Riksdagsmonitor Intelligence Platform โ€” API Documentation - v1.0.47
    Preparing search index...

    Hack23 Logo

    ๐Ÿ›ก๏ธ Riksdagsmonitor โ€” CRA Conformity Assessment

    Evidence-Driven Conformity Through Systematic Assessment
    Demonstrating CRA Compliance for Swedish Parliament Intelligence Platform

    Owner Version Effective Date Review Cycle

    ๐Ÿ“‹ Document Owner: CEO | ๐Ÿ“„ Version: 1.4 | ๐Ÿ“… Last Updated: 2026-05-06 (UTC) ๐Ÿ”„ Review Cycle: Quarterly | โฐ Next Review: 2026-08-06 ๐Ÿข Owner: Hack23 AB (Org.nr 5595347807) | ๐Ÿท๏ธ Classification: Public


    Hack23 AB's CRA conformity assessment process demonstrates how systematic regulatory compliance directly enables business growth rather than creating operational burden. This assessment documents Riksdagsmonitor's compliance with the EU Cyber Resilience Act (CRA), providing evidence-based self-assessment of cybersecurity requirements for our Swedish Parliament intelligence platform.

    As a cybersecurity consulting company, our approach to CRA compliance becomes a showcase of professional implementation, demonstrating to potential clients how systematic regulatory adherence creates competitive advantages through robust security foundations while enabling EU market access.

    โ€” James Pether Sรถrling, CEO/Founder


    This process provides a concise, repeatable CRA Conformity Assessment for Riksdagsmonitor. Aligns with CRA Annex I & V, Hack23 classification, secure development, and transparency policies.

    Scope: Riksdagsmonitor platform within Asset Register requiring EU market placement.

    Process Alignment: This assessment follows the CRA Conformity Assessment Process template and is governed by the Open Source Policy for open source compliance requirements.


    DocumentFocusDescription
    ๐Ÿ›๏ธ Architecture๐Ÿ—๏ธ C4 ModelsSystem context, containers, components
    ๐Ÿ“Š Data Model๐Ÿ“Š DataEntity relationships and data dictionary
    ๐Ÿ”„ Flowchart๐Ÿ”„ ProcessesBusiness process and data flows
    ๐Ÿ“ˆ State Diagram๐Ÿ“ˆ StatesSystem state transitions and lifecycles
    ๐Ÿง  Mindmap๐Ÿง  ConceptsSystem conceptual relationships
    ๐Ÿ’ผ SWOT๐Ÿ’ผ StrategyStrategic analysis and positioning
    ๐Ÿ”ง Workflows๐Ÿ”ง DevOpsCI/CD automation and pipelines
    ๐Ÿ›ก๏ธ Security Architecture๐Ÿ”’ SecurityCurrent security controls and design
    ๐ŸŽฏ Threat Model๐ŸŽฏ ThreatsSTRIDE/MITRE ATT&CK analysis
    ๐Ÿ›ก๏ธ CRA Assessment โญโš–๏ธ ComplianceEU Cyber Resilience Act conformity

    The following Hack23 AB projects demonstrate completed CRA assessments:

    ๐Ÿš€ Project๐Ÿ“ฆ Product Type๐Ÿท๏ธ CRA Classification๐Ÿ“‹ Assessment Status๐Ÿ”— Reference Link
    ๐Ÿ•ต๏ธ CIA (Citizen Intelligence Agency)Political transparency platformStandard (Non-commercial OSS)โœ… Complete๐Ÿ“„ CRA Assessment
    โšซ Black TrigramKorean martial arts gameStandard (Non-commercial OSS)โœ… Complete๐Ÿ“„ CRA Assessment
    ๐Ÿ›ก๏ธ CIA Compliance ManagerCompliance automation toolStandard (Non-commercial OSS)โœ… Complete๐Ÿ“„ CRA Assessment
    ๐Ÿ—ณ๏ธ RiksdagsmonitorParliament intelligence platformStandard (Non-commercial OSS)โœ… This Document๐Ÿ“„ CRA Assessment

    Supports CRA Annex V ยง 1 - Product Description Requirements

    FieldValue
    ๐Ÿ“ฆ ProductRiksdagsmonitor
    ๐Ÿท๏ธ Version Tag0.4.1 (reflects current project state)
    ๐Ÿ”— Repositoryhttps://github.com/Hack23/riksdagsmonitor
    ๐Ÿ“ง Security Contactsecurity@hack23.org
    ๐ŸŒ Websitehttps://riksdagsmonitor.com
    ๐ŸŽฏ Purpose (1โ€“2 lines)Static HTML/CSS intelligence platform monitoring Swedish Parliament (Riksdag) activity, providing 14-language dashboards with 50+ years of political data through CIA platform integration and automated news generation

    ๐Ÿ“‹ Evidence Links:

    • ๐Ÿ—๏ธ System Architecture: ARCHITECTURE.md โ€” Complete C4 model architecture
    • ๐Ÿ” Security Architecture: SECURITY_ARCHITECTURE.md โ€” Defense-in-depth security controls
    • ๐Ÿ›ก๏ธ Future Security Vision: FUTURE_SECURITY_ARCHITECTURE.md โ€” Security roadmap
    • ๐Ÿ“Š Data Architecture: DATA_MODEL.md โ€” Data structures, schemas, relationships
    • ๐Ÿ”„ Process Workflows: FLOWCHART.md โ€” Data processing and CI/CD workflows
    • ๐Ÿง  System Overview: MINDMAP.md โ€” Conceptual system relationships
    • ๐ŸŽฏ Strategic Analysis: SWOT.md โ€” Strategic assessment
    • ๐ŸŽฏ Threat Analysis: THREAT_MODEL.md โ€” STRIDE and MITRE ATT&CK mapping
    • ๐Ÿ”ง CI/CD Pipelines: WORKFLOWS.md โ€” 43 workflow automation documentation

    ๐Ÿ“Š Project Status & Quality Badges:

    GitHub ReleaseOpenSSF Scorecard

    Quality ChecksCodeQLTypeScript & JavaScript Testing

    ๐Ÿ“‹ Data Sources Evidence:

