Releases and Roadmap
We plan the work, we deliver the work, and we show our customers what just got delivered. This page is the live changelog and roadmap for the AppGenie Compliance MCP - the standards, profiles, overlays and frameworks that shape what the service can answer. Every entry is a controlled standard or overlay in the AppGenie compliance estate.
Just shipped
Customer-visible deliveries. Each one is a controlled standard or overlay in the AppGenie compliance estate. Where a delivery is in the customer-distributed RAG bundle, the AppGenie Compliance MCP serves it to AI clients immediately.
COMPLIANCE-PROFILE-IRAP rebuilt from the pinned ASD ISM OSCAL release and broadened to ten evidenced controls
The IRAP profile's ISM control mapping has been rebuilt directly from the pinned Australian Government ISM OSCAL release (v2026.06.18, catalogue SHA-256 recorded) rather than hand-entered control numbers. Nine controls that had been removed from the ISM were retired, incorrect titles were corrected, and the profile was broadened so it now declares and evidences all ten in-scope controls - event log monitoring (ISM-0109, ISM-1228), incident reporting to ASD (ISM-0140), media encryption (ISM-0459), data transfer (ISM-0663), multi-factor authentication (ISM-1173, ISM-1401), privileged access (ISM-1175), privileged and break-glass credential setting (ISM-1685) and vulnerability patching (ISM-1695) - each backed by a customer-safe supporting standard. Every mapping now carries a testable clause anchor that points at the specific section of the evidencing standard, and a weekly automated check keeps the mapping current against new ISM releases.
Customer impact: customers assessing ISM / IRAP alignment now receive an accurate, reproducible control mapping with clause-level evidence pointers in place of the previous over-broad list. Mapped and aligned - explicitly NOT an IRAP assessment or certification.
OAuth 2.1 metadata now discoverable relative to the /mcp endpoint
MCP clients that resolve OAuth authorization metadata relative to the connection endpoint (for example /mcp/.well-known/oauth-protected-resource) now receive it, in addition to the existing host-root location - following the RFC 9728 / RFC 8414 path-aware discovery pattern. Claude, Claude Code, ChatGPT and other MCP clients can complete the sign-in handshake without manual configuration.
Customer impact: fewer failed first connections - clients that look for auth metadata under the /mcp path can now discover it and start the OAuth flow automatically.
EU Digital Operational Resilience Act (Regulation 2022/2554) - articles mapped to AppGenie standards
New signed-off compliance profile - COMPLIANCE-PROFILE-DORA v1.0.0 - mapping DORA's ICT risk management, incident classification and reporting, digital operational-resilience testing, ICT third-party risk and critical-provider oversight obligations (Articles 5 through 45) to the underlying AppGenie standards, cross-referenced to ISO/IEC 27001:2022. Backed by a dedicated STD-DORA-* standards set: ICT risk-management framework, ICT risk protection controls, ICT change management, continuity/backup/recovery, incident classification and reporting, and critical ICT third-party oversight. Available as a DORA single-pack.
Customer impact: financial-sector customers assessing DORA readiness can query per-article alignment with cited AppGenie standards. Mapped and aligned - explicitly NOT a regulatory assessment or certification.
Foundational control standards opened to customers, new AI-governance and privacy controls, and a rebuilt RAG bundle
Nineteen foundational control standards are now customer-visible - Access Control, Encryption, Security and Solution Architecture, Third-Party Security, Internal Audit, Incident Response, Privileged Access, Endpoint, Backup/Restore, Disaster Recovery, Operational Security Monitoring and the AI-governance set - with operational specifics held back in internal-only sections. New customer-facing standards ship alongside: STD-ENTERPRISE-PRIVACY-MANAGEMENT (the privacy management programme / PIMS, backed by a Record of Processing Activities), STD-ENTERPRISE-ACCEPTABLE-USE (including AI/LLM tool use and inclusive-communication obligations), STD-DELIVERY-DEPLOYMENT-STRATEGY and STD-AI-MONITORING. AI governance gains real accountability: an LLM usage register where every system declares its AI status (positive or negative) and a production-admission gate - no system reaches production without a recorded declaration and sign-off.
