
The Global Governance Framework
GGF — Comply Once. Report Everywhere.
One control spine above six regimes — NERC CIP, IEC 62443, NIS2, the EU CRA, the EU AI Act, and NERC O&P. One inventory with six classifications. One control library with six crosswalks. One incident record that computes every notification obligation at once.
Built like NERC CIP: requirement language, measures, and evidence — not aspirational outcomes. Structured like the CSF. Scoped like nothing currently published.
LAYER 0 · THE REGIME DATA LAYER
Six regimes, one schema
Each regime is a data object — unit of governance, control corpus, reporting rule, inventory model, spotlight discipline. Adding a seventh regime is a data operation, not a redesign.
NERC CIP
Per Site- Controls
- 12 core cyber standards, CIP-002→013 (+ CIP-014 physical, CIP-015 INSM)
- Reports To
- E-ISAC + CISA within 1 hour of determination (CIP-008 R4)
- Inventory
- BES Cyber Systems — High / Medium / Low impact
- Spotlight
- Impact-rated inventory & RSAW evidence culture
IEC 62443
Per System / Product- Controls
- Parts 2-1 → 4-2 plus foundational requirements FR1–FR7
- Reports To
- Clock-silent — contractual only; incidents route via the statutory regimes
- Inventory
- Zones & Conduits — Security Levels SL 1–4
- Spotlight
- Secure Development Lifecycle (62443-4-1)
NIS2
Per Entity- Controls
- Article 21(2)(a–j) measures + Art 20 governance
- Reports To
- CSIRT — 24 h → 72 h → 1 month (Art 23)
- Inventory
- Essential / Important entities by Annex I–II sector
- Spotlight
- Governance & accountability — management liability
EU CRA
Per Device- Controls
- Annex I Part I essential requirements + Part II vulnerability handling
- Reports To
- ENISA/CSIRT — 24 h → 72 h → 14 days (exploited vuln; 1 mo severe incident)
- Inventory
- Products by criticality class — default / Class I / Class II / critical
- Spotlight
- SBOM & CE conformity
EU AI Act
Per Model- Controls
- Art 5 → 72, risk classification, Annex IV docs, EU-database registration
- Reports To
- Market surveillance — ≤ 15 d · 10 d death · 2 d critical-infra disruption (Art 73)
- Inventory
- AI systems by risk class — prohibited / high / limited / minimal + GPAI
- Spotlight
- Conformity & registration
NERC O&P
Per Registered Entity- Controls
- BAL · FAC · PRC · TOP · IRO · VAR · MOD · EOP · PER · COM
- Reports To
- EOP-004 within 24 h + DOE OE-417 (1 h / 6 h emergency lines)
- Inventory
- Facilities & Protection Systems by maintenance status (PRC-005)
- Spotlight
- Maintenance & event reporting
ARCHITECTURE
Five layers deep · eight functions across · four tiers up
Functions
8 top-level outcomes — the CSF six plus two TENET functions
Categories
34 categories, coded XX.YY
Controls
CIP-style “shall” requirements with sub-parts
Crosswalk
Per-control mapping into all six regimes
Evidence & Measures
RSAW-style measures and acceptable evidence
Every control carries four cross-cutting attributes: Owner / Approver · Timeline / Cadence · Applicability(site · system · entity · device · model · registered entity) · Reporting trigger.
L1–L2 · THE FUNCTION MODEL
Eight functions, thirty-four categories
The CSF six — rebuilt with enforceable clocks — plus the two functions that make the GGF worth publishing: Supply Chain & Product Integrity and Regulatory Reporting & Conformity.
GVGovernCSF Analog
One accountable executive, approved policy, competent people, a liable board.
Approved policies across every function, AGO re-approval every 15 calendar months.
Named Accountable Governance Officer; written delegations; Owner/Approver on every control.
One methodology producing every regime’s classifier from a single assessment event.
Role-based training before access; 15-month refresh; AI-literacy coverage.
Management body approves measures, receives quarterly metrics, trained on personal liability.
IDIdentifyCSF Analog
One register. Every unit. Six classifications. Fifteen-month truth.
One canonical register, all six unit types, each with a unique portable identifier — the [T] ID lives here.
One classification event, six outputs: H/M/L · SL-target · E/I · criticality class · AI risk class · maintenance criticality.
15-calendar-month review; 30-day re-check on triggering change; discrepancies to zero or formally risk-accepted.
Zones/conduits, perimeters, external connectivity, model data-flow maps.
PRProtectCSF Analog
Least privilege, hardened systems, controlled change, protected information.
Need-based authorization; quarterly verification; 24-hour revocation; MFA for interactive remote access.
Needed ports only; 35-day patch evaluation; malware protections.
BCSI-analog identification and protection; training-data governance for models.
Authorized baselines; 35-day deviation disposition; substantial modification triggers re-classification and re-conformity.
Zone/perimeter enforcement; documented permissions; vendor remote access individually terminable.
DEDetectCSF Analog
Log it, watch it, find the weakness before the adversary or the auditor does.
Event logging; 90-day retention; 15-day review cycle; INSM for high-impact zones.
15-month assessments; coordinated-disclosure intake; CRA-grade product vulnerability handling.
Maintenance status, model drift, field telemetry — degradation dispositioned.
E-ISAC / CISA / ENISA / PSIRT intake triaged against the register within SLA.
RSRespondCSF Analog
One plan, one clock, tested muscle.
One IR plan spanning all six regimes’ incident definitions, with per-regime reportability criteria.
Determine reportability across all six regimes on every incident; notify each triggered recipient inside its deadline. The crown jewel.
