Compliance as code, mapped by regulatory framework.
OPA/Rego policies aggregated from multiple permissively-licensed sources, deduplicated, validated on the real OPA engine, then mapped by framework (CIS, NIST, ISO 27001, SOC 2, PCI-DSS, NIS2, DORA, EU AI Act). You don’t start from 2,590 loose rules: you load the bundle for the framework you have to prove.
31 bundles, one framework at a time.
~555 policies relevant to EU obligations. NIS2 and DORA coverage is derived from your ISO 27001 / NIST / CIS controls via a regulatory crosswalk (ENISA table, CC BY 4.0, shipped in the pack), traced audit evidence, not a certification. Direct and derived stay distinguished.
Operational resilience and payment in one feed: DORA, PCI-DSS and SOC 2. For banks, insurers, fintechs and their providers.
The PCI-DSS-mapped policies to prove compliance of your payment environments, encryption, segmentation, logging, access.
The broadest coverage in the pack: CIS controls for AWS, Azure, GCP, Kubernetes and Docker. The most-requested hardening baseline.
Every policy targeting Terraform IaC, run in CI/CD before apply, to block a bad config before it reaches the cloud.
Kubernetes admission and configuration policies, plug into Gatekeeper/Conftest to reject a non-compliant manifest at admission.
Policies aggregated from several permissively-licensed open-source repos (Apache-2.0), deduplicated by content, validated on the real OPA engine (opa check, per Rego dialect) then indexed by framework and platform in mapping.json. Source provenance (commits) retained for license traceability.
Curation + mapping, not raw material.
Several permissively-licensed open-source repos (Apache-2.0) aggregated, deduplicated by content, one coherent library, not overlapping lists.
Every delivery passes `opa check` on the engine, policies that don’t compile are removed.
Every policy indexed by framework (CIS, NIST, ISO 27001, SOC 2, PCI-DSS, NIS2, DORA, EU AI Act) in mapping.json. The mapping that exists nowhere for free, the real moat.
29 ready-to-load bundles: by framework to prove and by IaC platform (Terraform, Kubernetes, CloudFormation, Ansible).
The feed is signed; you verify its integrity before every run.
Permissive sources only (Apache-2.0), provenance and attribution retained. The compilation and mapping remain ThreatClaw’s proprietary value.
How do I use it?
The pack ships a `policies/` folder (the curated set), a `bundles/` folder (by framework and platform) and a `mapping.json`. Load them with OPA or Conftest, in CI/CD before `terraform apply`, at Kubernetes admission (Gatekeeper), or in your pipelines. Each bundle is the policy list for one framework.
How do you cover NIS2 and DORA?
NIS2 and DORA don’t define low-level technical controls, they point to ISO 27001 and NIST. The pack applies a regulatory crosswalk, based on ENISA’s mapping table (CC BY 4.0, shipped in the pack) and NIST OLIR references, that derives a policy’s NIS2/DORA relevance from the ISO 27001 / NIST / CIS controls it already implements. Result: ~555 policies relevant to EU obligations, instead of a handful mapped explicitly. These derived mappings are clearly labelled, kept separate from direct mappings, each with the provenance of its derivation: it’s audit evidence, not a certification.
Why pay, when OPA and the policies are free?
You’re not paying for the policies, you’re paying to not have to aggregate, dedupe, test and above all map 2,590 rules to 16 frameworks. The compliance mapping (mapping.json), re-tested on every delivery, exists nowhere for free: it turns a pile of Rego into per-framework proof, ready for an audit.
What licenses, and can I resell / MSSP?
Permissive (Apache-2.0) sources only. The policies remain under Apache-2.0: redistributable with attribution (provenance and licenses are retained in the pack). The compilation, the compliance mapping (mapping.json) and the bundles, however, are ThreatClaw’s proprietary value. For MSSP use or reselling the mapping, let’s talk.
Ready to prove your compliance?
Annual subscription. Instant key. Cancel anytime.