Secani
Secani
  • Company
  • Roadmap
Request demo

Summarize with AI

Open in ChatGPTOpen in ClaudeOpen in PerplexityOpen in MistralOpen in Grok
SIBB Startups
Berlin
Co-funded by the European Union
Secani

Jonathan Bezdek

Wörther Straße 9

10435 Berlin


hello@secani.com

Product

  • Security
  • Roadmap
  • Documentation
  • OSCAL

Legal

  • Privacy Policy
  • Terms
  • Cookie settings
  • Legal Notice

Company

  • Company
  • Contact
  • Blog

Support

  • Help

Blog

July 28, 20269 min

CMMC Phase 2 is suspended. Phase 1 obligations remain.

Phase 2 is suspended, but CMMC and the underlying DFARS security obligations have not disappeared. Contractors should verify current solicitations, assessment designations, SPRS records, and data flows.

RegulatoryCMMC-Compliance
July 26, 20268 min

Beyond Spreadsheet Crosswalks

OLIR provides mapping content and governance. OSCAL provides the machine-readable structure for using those mappings in gap analysis, evidence reuse, and change-impact workflows.

OSCALCompliance automation
July 19, 20268 min

We counted every constraint in OSCAL 1.2.2. All 348 of them.

Every OSCAL validator claims to validate OSCAL. We enumerated all 348 constraint occurrences in the NIST sources, proved or excluded each one, and then ran the comparison against the Java CLI for real.

OSCALOSCAL-Validierung
July 18, 20266 min

NIS2: Germany's grace period is ending

Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.

RegulatoryNIS2-Compliance
July 17, 20267 min

IT-Grundschutz++ meets OSCAL

With the Stand-der-Technik-Bibliothek, IT-Grundschutz leaves the PDF behind: IT-Grundschutz++ ships as an OSCAL catalog – changing how ISMS work is organized.

IT baseline protectionFramework-Migration
July 16, 20266 min

FedRAMP goes machine-readable

With RFC-0024 and the Consolidated Rules 2026, FedRAMP makes structured authorization data mandatory. The deadlines are staggered – the direction is unambiguous.

OSCALAudit-Readiness
July 15, 20268 min

The OSCAL tools landscape

The OSCAL ecosystem is growing fast: viewing and validating are well covered, while authoring and day-to-day workflows remain the biggest gap.

OSCALCompliance automation
July 14, 20267 min

What is OSCAL?

OSCAL turns compliance documents into structured data: eight document models, three formats, and an ecosystem that is becoming the standard for regulation.

OSCALCompliance automation
June 6, 20265 min

Redefining Compliance

Compliance should not be a reporting project at the end. It should be a living system of trust for teams that need structure, speed, and control.

ISMSCompliance workspace
June 6, 20265 min

AI-native Compliance

AI-native compliance means importing existing evidence, understanding context, finding gaps, reviewing outputs, and keeping humans in control where judgment matters.

AI governanceCompliance automation