15-month test cadence; the clock rehearsed in every exercise; lessons learned within 90 days.
Escalation tree plus the non-regulator notices: product users, deployers, interconnected entities, service recipients.
RCRecoverCSF Analog
Restore the service, recall the product, retire the identity — provably.
Plans per critical unit; verified backups; protected recovery information.
15-month test; multi-year full exercise cycle; lessons learned in 90 days.
Corrective-action machinery for in-service units: recall, withdrawal, suspension — the off-ramp begins here.
Sanitize, tear down access, retire the identifier with history preserved, produce the proof-of-elimination package. Prove-it’s-gone.
SCSupply Chain & Product IntegrityTENET Function
What you buy, what you build, what you can prove about both.
Supply-chain risk plan in every procurement: notification duties, SDL attestations, right-to-SBOM, EOS commitments.
Documented SDL for anything the organization builds — products, models, systems — proportionate to classification.
Machine-readable SBOM per product/system, kept current through change, feeding vulnerability watch.
Authenticity verified before install; signed updates; model provenance and data lineage recorded.
Vendor access as first-class access — attributable, time-bounded, terminable within SLA.
RRRegulatory Reporting & ConformityTENET Function
The regulator-facing membrane: register, certify, evidence, report, attest.
Every statutory registration — NERC, EU AI database, CE/DoC, NIS2 entity — as a projection of one internal register key.
The unit-appropriate path — RSAW-grade audit readiness, 62443 certification, CRA route by class, AI Act Art 43 route.
Evidence as a by-product of execution, never reconstructed; strictest retention floor wins (10 years CRA/AI Act).
All non-incident submissions on one owned calendar with proof-of-submission artifacts.
Attest-and-mark-gaps per unit per function; AGO signs the roll-up; attestation drives the maturity rating.
THE CROWN JEWEL · GGF-RS.CL-1
The Unified Reporting Clock
One incident. One timeline. Every obligation placed on it — computed once, at declaration, for all six regimes. No published framework does this.
Detection / awareness
Declare, then determine wide. Reportability determination for all six regimes — documented even when the answer is “not reportable.”
NERC CIP
E-ISAC + CISA — Reportable Cyber Security Incident, from determination (attempts: end of next calendar day)
NERC O&P
DOE OE-417 emergency categories, where triggered
NERC O&P
EOP-004 event report
NIS2
Early warning to the CSIRT — 24 h double-tap with CRA: draft once, render twice
EU CRA
Early warning to ENISA/CSIRT — actively exploited vulnerability or severe incident
EU AI Act
Art 73 report — widespread infringement, or serious & irreversible disruption of critical infrastructure
NIS2
Incident notification — assessment, severity, indicators of compromise (72 h double-tap with CRA)
EU CRA
Vulnerability / incident notification
EU AI Act
Art 73 report — incident involving a death
EU CRA
Final report — exploited vulnerability
EU AI Act
Serious-incident report — standard path
NIS2
Final report (or progress report if the incident is ongoing)
EU CRA
Final report — severe incident
Determine wide, notify fast
The six-regime determination matrix runs on every incident. A documented “not reportable” is a deliverable, not a shrug.
Double-taps are one work product
NIS2 and CRA share a skeleton at 24 h and again at 72 h. One incident record, many renders.
Near-misses have clocks too
CIP attempted-compromise and NIS2 significant-threat provisions live in the plan, not discovered mid-event.
The clock beats the meeting
Standing delegation to the Reporting Officer. No deadline waits on a signature — rehearsed in every exercise.
L4 ROLLUP
Function × regime coverage
Where each regime is heavy, light, or silent. Every dash is a gap the GGF fills — the defensible “no one has this” claims live in those cells, and only there.
| Function | CIP | 62443 | NIS2 | CRA | AI Act | O&P |
|---|---|---|---|---|---|---|
| GV Govern | ● | ◐ | ● | ◐ | ● | ◐ |
| ID Identify | ● | ● | ◐ | ● | ● | ● |
| PR Protect | ● | ● | ● | ● | ◐ | ◐ |
| DE Detect | ● | ● | ◐ | ◐ | ● | ● |
| RS Respond | ● | ◐ | ● | ● | ● | ● |
| RC Recover | ● | ◐ | ◐ | ◐ | ◐ | ◐ |
| ↳ The off-ramp (RC.RM/RC.DE) | ○ | ○ | — | ◐ | ◐ | — |
| SC Supply Chain | ● | ● | ● | ● | ◐ | ○ |
| RR Reporting & Conformity | ● | ◐ | ● | ● | ● | ● |
● primary ◐ partial ○ light — regime silent · GGF fills the gap
ELEVATION · THE MATURITY MODEL
Four tiers up
Each of the eight functions is rated 1–4 from attestation evidence. The profile is the 8-value vector — never an average. A Tier-4 Protect does not offset a Tier-1 Reporting function.
Initial
Per-regime silos and heroics. Inventories disagree. Reporting deadlines met by luck. Evidence reconstructed for audits.
Managed
Each regime has a documented program, owner, and calendar — separately. Clocks computed by hand, per event.
Defined
One register, six classifications. One control library, crosswalked. One IR plan with the Unified Clock rehearsed. Evidence as a by-product of execution.
Governed / Adaptive
Register reconciliation, control monitoring, and clock-readiness automated and watched 24/7. Regime changes absorbed as data updates, not projects.
One spine. Six regimes. Every clock.
The GGF is delivered through the Tenet system — registered by FORGE, classified by ATLAS, scored by CODEX, and operated 24/7 by SENTINEL.
Start Here