v1.6.0 / v1.6.1 — 2026-07-03
Governance release: eval-credibility infrastructure, currency guardrails, five skill
expansions, benchmark re-run extended to 12 of 30 skills with primary-source assertions —
and remediation of every skill that scored below baseline. All 30 plugins at 1.6.1.
Benchmark — suite headline: 94% with skills vs 81% baseline (705/612 of 752, +13 pts)
- Assertions for re-run skills authored from primary sources (regulation text, official
notices) — never from skill content; post-cutoff facts embedded for graders. - Re-run in 1.6.0: NIS2 100%/84% (+16, expansion validated), EU AI Act 92%/72% (+20),
VN-PDPL 68%/60% (+8), EU CRA 80%/80% — plus four honest negative deltas. - Remediated in 1.6.1 (skills revised against exact graded failures, same assertions,
both arms re-run): CCPA/CPRA 100%/80% (+20, was −16); NZISM 96%/64% (+32, was −4);
NIST AI RMF 92%/84% (+8, was −4); CMMC 88%/80% (+8, was −8). No skill below baseline. - First committed grading artifacts for NZISM, VN-PDPL, EU CRA — all 30 skills now
have machine-checkable eval artifacts (grc-workspace/rerun-2026-07b, -07c).
Skill content
- Expanded five thinnest skills (NIS2 82→~190 lines incl. the Art. 3 essential-vs-important
size-cap test; EU AI Act deployer duties Art. 26 + FRIA Art. 27 + Annex III area guidance;
CCPA/CPRA full rights workflows; CMMC level/SPRS/scoping/assessment readiness;
NIST AI RMF categories, risk-register template, profiles). - 1.6.1 hardening: CMMC DFARS clause family (7012/7019/7020/7021) + conditional-certification
math (≥88 + all-1-point gate) + flow-down remediation menu; CCPA tiered verification
(§§7060–7062), 10-business-day acknowledgment, categorical §7050(c) CCBA rule,
notice-at-collection as a named GDPR-gap item; NIST AI RMF Playbook/voluntary framing,
SR 11-7 mapping, GOVERN mini-templates; NZISM verified control-ID reference
(never-invent-a-CID rule), offshore/cloud approval-chain workflow, SRMP in C&A. - Fixes: CCPA precise-geolocation radius corrected to 1,850 ft (§1798.140) and
right-to-know lookback to the §1798.130(a)(2)(B) formulation; CMMC POA&M rule
sharpened to 1-point eligibility with the 88 floor.
Guardrails & process
- Every SKILL.md now carries a Last-verified date and a standard not-legal-advice
disclaimer; new CI tests fail stale (>120 days), relative-time language, or missing
disclaimers; quarterly review checklist with per-framework primary sources documented. - New summary-block consistency tests: suite stats identical across all three pages,
deltas arithmetically derived, per-skill cells sum to published totals, and any
negative delta must be explicitly acknowledged (allowance currently empty).
Caught and fixed a live bug on day one (GDPR cell 25/25 next to 88% → 22/25). - Eval integrity: 3 grader judgments amended with documented notes after verification
(Decree 356/2025/ND-CP is real); 2 assertion-writer errors acknowledged; grader-flagged
assertions reviewed against primary sources and upheld.