST3US frameworks where adopted internationally
Privacy & Data Protection5GDPR, POPIA, and adjacent regimes
Cyber & Sector Regulation4DORA, NIS2, sector-specific
Risk & Continuity2BCM and risk-specific
AI & Emerging2ISO 42001 and AI Act
International Auditing Standard Methodologies4International assurance and audit-report methodologies (ISAE 3402, SOC 2)
Respective Corporate Governance Codes4Corporate governance codes (King V, G20/OECD, UK Corporate Governance Code, SOX)

4. Maintenance, Expansion & Retirement

The Register is kept current under the Standards Upkeep Process, which governs the full lifecycle of every entry — monitoring for revision, onboarding of new standards, version transitions, and retirement of superseded standards. In summary: a referenced standard revised by its issuing body is handled as a source-standard re-issue; a proposal engaging a standard not yet in the Register is a Register Addition Request; and a withdrawn or superseded standard is retired with its mappings reattributed, archived, or routed for editorial resolution. Each pathway is executed through the Change Management & Versioning Process and produces entries in the Release Calendar pipeline as Material changes. Register expansion is additive — adding an entry never affects a member’s existing mappings against previously-registered standards.

Part of the CIAO Standard architecture — see Standard Architecture & Tier Content Depth for the canonical domain spine and tier-by-tier content ladder.

● LIVE CONTENT  ·  Verified 21 June 2026 at 12:30 UTC  ·  Version 1.0  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026