    • ๐Ÿ›๏ธ Swedish Parliament: data.riksdagen.se โ€” Parliamentary members, committees, documents, votes
    • ๐Ÿ—ณ๏ธ Election Authority: val.se โ€” Election data, parties, voting results
    • ๐Ÿ“Š SCB (Statistics Sweden): scb.se โ€” PxWebAPI 2.0 (scb-mcp) โ€” official Swedish statistics (economy, labour, population, education, environment)
    • ๐ŸŒ World Bank Open Data: data.worldbank.org โ€” WGI governance, environment, long-horizon social/education (world-bank-mcp)
    • ๐ŸŒ IMF Open Data: data.imf.org โ€” macro/fiscal/monetary/external-sector freshness + T+5 projections (WEO, Fiscal Monitor, IFS, GFS_COFOG); consumed via pure-TypeScript client scripts/imf-client.ts (Datamapper JSON + SDMX 3.0) โ€” not an MCP server, SBOM-covered via npm (ADR 0001)
    • ๐Ÿ•ต๏ธ CIA Platform: Citizen Intelligence Agency โ€” 19 intelligence products, risk assessments, analytics

    Supports CRA Article 6 - Scope and Article 7 - Product Classification Assessment

    Non-commercial OSS

    Community

    Standard

    ๐Ÿ“ CRA Scope Justification: Riksdagsmonitor is a non-commercial open-source static website providing Swedish Parliament transparency services through data visualization and news generation. As a volunteer-driven initiative with community distribution via GitHub under Apache 2.0 license, it falls under non-commercial OSS with Standard CRA classification enabling self-assessment approach. The static site architecture (HTML/CSS/JS with no server-side execution) significantly reduces the attack surface compared to traditional web applications.

    ๐Ÿ“‹ Classification Evidence:

    ๐Ÿ” Classification Impact:

    • Standard: Self-assessment approach (this document provides evidence)
    • Class I/II: Would require notified body assessment + additional documentation

    Supports CRA Annex V ยง 2 - Technical Documentation Requirements

    ๐Ÿ—๏ธ CRA Technical Area๐Ÿ“ Implementation Summary๐Ÿ“‹ Evidence Location
    ๐ŸŽจ Product Architecture (Annex V ยง 2.1)Static HTML/CSS website with C4 architecture model. Deployed on AWS CloudFront (us-east-1 primary, eu-west-1 replica) with GitHub Pages DR. 14-language support, Chart.js/D3.js dashboardsARCHITECTURE.md + SECURITY_ARCHITECTURE.md + MINDMAP.md
    ๐Ÿ“ฆ SBOM & Components (Annex I ยง 1.1)npm package management with package-lock.json. Dependabot automated dependency scanning. OpenSSF Scorecard monitoring. News pipeline additions (2026 Q1): unified, remark-parse, remark-gfm, remark-rehype, rehype-raw, rehype-sanitize, rehype-slug, rehype-autolink-headings, rehype-stringify, gray-matter โ€” all npm-managed, version-pinned in package-lock.json, Dependabot-grouped under dependencies. mermaid loaded as ESM from the same package for client-side diagram rendering (strict-mode; no eval).package.json + Dependabot Config + OpenSSF Scorecard
    ๐Ÿ” Cybersecurity Controls (Annex I ยง 1.2)Static site architecture (no server-side execution), HTTPS-only via CloudFront/GitHub Pages, CSP headers, SRI for CDN assets, SHA-pinned GitHub Actions, step-security/harden-runner. News pipeline additions: rehype-sanitize allow-list enforced at the trust boundary between AI-authored markdown and published HTML; Mermaid rendered in securityLevel: 'strict' (no eval, no click handlers); SHA-256 manifest in .manifest.json sibling to each article.md for tamper detection. Agentic control-plane additions (v0.9.40): 23 required analysis artifacts, analysis gate checks 1โ€“9b, methodology-reflection validator, safe-output PR boundary, Squid + iptables egress firewall.SECURITY_ARCHITECTURE.md ยงPolitical Intelligence Security Surface + THREAT_MODEL.md TB-PI series
    ๐Ÿ›ก๏ธ Supply Chain Security (Annex I ยง 1.3)SHA-pinned GitHub Actions, Dependabot automation, OpenSSF Scorecard monitoring, CodeQL analysis, dependency review workflow, step-security/harden-runner egress auditingWORKFLOWS.md + OpenSSF Scorecard
    ๐Ÿ”„ Update Mechanism (Annex I ยง 1.4)Automated CI/CD pipeline via GitHub Actions with security scanning (CodeQL, dependency review), dual deployment (S3 + GitHub Pages), version management via release workflowWORKFLOWS.md + Release Workflow
    ๐Ÿ“Š Security Monitoring (Annex I ยง 1.5)GitHub Security Dashboard (code scanning, secret scanning, Dependabot alerts), Lighthouse CI performance monitoring, uptime monitoring, AWS CloudWatch/CloudFront metricsSECURITY_ARCHITECTURE.md + WORKFLOWS.md
    ๐Ÿท๏ธ Data Protection (Annex I ยง 2.1)No personal data collection. Public political data only. GDPR compliant by design โ€” static site with no user accounts, no cookies, no tracking. All data sourced from public government APIsDATA_MODEL.md + THREAT_MODEL.md
    ๐Ÿ“š User Guidance (Annex I ยง 2.2)Comprehensive README with deployment instructions, architecture documentation, security configuration guidesREADME.md + ARCHITECTURE.md + SECURITY_ARCHITECTURE.md
    ๐Ÿ” Vulnerability Disclosure (Annex I ยง 2.3)Public vulnerability disclosure policy via GitHub Security Advisories, coordinated disclosure process, 48h acknowledgment timelineSECURITY.md + Security Advisories

    ๐Ÿ“‹ Comprehensive ISMS Integration:


    Supports CRA Annex V ยง 3 - Risk Assessment Documentation

    Reference: ๐Ÿ“Š Risk Assessment Methodology and โš ๏ธ Risk Register

    ๐Ÿšจ CRA Risk Category๐ŸŽฏ Asset๐Ÿ“Š Likelihood๐Ÿ’ฅ Impact (C/I/A)๐Ÿ›ก๏ธ CRA Control Implementationโš–๏ธ Residual๐Ÿ“‹ Evidence
    Supply Chain Attack (Art. 11)Build pipeline & npm dependenciesMH/H/MSHA-pinned GitHub Actions + Dependabot automation + step-security/harden-runner egress audit + OpenSSF Scorecard monitoring + dependency review workflowLWORKFLOWS.md + OpenSSF Scorecard
    Website Defacement (Art. 11)Static website content & dashboardsMM/H/MBranch protection rules + required PR reviews + CodeQL scanning + dual deployment (S3 + GitHub Pages) for DRLSECURITY_ARCHITECTURE.md + THREAT_MODEL.md
    Data Integrity Attack (Art. 11)Political data & news contentML/H/MCIA data validation schemas + automated translation validation + multi-source data verification + git-based audit trailLDATA_MODEL.md + WORKFLOWS.md
    AI Content Manipulation (Art. 11)AI-authored analysis artifacts โ†’ rendered news HTMLMM/H/Lrehype-sanitize allow-list at trust boundary (blocks <script>, <iframe>, inline handlers, javascript: URIs); Mermaid rendered in securityLevel: 'strict' (no eval); SHA-256 manifest per article for tamper detection; analysis gate checks 1โ€“9b; methodology-reflection validator; 23-artifact completeness gate; mandatory human PR reviewMSECURITY_ARCHITECTURE.md ยงPolitical Intelligence Security Surface + THREAT_MODEL.md TB-PI series + WORKFLOWS.md
    CDN/Infrastructure Compromise (Art. 11)CloudFront distribution & S3 storageLM/H/HAWS multi-region deployment + SRI for CDN assets + GitHub Pages DR failover + HTTPS-only + TLS 1.3LSECURITY_ARCHITECTURE.md + ARCHITECTURE.md
    Component Vulnerability (Art. 11)npm dependencies (Chart.js, D3.js, Vite)MM/H/MDependabot updates + CodeQL scanning + dependency review workflow + SRI hashes for CDN assetsLSecurity Scanning + Dependabot

    โš–๏ธ CRA Risk Statement: LOW โ€” Static site architecture eliminates entire categories of server-side vulnerabilities. Comprehensive security controls and evidence-based monitoring support CRA essential cybersecurity requirements. โœ… Risk Acceptance: James Sรถrling, CEO Hack23 AB โ€” February 2026

    ๐Ÿ“‹ Risk Management Framework Evidence:


    Supports CRA Annex I - Essential Requirements Self-Assessment

    ๐Ÿ“‹ CRA Annex I Requirementโœ… Status๐Ÿ“‹ Implementation Evidence
    ๐Ÿ›ก๏ธ ยง 1.1 - Secure by Design[x]Defense-in-depth Architecture โ€” Static site architecture eliminates server-side attack vectors. CSP headers, SRI hashes, HTTPS-only, multi-region deployment
    ๐Ÿ”’ ยง 1.2 - Secure by Default[x]Static HTML/CSS with no server-side execution. No user accounts, no cookies, no tracking. Security Architecture documents secure defaults
    ๐Ÿท๏ธ ยง 2.1 - Personal Data Protection[x]No personal data collection โ€” GDPR compliant by design. Public political data only. Data Model documents data handling
    ๐Ÿ” ยง 2.2 - Vulnerability Disclosure[x]SECURITY.md with GitHub Security Advisories, coordinated disclosure, 48h acknowledgment. Vulnerability Management
    ๐Ÿ“ฆ ยง 2.3 - Software Bill of Materials[x]package.json + package-lock.json provide complete dependency inventory. Dependabot provides continuous SCA
    ๐Ÿ” ยง 2.4 - Secure Updates[x]Automated CI/CD pipeline with CodeQL, dependency review, SHA-pinned actions. WORKFLOWS.md documents 43 workflows
    ๐Ÿ“Š ยง 2.5 - Security Monitoring[x]GitHub Security Dashboard (code scanning, secret scanning, Dependabot), Lighthouse CI, uptime monitoring. SECURITY_ARCHITECTURE.md
    ๐Ÿ“š ยง 2.6 - Security Documentation[x]Complete architecture documentation portfolio: ARCHITECTURE.md, SECURITY_ARCHITECTURE.md, THREAT_MODEL.md, DATA_MODEL.md + 6 future-state documents

    ๐ŸŽฏ CRA Self-Assessment Status: EVIDENCE_DOCUMENTED

    ๐Ÿ” Security Implementation Evidence:

    • ๐Ÿ›ก๏ธ Static Site Security: No server-side code execution eliminates SQL injection, RCE, SSRF, and authentication bypass vulnerabilities
    • ๐Ÿ”’ Transport Security: HTTPS-only via AWS CloudFront (TLS 1.3) and GitHub Pages
    • ๐Ÿ“Š Supply Chain: SHA-pinned GitHub Actions, Dependabot, CodeQL, step-security/harden-runner
    • ๐Ÿ” Content Integrity: Subresource Integrity (SRI) for CDN-loaded Chart.js and D3.js libraries

    Supports CRA Article 19 - Conformity Assessment Documentation

    Reference: ๐Ÿ› ๏ธ Secure Development Policy

    ๐Ÿงช Control๐ŸŽฏ Requirementโœ… Implementation๐Ÿ“‹ Evidence
    ๐Ÿงช Unit TestingComprehensive test coverageโœ… ImplementedVitest โ€” 7,500+ tests across 237 test files
    ๐ŸŒ E2E TestingCritical user journeys validatedโœ… ImplementedCypress E2E โ€” Multi-language homepage, dashboard, accessibility
    ๐Ÿ” SAST ScanningZero critical/high vulnerabilitiesโœ… ImplementedCodeQL Analysis
    ๐Ÿ“ฆ SCA ScanningZero critical unresolved dependenciesโœ… ImplementedDependabot Alerts + Dependency Review
    ๐Ÿ”’ Secret ScanningZero exposed secrets/credentialsโœ… ImplementedGitHub Secret Scanning + Push protection enabled
    ๐Ÿ“Š Quality GatesHTML validation + link checkingโœ… ImplementedQuality Checks โ€” HTMLHint + linkinator
    ๐Ÿ” Supply ChainSHA-pinned actions + egress auditโœ… ImplementedOpenSSF Scorecard + step-security/harden-runner
    ๐Ÿ“ˆ PerformanceLighthouse CI monitoringโœ… ImplementedLighthouse CI โ€” Core Web Vitals tracking

