Canonical Source Standards Register

CIAO COMMONS — REGISTER
C-AO/REG/SSR/001:2026 PUBLIC
Canonical Source Standards Register
The Authoritative Scope of Normative Reference — Class B Foundational
Date Issued  26 April 2026
Review Date  26 April 2027
Cite as: CIAO Standard. (2026). Canonical Source Standards Register. v1.0. C-AO/REG/SSR/001:2026. www.c-ao.com
🟢 Commons — Public

1. Purpose & Authority

The Canonical Source Standards Register is the authoritative scope of normative reference for the CIAO Standard. It defines which source standards CIAO documents may engage. Amendments to CIAO content may engage only standards in this Register; proposals engaging unregistered standards are escalated as Register Addition Requests under the Change Management & Versioning Process.

The Register is an instrument of foundational governance — Class B in the Constitutional hierarchy declared in Constitution Section 7. Its authority arises from the role it plays: every entry in the Register represents the application of the patented multi-framework mapping methodology to that source standard, producing a normalized cross-mapping against the entire CIAO Standard content. A standard not yet in the Register has not yet been compiled into the CIAO mapping fabric; it cannot serve as a normative reference until that compilation is performed.

Each entry below names a source standard the CIAO Standard cites in its mappings. Each entry carries a short code used in inline references; a family classification used to group standards by tradition; the issuing authority; and the primary CAO content domain into which the standard most closely maps. Where a standard genuinely spans two CAO domains, both are listed.

Members configure their applicable source-standards portfolio at the My Source Standards page (login required). Once configured, the Dynamic Selection Engine filters the Standard’s inline references to the member’s selected portfolio. The Register’s authority over what may be referenced is independent of any individual member’s portfolio configuration; portfolio configuration is presentational, the Register’s authority is normative.

2. The Register

Twenty-six source standards are currently in the Register, organised across seven families. Additions follow the source-standard re-issue trigger pathway in the Change Management & Versioning Process.

ISO 27k  (6)

StandardShort CodeAuthorityPrimary CAO Domain
ISO/IEC 27001:2022ISO27001ISO/IECCAO-400
ISO/IEC 27002:2022ISO27002ISO/IECCAO-400
ISO/IEC 27005:2022ISO27005ISO/IECCAO-200
ISO/IEC 27017:2015ISO27017ISO/IECCAO-400
ISO/IEC 27018:2019ISO27018ISO/IECCAO-400, CAO-300
ISO/IEC 27701:2019ISO27701ISO/IECCAO-300

ISO 9k / 22k / 31k  (4)

StandardShort CodeAuthorityPrimary CAO Domain
ISO 22301:2019ISO22301ISOCAO-500
ISO 31000:2018ISO31000ISOCAO-200
ISO 9001:2015ISO9001ISOCAO-100
ISO/IEC 38500:2024ISO38500ISO/IECCAO-100

NIST  (3)

StandardShort CodeAuthorityPrimary CAO Domain
NIST Cybersecurity Framework v2.0NISTCSFNIST (US)CAO-400
NIST SP 800-37 Rev. 2NISTSP80037NIST (US)CAO-200
NIST SP 800-53 Rev. 5NISTSP80053NIST (US)CAO-400

Privacy & Data Protection  (5)

StandardShort CodeAuthorityPrimary CAO Domain
CCPA / CPRA (California)CCPAState of California, USCAO-300, CAO-800
GDPR (EU 2016/679)GDPREuropean UnionCAO-300, CAO-800
PIPEDA (Canada)PIPEDAGovernment of CanadaCAO-300, CAO-800
POPIA (Act 4 of 2013)POPIARepublic of South AfricaCAO-300, CAO-800
UK GDPR & DPA 2018UKGDPRUnited KingdomCAO-300, CAO-800

Cyber & Sector Regulation  (4)

StandardShort CodeAuthorityPrimary CAO Domain
EU DORA (Regulation 2022/2554)DORAEuropean UnionCAO-400, CAO-500
EU NIS2 Directive (2022/2555)NIS2European UnionCAO-400, CAO-800
PCI DSS v4.0PCIDSSPCI Security Standards CouncilCAO-400
SA Cybercrimes Act (No. 19 of 2020)SACYBERRepublic of South AfricaCAO-400, CAO-800

Risk & Continuity  (2)

StandardShort CodeAuthorityPrimary CAO Domain
COSO ERM Framework (2017)COSOERMCommittee of Sponsoring OrganizationsCAO-200
ISO/IEC 27031:2011ISO27031ISO/IECCAO-500

AI & Emerging  (2)

StandardShort CodeAuthorityPrimary CAO Domain
EU AI Act (2024/1689)EUAIACTEuropean UnionCAO-700, CAO-800
ISO/IEC 42001:2023ISO42001ISO/IECCAO-700

3. Family Coverage

Family Count Notes
ISO 27k6Information security family — ISO 27001 anchor, plus aligned profiles
ISO 9k / 22k / 31k4General-purpose management system standards
NIST3US frameworks where adopted internationally
Privacy & Data Protection5GDPR, POPIA, and adjacent regimes
Cyber & Sector Regulation4DORA, NIS2, sector-specific
Risk & Continuity2BCM and risk-specific
AI & Emerging2ISO 42001 and AI Act

4. Maintenance and Expansion

The Register is maintained by the Secretariat under two pathways set out in the Change Management Process.

Re-issue of an existing entry. When a referenced source standard is itself revised by its issuing body, a Secretariat-initiated proposal is automatically created to assess the impact on every CIAO mapping that references the affected standard. Re-issues are handled at the next minor release with full notification to affected members.

Addition of a new entry — Register Addition Request. Proposals to amend CIAO content with reference to a source standard not yet in the Register are reclassified as Register Addition Requests. Addition follows three sequential steps: (a) the patented multi-framework mapping methodology is applied to the candidate standard to produce its normalized cross-mapping with the entire existing CIAO content; (b) the new entry is added to the Register at the next scheduled release event; (c) existing CIAO documents are progressively re-rendered to incorporate the new mappings across one or more subsequent minor releases. The expansion is eventually-consistent: the new standard enters the Register and operational use upon completion of step (b), with content re-rendering proceeding under the established release cadence rather than triggering an immediate major release. No individual submitter has standing to compel an immediate major release through a Register Addition Request.

Both pathways — re-issue and addition — produce entries in the Release Calendar change pipeline as Material changes. Additions are also recorded in the version history of this Register itself, and the affected-document re-rendering work is tracked across minor release events until the new entry’s mapping coverage is complete across the corpus.

Part of the CIAO Standard architecture — see Standard Architecture & Tier Content Depth for the canonical domain spine and tier-by-tier content ladder.

● LIVE CONTENT  ·  Verified 29 May 2026 at 15:31 UTC  ·  Version 1.0  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026