Customer impact: customers performing security due diligence can now read the control standards behind the framework mappings, not just the mappings. The estate also passed an end-to-end reference-integrity normalisation and a new binding classification-coherence gate - a customer-facing document can never depend on an internal one - and the customer RAG bundle has been rebuilt and republished, so the AppGenie Compliance MCP serves all of the above immediately.
AICPA SOC 2 Trust Services Criteria - per-criterion self-assessed alignment for the AppGenie SaaS scope
Closed the SOC 2 coverage gap - the dominant US/international SaaS commercial assurance framework. STD-ENTERPRISE-SOC-2-OVERLAY v1.0.0 maps Common Criteria CC1-CC9, Availability A1, Confidentiality C1, Processing Integrity PI1 and Privacy P1-P8 to the underlying AppGenie standards. Common Criteria + Availability + Confidentiality at Substantial tier; Processing Integrity and Privacy explicitly Initial pending point-of-focus mapping and privacy-management completion. Paired customer profile ships with it.
Customer impact: customers asking "where is AppGenie on SOC 2?" now get a per-criterion alignment position with honest scope qualifiers. AppGenie is explicitly NOT SOC 2 audited - CPA-firm attestation is a separate commercial decision. SOC 2 produces a report, not a certificate; "SOC 2 certified" language is incorrect.
ISO/IEC 20000-1:2018 lifted from Initial to Substantial coverage
Added ISO/IEC 20000-1:2018 primary mappings across the services-management estate (incident, problem, SLA/SLO, support model, availability, disaster recovery, monitoring, capacity, change, supplier, performance, configuration, backup, knowledge base, runbook), delivery (change management, release packaging) and enterprise (risk register, risk treatment, internal audit, CAPA). Coverage moves from Initial to Substantial across the in-scope ISO 20000 subset. Paired customer profile ships with it.
Customer impact: the ISO 20000-curious customer no longer sees the weakest single position in the coverage statement. The AppGenie Service Management System is aligned to ISO 20000-1:2018 at Substantial tier. Aligned, NOT certified - certification is a separate commercial decision.
Single managed view of AppGenie's framework coverage portfolio
New customer-facing dashboard - STD-ENTERPRISE-FRAMEWORK-COVERAGE-DASHBOARD v1.0.0 - that consolidates every framework AppGenie has scoped: where we sit today (Comprehensive / Substantial / Targeted / Initial), what's on the roadmap, and what's explicitly Out of Current Scope. Each tier value reports both AppGenie's scoped coverage and the honest position against the full published framework.
Customer impact: a single page answers "where is AppGenie on framework X?" in customer due-diligence conversations. Distributed via the MCP RAG bundle alongside the RACI and the substantive coverage statement.
ACSC Essential Eight - per-strategy self-assessed maturity across the group
Closed the Essential Eight gap that customers ask about first. STD-ENTERPRISE-ESSENTIAL-EIGHT-OVERLAY v1.0.0 maps all 8 strategies (E8.1 application control through E8.8 regular backups) to AppGenie group standards and engineering controls with self-assessed maturity per scope.
Customer impact: customers asking the Essential Eight question first now get a per-strategy self-assessed maturity position with honest scope qualifiers, instead of being referred to ISM alignment as the proximal answer. AppGenie is explicitly NOT ACSC-assessed - a formal assessment is a separate commercial decision.
Per-publication alignment to cyber.gov.au guidance catalogue
Customer-facing register - REG-ACSC-PUBLICATION-ALIGNMENT v1.0.0 - enumerating every ACSC publication relevant to the AppGenie group with a tier value: ISM Comprehensive against curated scope, SBOM Shared Vision Comprehensive, Cyber Security Incident Response Substantial, and so on.
Customer impact: answers the question "how does AppGenie align to cyber.gov.au?" with a per-publication position rather than a generic ISM reference.