    ๐Ÿ” Supply Chain Security: OpenSSF Scorecard

    ๐Ÿ›ก๏ธ Security Scanning: CodeQLDependency ReviewScorecards

    ๐Ÿ“Š Quality & Testing: Quality ChecksTypeScript & JavaScript Testing

    โš–๏ธ License: license


    7๏ธโƒฃ Post-Market Surveillance

    Supports CRA Article 23 - Obligations of Economic Operators

    Reference: ๐ŸŒ ISMS Transparency Plan and ๐Ÿ“Š Security Metrics

    ๐Ÿ“ก CRA Monitoring Obligation๐Ÿ”ง Implementationโฑ๏ธ Frequency๐ŸŽฏ Action Trigger๐Ÿ“‹ Evidence
    ๐Ÿ” Vulnerability Monitoring (Art. 23.1)Dependabot + GitHub advisories + CodeQL scanning + dependency reviewContinuousAuto-create security issues and PRsDependabot Alerts + Security Advisories
    ๐Ÿšจ Incident Reporting (Art. 23.2)GitHub Security Dashboard + AWS CloudWatch + CloudFront access logsReal-timeENISA 24h notification prep via ISMS incident responseSECURITY.md + Incident Response Plan
    ๐Ÿ“Š Security Posture Tracking (Art. 23.3)OpenSSF Scorecard + Lighthouse CI + uptime monitoringWeekly/DailyScore decline investigation via automated alertsOpenSSF Scorecard
    ๐Ÿ”„ Update Distribution (Art. 23.4)Automated GitHub releases + dual deployment (S3 + GitHub Pages) + CI/CD pipelineAs neededCritical vulnerability patches via secure CI/CD pipelineRelease Management + WORKFLOWS.md

    ๐Ÿ“‹ CRA Reporting Readiness: Documentation and procedures prepared for ENISA incident reporting per ๐Ÿšจ Incident Response Plan

    ๐Ÿ”— ISMS Monitoring Integration:


    Supports CRA Article 28 - EU Declaration of Conformity

    ๐Ÿข Manufacturer: Hack23 AB, Gothenburg, Sweden ๐Ÿ“ฆ Product: Riksdagsmonitor v0.9.40 ๐Ÿ“‹ CRA Compliance: Self-assessment documentation supporting CRA essential cybersecurity requirements evaluation ๐Ÿ” Assessment: Self-assessment documentation per Article 24 (non-commercial OSS with standard classification) ๐Ÿ“Š Standards: ISO/IEC 27001 security framework + OWASP web security guidelines + NIST SSDF secure development

    ๐Ÿ“… Date & Signature: 2026-05-06 โ€” James Sรถrling, CEO Hack23 AB

    ๐Ÿ“‚ Technical Documentation: This assessment + evidence bundle supports CRA Annex V technical documentation requirements


    Supports CRA Article 16 - Quality Management System Documentation

    Overall CRA Documentation Status: EVIDENCE_DOCUMENTED

    Key CRA Documentation Areas:

    • โœ… Annex I essential requirements documented with comprehensive evidence links
    • โœ… Annex V technical documentation comprehensively structured
    • โœ… Article 11 security measures implemented and documented
    • โœ… Article 23 post-market surveillance procedures operational

    Static Site Security Advantage: Riksdagsmonitor's static site architecture provides inherent security benefits:

    • No server-side code execution (eliminates SQL injection, RCE, SSRF)
    • No user authentication/session management (eliminates authentication bypass, session hijacking)
    • No database (eliminates data breach risks)
    • No cookies/tracking (GDPR compliant by design)
    • CDN-distributed content (inherent DDoS resilience)
    ๐Ÿ‘ค Role๐Ÿ“ Name๐Ÿ“… Dateโœ๏ธ Assessment Attestation
    ๐Ÿ”’ CRA Security AssessmentJames Sรถrling2026-05-06Essential requirements documented with comprehensive evidence
    ๐ŸŽฏ Product ResponsibilityJames Sรถrling2026-05-06Technical documentation complete and publicly accessible
    โš–๏ธ Legal Compliance ReviewJames Sรถrling2026-05-06EU regulatory documentation requirements satisfied

    ๐Ÿ“Š CRA Assessment Status: SELF_ASSESSMENT_DOCUMENTED


    Per CRA Article 15 - Substantial Modification

    CRA assessment updated only when changes constitute "substantial modification" under CRA:

    1. ๐Ÿ—๏ธ Security Architecture Changes: New trust boundaries, encryption, or deployment topology
    2. ๐Ÿ›ก๏ธ Essential Requirement Impact: Changes affecting Annex I compliance
    3. ๐Ÿ“ฆ Critical Dependencies: New supply chain components with security implications (e.g., new CDN libraries)
    4. ๐Ÿ” Risk Profile Changes: New threats or vulnerability classes affecting political data integrity
    5. โš–๏ธ Regulatory Updates: CRA implementing acts or guidance changes

    ๐ŸŽฏ Maintenance Principle: Assessment stability preferred โ€” avoid routine updates that don't impact CRA compliance


    ๐Ÿ” CRA Article Cross-References

    • Article 6: Scope determination โ†’ Section 2 (CRA Classification)
    • Article 11: Essential cybersecurity requirements โ†’ Section 5 (Requirements Assessment)
    • Article 19: Conformity assessment โ†’ Section 6 (Evidence Documentation)
    • Article 23: Post-market obligations โ†’ Section 7 (Surveillance Documentation)
    • Article 28: Declaration of conformity โ†’ Section 8 (DoC Template)
    • Annex I: Technical requirements โ†’ Section 5 (Requirements self-assessment mapping)
    • Annex V: Technical documentation โ†’ Complete template structure
    • ๐Ÿ”„ Operational Continuity: CRA self-assessment integrated with existing security operations
    • ๐Ÿ“Š Evidence Reuse: Security metrics and monitoring serve dual ISMS/CRA documentation purposes
    • ๐ŸŽฏ Business Value: CRA readiness demonstrates cybersecurity consulting expertise
    • ๐Ÿค Client Confidence: Transparent self-assessment showcases professional implementation methodology

