Compliance as code, mapped by regulatory framework.

OPA/Rego policies aggregated from multiple permissively-licensed sources, deduplicated, validated on the real OPA engine, then mapped by framework (CIS, NIST, ISO 27001, SOC 2, PCI-DSS, NIS2, DORA, EU AI Act). You don’t start from 2,590 loose rules: you load the bundle for the framework you have to prove.

2 590+
OPA-validated policies
16
frameworks mapped
18
IaC platforms
Ed25519
signed, engine-tested

31 bundles, one framework at a time.

EU compliance

~555 policies relevant to EU obligations. NIS2 and DORA coverage is derived from your ISO 27001 / NIST / CIS controls via a regulatory crosswalk (ENISA table, CC BY 4.0, shipped in the pack), traced audit evidence, not a certification. Direct and derived stay distinguished.

Financial services

Operational resilience and payment in one feed: DORA, PCI-DSS and SOC 2. For banks, insurers, fintechs and their providers.

PCI-DSS

The PCI-DSS-mapped policies to prove compliance of your payment environments, encryption, segmentation, logging, access.

CIS Benchmarks

The broadest coverage in the pack: CIS controls for AWS, Azure, GCP, Kubernetes and Docker. The most-requested hardening baseline.

Terraform

Every policy targeting Terraform IaC, run in CI/CD before apply, to block a bad config before it reaches the cloud.

Kubernetes

Kubernetes admission and configuration policies, plug into Gatekeeper/Conftest to reject a non-compliant manifest at admission.

Policies aggregated from several permissively-licensed open-source repos (Apache-2.0), deduplicated by content, validated on the real OPA engine (opa check, per Rego dialect) then indexed by framework and platform in mapping.json. Source provenance (commits) retained for license traceability.

See the full coverage

Curation + mapping, not raw material.

01
Multi-source, deduplicated

Several permissively-licensed open-source repos (Apache-2.0) aggregated, deduplicated by content, one coherent library, not overlapping lists.

02
Validated on real OPA

Every delivery passes `opa check` on the engine, policies that don’t compile are removed.

03
Mapped by regulatory framework

Every policy indexed by framework (CIS, NIST, ISO 27001, SOC 2, PCI-DSS, NIS2, DORA, EU AI Act) in mapping.json. The mapping that exists nowhere for free, the real moat.

04
Bundles by framework & platform

29 ready-to-load bundles: by framework to prove and by IaC platform (Terraform, Kubernetes, CloudFormation, Ansible).

05
Ed25519-signed

The feed is signed; you verify its integrity before every run.

06
Apache-2.0 licenses traced

Permissive sources only (Apache-2.0), provenance and attribution retained. The compilation and mapping remain ThreatClaw’s proprietary value.

How do I use it?

The pack ships a `policies/` folder (the curated set), a `bundles/` folder (by framework and platform) and a `mapping.json`. Load them with OPA or Conftest, in CI/CD before `terraform apply`, at Kubernetes admission (Gatekeeper), or in your pipelines. Each bundle is the policy list for one framework.

How do you cover NIS2 and DORA?

NIS2 and DORA don’t define low-level technical controls, they point to ISO 27001 and NIST. The pack applies a regulatory crosswalk, based on ENISA’s mapping table (CC BY 4.0, shipped in the pack) and NIST OLIR references, that derives a policy’s NIS2/DORA relevance from the ISO 27001 / NIST / CIS controls it already implements. Result: ~555 policies relevant to EU obligations, instead of a handful mapped explicitly. These derived mappings are clearly labelled, kept separate from direct mappings, each with the provenance of its derivation: it’s audit evidence, not a certification.

Why pay, when OPA and the policies are free?

You’re not paying for the policies, you’re paying to not have to aggregate, dedupe, test and above all map 2,590 rules to 16 frameworks. The compliance mapping (mapping.json), re-tested on every delivery, exists nowhere for free: it turns a pile of Rego into per-framework proof, ready for an audit.

What licenses, and can I resell / MSSP?

Permissive (Apache-2.0) sources only. The policies remain under Apache-2.0: redistributable with attribution (provenance and licenses are retained in the pack). The compilation, the compliance mapping (mapping.json) and the bundles, however, are ThreatClaw’s proprietary value. For MSSP use or reselling the mapping, let’s talk.

Ready to prove your compliance?

Annual subscription. Instant key. Cancel anytime.

€349 / month, billed annually €4,188 excl. tax
Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.