STD-DELIVERY-SBOM - three-role model + NTIA minimum elements + VEX/CSAF + EOL/EOS tracking
Software Bill of Materials standard updated in full from the "Shared Vision of Software Bill of Materials for Cybersecurity" co-authored by CISA, ASD's ACSC, NSA and 16 other national cyber security agencies (2025). AppGenie operates in three SBOM roles - Producer (when AppGenie builds), Chooser (when AppGenie procures third-party software), Operator (when AppGenie runs deployed software in production). VEX statements are companion to SBOMs; end-of-life and end-of-support components are tracked in life.
Customer impact: customers can request the SBOM for any AppGenie-produced artefact they have deployed. AppGenie consumes supplier SBOMs at procurement and runs continuous SBOM-vs-vulnerability monitoring on every in-life service.
Customer-facing coverage statement with honest tiers and explicit out-of-scope rationale
STD-ENTERPRISE-COMPLIANCE-COVERAGE-STATEMENT v1.0.0 - the substantive per-framework coverage statement underpinning the dashboard. Reports coverage against ISO 27001 (Comprehensive), NIST SP 800-53 Rev 5 (Comprehensive against scope), FedRAMP (Comprehensive against scope - not authorised), IRAP/ISM (Comprehensive against scope - not assessed), ISO 9001 (Substantial), ISO 20000 (Substantial), ISO 42001 (Targeted), NIST AI RMF (Substantial). Plus the explicit set of frameworks not yet addressed.
Customer impact: the substantive answer to vendor due-diligence. Honest about what AppGenie covers and what it does not.
Estate-wide RACI framework + customer-facing role lookup
STD-ENTERPRISE-RACI v1.0.0 defines the four postures (R, A, C, I), the rules ("one A per activity", "at least one R per activity"), and the canonical role set across the AppGenie standards estate. Paired with a role-to-standards lookup that takes a role and returns every AppGenie standard that names it. RACI tables added to the priority standards on the same day.
Customer impact: customers asking "who does what under standard X" get a structured RACI table answer for the priority set.
Bilateral co-sign + staged-acceptance handover model
STD-ENTERPRISE-SERVICE-OWNERSHIP names a single accountable individual for a service from production cutover through decommission. Bilateral co-sign at the handover gate (Delivery Owner declares completeness; Service Owner accepts and authorises go-live). Tier 3 initiatives use the staged-acceptance overlay (provisional then final). The Service Owner role is threaded through the standards estate.
Customer impact: every in-life AppGenie service has a named accountable individual visible in the service catalog. Customer escalations route to a known role.
Single authoritative system of record for delivery commitments
STD-DELIVERY-BACKLOG-GOVERNANCE establishes a single authoritative system of record for backlog content across the AppGenie product lines, with rationalisation rules (dedup, scope, sizing, ownership), cross-entity reconciliation, and enforcement gates at sprint planning, change advisory and release commitment. The hygiene cadence is documented.
Customer impact: AppGenie cannot run shadow backlogs. Every commitment traces to a controlled item visible to governance, prioritisation and audit.
In progress
Coverage work actively under way. Priority and sequencing are subject to commercial demand.
Walking every "Not Yet Audited" publication on the ACSC alignment register
For each ACSC publication currently marked "Not Yet Audited", we read the publication, map its substantive requirements to AppGenie group standards (or record it as a coverage gap), and update the register tier accordingly. Operational-technology and edge-device publications are prioritised given the Aeon Edge product positioning.
Framework coverage wave - delivered
The framework overlays and profiles previously listed on this roadmap have all shipped. Each is now an Approved, controlled standard or profile in the AppGenie compliance estate, effective 2026-06-03 (ACSC system hardening followed on 2026-07-17). All are self-assessed alignment positions - not certifications.
STD-ENTERPRISE-NIST-CSF-2-0-OVERLAY - outcomes-oriented framework above NIST 800-53
CSF 2.0 maps AppGenie controls to the GOVERN / IDENTIFY / PROTECT / DETECT / RESPOND / RECOVER function, category and subcategory codes, anchored on the Comprehensive coverage of the curated NIST 800-53 subset. All 22 categories are recorded at Substantial, and a customer-facing profile-nist-csf-2-0 packages it.