    Demonstrating compliance with Hack23 AB Open Source Policy

    RequirementStatusEvidence
    OpenSSF Scorecard โ‰ฅ7.0โœ… ActiveOpenSSF Scorecard
    Quality Gate Passedโœ… ActiveQuality Checks Workflow
    License Badgeโœ… Activelicense
    Threat Model Publishedโœ… ActiveThreat Model
    STRIDE Analysis Completeโœ… ActiveSTRIDE Analysis
    Required ArtifactStatusEvidence
    SECURITY_ARCHITECTURE.mdโœ… PresentSECURITY_ARCHITECTURE.md โ€” Defense-in-depth with Mermaid diagrams
    FUTURE_SECURITY_ARCHITECTURE.mdโœ… PresentFUTURE_SECURITY_ARCHITECTURE.md โ€” Security roadmap
    SECURITY.mdโœ… PresentSECURITY.md โ€” Coordinated vulnerability disclosure
    WORKFLOWS.mdโœ… PresentWORKFLOWS.md โ€” CI/CD pipeline with security gates
    LICENSEโœ… Apache 2.0LICENSE โ€” OSI-approved
    CRA-ASSESSMENT.mdโœ… PresentThis document
    CODE_OF_CONDUCT.mdโœ… PresentCODE_OF_CONDUCT.md โ€” Community standards
    CONTRIBUTING.mdโœ… PresentCONTRIBUTING.md โ€” Contribution guidelines
    README.mdโœ… PresentREADME.md โ€” Includes project classification section
    RequirementStatusEvidence
    Supply Chain: Dependency Scanningโœ… AutomatedDependabot Config
    Supply Chain: SHA-pinned Actionsโœ… EnforcedWORKFLOWS.md โ€” All Actions pinned to SHA
    Supply Chain: step-security/harden-runnerโœ… ActiveEgress auditing on all workflows
    Vulnerability Management SLAโœ… ActiveSECURITY.md โ€” Coordinated disclosure + Dependabot auto-remediation
    SAST: CodeQLโœ… ActiveCodeQL Workflow
    SCA: Dependency Reviewโœ… ActiveDependency Review Workflow
    Secret Scanningโœ… ActiveSecurity Overview
    RequirementStatusEvidence
    Primary License: Apache 2.0โœ… Approved (Permissive)LICENSE
    Dependencies: Permissive Licensesโœ… All permissivenpm dependencies under MIT/ISC/Apache 2.0/BSD
    No Prohibited Licensesโœ… VerifiedNo AGPL/GPL/advertising-clause licenses in dependency tree
    RequirementStatusEvidence
    CIA Triad Classificationโœ… DeclaredPublic / High Integrity / High Availability
    Business Impact Assessmentโœ… DocumentedSWOT.md + CRA Risk Assessment
    RTO/RPO Objectivesโœ… DefinedRTO: <24h (Medium) / RPO: <24h (Daily)
    RequirementStatusEvidence
    No PII/GDPR dataโœ… CompliantNo personal data collection โ€” static site, no user accounts
    No production credentialsโœ… CompliantGitHub secret scanning active
    Public data onlyโœ… CompliantAll data sourced from public government APIs
    RequirementStatusEvidence
    Contribution guidelinesโœ… PublishedCONTRIBUTING.md
    Code of Conductโœ… PublishedCODE_OF_CONDUCT.md
    PR review processโœ… ActiveBranch protection + required reviews

    Demonstrating compliance with Hack23 AB CRA Conformity Assessment Process

    Process StepTemplate SectionStatusRiksdagsmonitor Evidence
    1๏ธโƒฃ Project IdentificationCRA Annex V ยง1โœ… CompleteSection 1 โ€” Product description, badges, data sources
    2๏ธโƒฃ CRA Scope & ClassificationCRA Art. 6-7โœ… CompleteSection 2 โ€” Non-commercial OSS, Standard, Community distribution
    3๏ธโƒฃ Technical DocumentationCRA Annex V ยง2โœ… CompleteSection 3 โ€” 9 CRA technical areas documented with evidence links
    4๏ธโƒฃ Risk AssessmentCRA Annex V ยง3โœ… CompleteSection 4 โ€” 6 risk categories assessed with residual risk
    5๏ธโƒฃ Essential RequirementsCRA Annex Iโœ… CompleteSection 5 โ€” 13 essential requirements mapped
    6๏ธโƒฃ Conformity EvidenceCRA Art. 19โœ… CompleteSection 6 โ€” Badges, CI/CD evidence, release artifacts
    7๏ธโƒฃ Post-Market SurveillanceCRA Art. 23โœ… CompleteSection 7 โ€” Monitoring, reporting, update mechanisms
    8๏ธโƒฃ Declaration of ConformityCRA Art. 28โœ… DraftSection 8 โ€” DoC template ready for formal placement
    9๏ธโƒฃ Assessment ApprovalInternalโœ… CompleteSection 9 โ€” CEO approval documented
    Classification DimensionSelected ValueJustification
    ๐Ÿช Market CategoryOSSApache 2.0 licensed, freely available on GitHub
    ๐Ÿ›ก๏ธ ConfidentialityPublicAll data from public government sources
    โœ… IntegrityHighPolitical data accuracy is essential for democratic trust
    โฑ๏ธ AvailabilityHigh99.998% design availability (AWS CloudFront multi-region + GitHub Pages DR), automated failover
    ๐Ÿ• RTOMediumGitHub Pages DR available within hours
    ๐Ÿ”„ RPODailyGit-based continuous backup, daily content generation
    ๐Ÿข CRA ApplicabilityNon-commercial OSSVolunteer-driven, no revenue model
    ๐ŸŒ DistributionCommunityGitHub public repository
    ๐Ÿ“‹ CRA ClassificationStandardNot in Annex III/IV critical categories

    This section provides a systematic mapping of all 13 essential cybersecurity requirements from CRA Annex I, Part I to Riksdagsmonitor implementations.

    Req #Annex I RequirementRiksdagsmonitor ImplementationEvidenceCompliance Status
    1Products with digital elements shall be designed, developed and produced with appropriate security, considering the risks during developmentStatic HTML/CSS/JS architecture eliminates server-side attack surface. Secure development lifecycle with threat modeling (THREAT_MODEL.md), security architecture (SECURITY_ARCHITECTURE.md), and annual security reviewsTHREAT_MODEL.md, SECURITY_ARCHITECTURE.md, GitHub CodeQL scan resultsCOMPLIANT
    2Products shall be delivered without known exploitable vulnerabilitiesDependabot automated vulnerability scanning, npm audit in CI/CD, CodeQL SAST analysis, no known CVEs in production dependencies. Pre-deployment security gate in GitHub ActionsGitHub Security tab - 0 open critical/high alerts, npm audit reports in CI logsCOMPLIANT
    3Products shall have secure by default configurations, including possibility to reset to factory settingsNo configuration required by end users. Static site has no user-configurable settings. TLS 1.3 enforced by GitHub Pages/CloudFront. CSP headers set by defaultGitHub Pages HTTPS enforcement, CloudFront TLS policy, HTTP response headersCOMPLIANT
    4Products shall protect against unauthorized access through appropriate access control mechanismsRepository protected by GitHub authentication and branch protection rules. No public write access. Least privilege permissions in GitHub Actions workflows. GitHub Secrets for credential storageGitHub branch protection settings, workflow permissions YAML, GitHub Actions audit logCOMPLIANT
    5Products shall protect the confidentiality of data by appropriate means including encryption of data at rest and in transitAll data in transit protected by TLS 1.3 enforced via GitHub Pages and CloudFront. No sensitive data at rest (all content is public political data). No PII collected or processedCloudFront TLS 1.3 configuration, HSTS headers, no-cookie policyCOMPLIANT
    6Products shall protect the integrity of data in transit and stored data against manipulationSLSA provenance attestation (Level 2+), Sigstore signing, Git commit signatures, GitHub content integrity guarantees. Article-level SHA-256 planned Q3 2026SLSA attestation in GitHub Actions, Sigstore transparency log, Git commit signature verification, GitHub repository content integrity documentationCOMPLIANT
    7Products shall process only data, both personal and other, that is adequate, relevant and limited to what is necessaryZero PII collected. Platform processes only publicly available Riksdag political data. No analytics cookies. No user tracking. Data minimization by designPrivacy policy (no-cookie design), source code review showing no PII collectionCOMPLIANT
    8Products shall protect the availability of essential functions including protection against denial of service attacksAWS CloudFront CDN with DDoS protection at edge. GitHub Pages provides secondary availability. Route 53 health-check-based failover. 99.998% availability targetCloudFront Shield Standard coverage, BCPPlan.md, dual-deployment architectureCOMPLIANT
    9Products shall minimize the negative impact on the availability of services provided by other devices or networksStatic site generates no outbound network calls from user browsers beyond CDN. MCP pipeline calls are server-side in GitHub Actions (controlled, rate-limited)Source code showing no user-browser-initiated external calls, rate limiting in MCP clientCOMPLIANT
    10Products shall be designed, developed and produced to limit attack surfaces, including external interfacesAttack surface minimized: no database, no server-side code, no user input forms, no cookies. Only surfaces: HTTPS static file serving, GitHub API (authenticated). No exposed portsArchitecture.md showing static-only design, no open ports analysisCOMPLIANT
    11Products shall be designed, developed and produced to reduce the impact of an incident including through appropriate mechanisms for resilienceAutomatic failover (CloudFront origin failover <30s, DNS failover <15min). Complete Git history for rollback. Incident response procedures in BCPPlan.md and ISMS. No persistent state to loseBCPPlan.md dual-deployment, RTO metrics, Git rollback capabilityCOMPLIANT
    12Products shall record and/or monitor relevant internal activities in order to detect and investigate cybersecurity incidentsGitHub Actions audit logs, CloudFront access logs, GitHub Security alerts, OpenSSF Scorecard monitoring, automated Dependabot alerts. step-security/harden-runner egress monitoringGitHub Audit Log API, CloudFront log groups, Security tab alert historyCOMPLIANT
    13Products shall ensure that vulnerabilities can be addressed through security updates including, where technically possible, automatic updatesDependabot automated PRs for dependency updates. GitHub Actions automated vulnerability notifications. Security contact (security@hack23.com) for coordinated disclosure. SECURITY.md outlines update processDependabot configuration, SECURITY.md, coordinated disclosure policyCOMPLIANT

    Req #Annex I Part II RequirementRiksdagsmonitor ImplementationEvidenceCompliance Status
    1Identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materialsnpm package-lock.json provides complete dependency graph. Dependabot monitors all dependencies. SBOM generation planned for 2027 via GitHub SBOM featurepackage-lock.json, npm audit output, Dependabot alertsPARTIAL โ€” SBOM automation planned 2027
    2Address vulnerabilities without delay including by providing security updatesCritical: <7 days. High: <30 days. Medium: <90 days. Dependabot auto-PRs for patch releases. Manual review for major version upgradesDependabot configuration, vulnerability management in ISMS, MTTP metricsCOMPLIANT
    3Apply effective and regular testing and reviews of the security of products with digital elementsCodeQL SAST on every PR and commit. Dependabot daily scans. Quarterly threat model review. Annual security architecture review. OpenSSF Scorecard monthlyGitHub Actions security scan results, CodeQL alerts, Scorecard historyCOMPLIANT
    4After becoming aware of a vulnerability, share information about it with ENISA without undue delayENISA reporting procedure: notify via security@hack23.com internal triage, then report to ENISA vulnerability database within 72 hours for critical issuesISMS Incident Response Plan, coordinated disclosure procedureCOMPLIANT โ€” procedure documented
    5Establish and document a coordinated vulnerability disclosure policySECURITY.md contains full coordinated vulnerability disclosure policy. security@hack23.com for reporting. 90-day disclosure timeline. Response SLA: acknowledge within 5 business daysSECURITY.md public policyCOMPLIANT
    6Take measures to facilitate the sharing of information about vulnerabilities in the productPublic GitHub Security Advisories for all confirmed vulnerabilities. SECURITY.md disclosure policy. GitHub private vulnerability reporting enabledGitHub Security Advisories tab, SECURITY.mdCOMPLIANT
    7Provide for a mechanism for coordinating the vulnerability disclosure process with other manufacturers or security researcherssecurity@hack23.com receives all vulnerability reports. GitHub private vulnerability reporting. Coordinated disclosure gives reporters credit. No retaliation policySECURITY.md safe harbor clauseCOMPLIANT
    8As long as products are supported, make available without delay security updates to address vulnerabilitiesImmediate security updates for critical vulnerabilities. Automated Dependabot PRs for all vulnerable dependencies. Auto-merge configured for patch-level security updatesDependabot auto-merge configuration, security update historyCOMPLIANT

    Assessment Method: Self-Assessment (Module A - Internal Production Control)

    Riksdagsmonitor qualifies for self-assessment under CRA Article 32(1) as it is:

    • A standard product with digital elements (not critical or important category per Annex III/IV)
    • Non-commercial open-source software distributed publicly without charge
    • A civic transparency tool with low risk profile (no safety functions, no critical infrastructure)

    Self-Assessment Process:

    1. Technical Documentation (CRA Annex V): Complete โ€” this document and linked ISMS documents
    2. Design and Development Assessment: Complete โ€” THREAT_MODEL.md, SECURITY_ARCHITECTURE.md
    3. Production Controls: Complete โ€” CI/CD pipeline with security gates documented in WORKFLOWS.md
    4. Conformity Declaration: Template in Section 8 of this document
    5. CE Marking: Applicable upon formal EU market placement (currently pre-commercial)

    Assessment Conclusion:

    CRA AreaRequirementsCompliantPartialNon-Compliant
    Annex I Part I131300
    Annex I Part II8710
    Annex V DocumentationCompleteYesโ€”โ€”
    Vulnerability HandlingPolicy existsYesโ€”โ€”
    Overall212010

    Open Item: SBOM automation (Annex I Part II Req 1) โ€” planned Q1 2027 via GitHub SBOM generation feature.