Customer impact: customers aligning to CSF 2.0 receive a function / category / subcategory mapping directly from the MCP. Self-assessed alignment - CSF has no certification scheme.
STD-ENTERPRISE-NIST-AI-RMF-OVERLAY - MEASURE and MANAGE completed
GOVERN and MAP were already Substantial; the MEASURE function (metrics, tracking, KPIs) and MANAGE function (continuous monitoring, response) are now mapped as primary evidence, taking all 19 in-scope subcategories to Substantial across the full framework. Packaged as profile-nist-ai-rmf.
Customer impact: AI risk-management alignment is now complete across all four NIST AI RMF functions. Self-assessed - there is no NIST AI RMF certification or conformance scheme.
STD-ENTERPRISE-EU-AI-ACT-OVERLAY - Articles 9-15 for high-risk AI systems
Maps AppGenie standards to risk management (Art. 9), data governance (Art. 10), transparency (Art. 13), human oversight (Art. 14) and accuracy / robustness / cybersecurity (Art. 15), building on the ISO 42001 coverage. The Article 27 fundamental-rights impact assessment is explicitly recorded as Initial. Packaged as profile-eu-ai-act.
Customer impact: high-risk AI system obligations are mapped to vendor-side evidence. Self-assessed alignment - NOT a conformity assessment under Article 43, and no CE marking is held.
ISO-27701 lead, plus GDPR, UK-GDPR, AU-PRIVACY-ACT and US-STATE-PRIVACY overlays
ISO 27701 PIMS leads as the privacy extension to the existing ISO 27001 alignment; the GDPR Articles, the Australian Privacy Act (13 APPs), UK GDPR (DPA 2018) and a US state-privacy common-denominator overlay round out multi-jurisdictional coverage. All Approved, each with its own customer-facing profile.
Customer impact: customers with multi-jurisdictional privacy obligations can consume vendor-side alignment across five regimes. Self-assessed - none of these regimes has a certification scheme that AppGenie holds.
STRATEGIES-TO-MITIGATE, MODERN-DEFENSIBLE-ARCHITECTURE, CLOUD-COMPUTING and SYSTEM-HARDENING overlays
Strategies to Mitigate extends the Essential Eight to the wider 37; Modern Defensible Architecture maps to the security and solution architecture standards; Cloud Computing cross-references the existing ISO A.5.23 alignment; and System Hardening (shipped 2026-07-17) covers endpoint and platform hardening. All Approved.
Customer impact: customers following ACSC guidance receive vendor-side mappings across the four publications. Self-assessed - the ACSC does not operate a certification scheme.
COMPLIANCE-PROFILE-ESSENTIAL-EIGHT, COMPLIANCE-PROFILE-ISO-42001 and COMPLIANCE-PROFILE-ISO-27002
Packaged, customer-facing profiles for frameworks where AppGenie had coverage but no standalone profile: Essential Eight (overlay plus profile), ISO 42001 as a standalone profile (previously composite under the AI-controlled profile), and ISO 27002 explicit (previously contributory under ISO 27001).
Customer impact: these frameworks are now first-class subscription profiles served by the MCP rather than implicit coverage.
Planned next
The published framework-coverage roadmap is now delivered. Further coverage is prioritised by commercial demand - customers may influence the sequence by engaging AppGenie commercially. Named residual items (for example the EU AI Act Article 27 fundamental-rights impact assessment, currently Initial) are tracked in the compliance backlog and surfaced here as they ship.
How this page works
Every entry on this page traces back to a controlled artefact in the AppGenie compliance estate. Shipped items reference the standard or overlay by document ID (STD-* or REG-*) where one is published. This page is updated as part of each compliance release and reviewed at the same quarterly cadence as the dashboard.
Want the AI Compliance MCP to answer in real time? Connect Claude, Claude Code, ChatGPT or any MCP-compatible client to compliance.appgenie.com.au and ask the questions directly. See documentation for connection steps.