    This section provides a forward-looking readiness checklist for when Riksdagsmonitor formally enters EU market distribution as a commercial product.

    AreaRequirementCurrent ReadinessAction RequiredTarget Date
    Technical DocumentationCRA Annex V complete documentation95% completeFinalize SBOM generationQ1 2027
    Conformity AssessmentSelf-assessment completed and documented90% completeFormal declaration of conformityQ2 2027
    Vulnerability Handling PolicyPublished and accessible100%None - SECURITY.md completeDone
    Security Update ProcessDocumented and operational100%None - Dependabot + MTTP policyDone
    Coordinated DisclosurePolicy and contact established100%None - security@hack23.comDone
    CE MarkingRequired for EU market productsNot yetApply after conformity assessment2027
    ENISA ReportingIncident reporting procedure85%Document ENISA contact and timelineQ2 2026
    SBOMSoftware Bill of MaterialsPartialImplement GitHub SBOM generationQ1 2027
    Post-Market SurveillanceOngoing monitoring plan80%Formalize surveillance process docQ3 2026
    flowchart LR
    VULN_DISCOVERED[Vulnerability Discovered] --> ASSESS[Severity Assessment]
    ASSESS --> CRITICAL{Critical CVSS 9+?}
    CRITICAL -->|Yes| PATCH_7[Patch within 7 days]
    CRITICAL -->|No| HIGH{High CVSS 7-8.9?}
    HIGH -->|Yes| PATCH_30[Patch within 30 days]
    HIGH -->|No| MED{Medium CVSS 4-6.9?}
    MED -->|Yes| PATCH_90[Patch within 90 days]
    MED -->|No| PATCH_SCHED[Patch in next release]
    PATCH_7 --> DEPLOY[Deploy Security Update]
    PATCH_30 --> DEPLOY
    PATCH_90 --> DEPLOY
    PATCH_SCHED --> DEPLOY
    DEPLOY --> NOTIFY[Notify via SECURITY.md Advisory]
    NOTIFY --> ENISA_CHECK{Significant incident?}
    ENISA_CHECK -->|Yes| ENISA_REPORT[Report to ENISA within 24h]
    ENISA_CHECK -->|No| CLOSE[Close Vulnerability Record]
    ENISA_REPORT --> CLOSE

    CRA Article 13 Manufacturer Obligations Tracking

    ObligationArticleImplementationStatus
    Design and produce with appropriate cybersecurity13(1)Secure SDLC, STRIDE threat modelingDone
    Deliver without known exploitable vulnerabilities13(2)Dependabot, npm audit, CodeQL pre-deployDone
    Perform vulnerability assessment13(3)Quarterly threat model reviewDone
    Apply security updates without undue delay13(4)Dependabot auto-merge, MTTP policyDone
    Ensure security for expected lifetime13(5)Lifecycle support policy documentedDone
    Set support period in declaration of conformity13(6)Support period: 5 years from last releasePlanned
    Provide security updates for support period13(7)Dependabot + manual review ongoingDone
    Notify ENISA of actively exploited vulnerabilities13(8)ENISA procedure in IR PlanDone
    Provide technical documentation13(14)CRA-ASSESSMENT.md + SECURITY_ARCHITECTURE.mdDone
    Affix CE marking13(15)Not yet - required for market placementPlanned
    Draw up EU declaration of conformity13(16)Template exists - formal sign-off pendingPlanned

    CRA Article 14 Reporting Obligations

    Active Exploitation Reporting (Article 14(2)):

    • Notification timeline: Within 24 hours of becoming aware
    • Recipient: ENISA Early Warning notification system
    • Content: Product identification, vulnerability description, known exploited instances
    • Contact: security@hack23.com (internal) โ†’ ENISA online notification form

    Severe Incident Reporting (Article 14(3)):

    • Notification timeline: Within 72 hours of detection
    • Recipient: Competent market surveillance authority (MSA) and ENISA
    • For Sweden: Swedish Post and Telecom Authority (PTS) as likely MSA
    • Content: Detailed incident report including impact, affected versions, remediation

    User Notification (Article 14(8)):

    • If security update available: Notify users via GitHub Security Advisories
    • If vulnerability affects user security: Post advisory on riksdagsmonitor.com
    • Update README.md security section for significant vulnerabilities

    Riksdagsmonitor must be evaluated against CRA's product classification system to determine the applicable conformity assessment route:

    CRA Annex III โ€” Important Products with Digital Elements (Class I):

    CategoryRiksdagsmonitor Assessment
    Identity management softwareNot applicable
    Password managersNot applicable
    BrowsersNot applicable
    Operating systemsNot applicable
    VPNsNot applicable
    Network management softwareNot applicable
    FirewallsNot applicable
    Intrusion detection systemsNot applicable
    MicrocontrollersNot applicable
    Consumer IoTNot applicable

    Conclusion: Riksdagsmonitor does not qualify as a Class I Important Product under Annex III.

    CRA Annex IV โ€” Critical Products with Digital Elements (Class II):

    CategoryRiksdagsmonitor Assessment
    Critical infrastructure softwareNot applicable - civic transparency platform
    HSMs / Secure elementsNot applicable
    Smart metersNot applicable
    Industrial control systemsNot applicable

    Conclusion: Riksdagsmonitor does not qualify as a Class II Critical Product under Annex IV.

    Final Classification: Standard Product with Digital Elements โ€” eligible for Module A Self-Assessment


    Open Source Software Considerations (CRA Article 16)

    Riksdagsmonitor benefits from the CRA open source carve-out provisions:

    CRA ProvisionApplication to Riksdagsmonitor
    Non-commercial OSS exemption (Recital 18)Riksdagsmonitor is freely available, non-commercial, no revenue model
    Commercial distribution triggers CRA (Art. 16(1))If Riksdagsmonitor is commercialized (API subscriptions), CRA obligations apply in full
    Steward provisionsHack23 AB acts as open source steward
    Vulnerability handling (Art. 16(2))Security policy (SECURITY.md) and coordinated disclosure required even for OSS
    Security advisoriesPublic security advisories for known vulnerabilities

    Compliance Strategy: Maintain full CRA technical documentation now, enabling smooth transition to formal commercial compliance when API tier launches in 2027.


    The following template will be formalized upon entry into EU commercial distribution:

    EU DECLARATION OF CONFORMITY
    Riksdagsmonitor - Version [X.Y]

    Hack23 AB (Org.nr 5595347807)
    Sweden

    This declaration of conformity is issued under the sole responsibility
    of the manufacturer.

    Product: Riksdagsmonitor - Swedish Parliamentary Transparency Platform
    Version: [X.Y]
    Description: Web-based civic technology platform providing access to
    Swedish Riksdag parliamentary data, voting records, and AI-generated
    political news in 14 languages.

    Conformity Assessment Method: Module A (Self-Assessment)
    Product Category: Standard product with digital elements
    Annex III/IV Category: Not applicable

    The object of the declaration described above is in conformity with
    the relevant Union harmonisation legislation:

    Regulation (EU) 2024/2847 - Cyber Resilience Act
    - Annex I Part I: Essential cybersecurity requirements (13/13 compliant)
    - Annex I Part II: Vulnerability handling requirements (7/8 compliant)
    - Annex V: Technical documentation available at:
    github.com/Hack23/riksdagsmonitor/blob/main/CRA-ASSESSMENT.md

    Signed for and on behalf of: James Pether Sorling, CEO
    Date: [To be completed upon formal market placement]
    Place: Sweden

    ๐Ÿ“‹ Document Control: โœ… Approved by: James Pether Sรถrling, CEO ๐Ÿ“ค Distribution: Public ๐Ÿท๏ธ Classification: Confidentiality: Public๐Ÿ“… Effective Date: 2026-05-06 โฐ Next Review: 2026-08-06 ๐ŸŽฏ CRA Alignment: Follows CRA Conformity Assessment Process template โ€” supports CRA Annex V technical documentation and self-assessment requirements ๐Ÿ”“ OSS Alignment: Conforms with Open Source Policy โ€” governance artifacts, security posture evidence, license compliance ๐Ÿข ISMS Integration: Comprehensive alignment with public ISMS framework for operational excellence ๐ŸŽฏ Framework Compliance: ISO 27001NIST CSF 2.0CIS Controls


    Effective: 2026-04-24 ยท Authoritative hub: analysis/imf/README.md ยท analysis/imf/agentic-integration.md ยท analysis/imf/indicators-inventory.json ยท analysis/imf/data-dictionary.md ยท .github/aw/ECONOMIC_DATA_CONTRACT.md

    AttributeValue
    Service nameInternational Monetary Fund โ€” Public APIs (Datamapper REST + SDMX 3.0)
    VendorInternational Monetary Fund (IGO; not a commercial vendor)
    Hostnames (egress allow-list)www.imf.org, api.imf.org
    AuthenticationDatamapper: none (anonymous public API) ยท SDMX 3.0: Azure APIM subscription key (Ocp-Apim-Subscription-Key / IMF_SDMX_SUBSCRIPTION_KEY) โ€” gates throttle/quota only; payloads are public
    Data classification consumedPUBLIC macro/fiscal/monetary/external statistics; no PII
    Data flow directionInbound only (read-only)
    Rate limit~30 req/min observed; self-imposed โ‰ค30 req/min with back-off
    RedundancyTwo endpoints (Datamapper + SDMX) for the same underlying data
    CacheVintage-tagged in analysis/imf/ + analysis/daily/*/economic-data.json
    IntegritySHA-256 payload pin + supersedes-chain
    Vendor security postureIMF Open Data โ€” published rate limits, public terms, no auth surface
    LicenceAttribution required; redistribution permitted with citation
    CRA risk classLow (read-only, public, no PII, no credentials)
    CRA conformity decisionSelf-assessment Annex V โ€” no notified body required
    • Eliminates a credential-management surface that a commercial economic-data provider would introduce
    • Eliminates a supply-chain dependency on a single commercial vendor
    • Eliminates GDPR DPIA scope (no PII)
    • Provides redundancy via two independent endpoints (Datamapper + SDMX)

    Egress hosts (allow-list): www.imf.org (Datamapper REST ยท WEO/FM, unauthenticated), api.imf.org (SDMX 3.0 REST ยท IFS/BOP/DOTS/GFS/PCPS/ER/MFS_IR/MFS_PR, subscription-key authenticated via the Azure APIM Ocp-Apim-Subscription-Key header / IMF_SDMX_SUBSCRIPTION_KEY secret). Both HTTPS-only; payloads are public macro statistics with no PII.

    Canonical rule. Every economic claim in a Riksdagsmonitor article cites an IMF dataflow first; World Bank citations are reserved for governance, environment and social residue (the classes IMF does not publish). SCB is the Swedish-specific ground truth layer. See ECONOMIC_DATA_CONTRACT.md v2.1 for the banned-phrase list and vintage discipline (>6 mo โ†’ annotation).


    ๐ŸŒ Platforms๐Ÿ“ฆ Open-Source Projects๐Ÿ›ก๏ธ Governance & Standards
    ๐Ÿ—ณ๏ธ Riksdagsmonitor โ€” Swedish Parliament intelligence
    ๐Ÿ‡ช๐Ÿ‡บ EU Parliament Monitor โ€” European coverage
    ๐Ÿ•ต๏ธ Citizen Intelligence Agency โ€” political-data engine
    ๐ŸŒ Hack23 AB โ€” corporate site
    ๐Ÿ“ฐ Hack23 Blog โ€” engineering & policy
    ๐Ÿ’ผ Hack23 on LinkedIn
    ๐Ÿ—ณ๏ธ Hack23/riksdagsmonitor
    ๐Ÿ•ต๏ธ Hack23/cia
    ๐Ÿ‡ช๐Ÿ‡บ Hack23/euparliamentmonitor
    ๐Ÿ”Œ Hack23/european-parliament-mcp
    โœ… Hack23/cia-compliance-manager
    ๐Ÿฅ‹ Hack23/black-trigram
    ๐Ÿ  Hack23/homepage
    ๐Ÿ›ก๏ธ Hack23 ISMS-PUBLIC โ€” public ISMS
    ๐Ÿ”’ Information Security Policy
    ๐Ÿค– AI Policy
    ๐Ÿงช Secure Development Policy
    ๐ŸŽฏ Threat Modeling Policy
    โš ๏ธ Vulnerability Management
    ๐Ÿท๏ธ Classification Framework

    OpenSSF Best PracticesOpenSSF ScorecardISO 27001:2022NIST CSF 2.0CIS Controls v8.1Apache 2.0

    ๐Ÿ—ณ๏ธ Empower citizens ยท ๐Ÿ” Strengthen democratic accountability ยท ๐Ÿ•ต๏ธ Illuminate the political process

    ยฉ 2008โ€“2026 Hack23 AB (Org.nr 559534-7807) ยท Maintainer: James Pether Sรถrling, CISSP CISM