· intuitem · News  · 4 min read

What's New in CISO Assistant — Week 30, 2026 (v3.20.0 – v3.20.2)

The v3.20 cycle lands: a new technical posture management capability, a library builder, single logout for OIDC and SAML, GDPR processing export/import, CyFun 2025 import, the ABDO 2019 framework, and complete Czech localization.

The v3.20 cycle lands: a new technical posture management capability, a library builder, single logout for OIDC and SAML, GDPR processing export/import, CyFun 2025 import, the ABDO 2019 framework, and complete Czech localization.

After a quiet week 29, the v3.20 cycle arrived in force: the v3.20.0 minor release landed on July 21, followed the same evening by the v3.20.1 hotfix (which repaired a broken enterprise-edition build pipeline) and the v3.20.2 patch on July 22. Together they bring a brand-new technical posture management capability, a library builder, single logout for SSO, and a healthy round of framework, localization, and quality updates.

Headline Features

  • Technical posture management — A new epic introduces technical posture management, connecting your technical security signals to your governance work (PR #4513), with documentation (PR #4546) and an IAM hardening pass with extra tests following in v3.20.2 (PR #4554). Thanks to @ab-smith.
  • Library builder — A new library builder makes it much easier to author custom frameworks and libraries, from the initial spike (PR #4498) through documentation (PR #4511) to a polish pass that adds requirement weight support (PR #4543). Thanks to @eric-intuitem and @ab-smith.
  • Single logout (SLO) for OIDC and SAML — Logging out of CISO Assistant can now propagate to your identity provider for both OIDC and SAML authentication (PR #4496). Thanks to @tchoumi313.

New Features

  • GDPR processing full export/import — GDPR processing records can now be fully exported and re-imported (PR #4548). Thanks to @ab-smith.
  • CyFun 2025 Excel import — Assessments in the CyberFundamentals (CyFun) 2025 Excel format can now be imported directly (PR #4553). Thanks to @ab-smith.
  • Change the domain of an EBIOS-RM study — EBIOS-RM studies are no longer locked to the domain they were created in (PR #4502). Thanks to @eric-intuitem.
  • CLI domain export — The CLI gains a domain export capability for scripted backups and migrations (PR #4522). Thanks to @ab-smith.
  • Domain managers can edit group members — Group membership can now be managed at the domain-manager level, not just by administrators (PR #4512). Thanks to @eric-intuitem.
  • MCP access to maturity scores — The AI/MCP integration can now read maturity scores, opening them up to assistant-driven analysis (PR #4516). Thanks to @eric-intuitem.

Framework & Library Updates

  • ABDO 2019 — Added the Dutch Ministry of Defence’s ABDO 2019 (Algemene Beveiligingseisen voor Defensieopdrachten) framework, bilingual (Dutch/English) with 435 assessable requirements and the TBB1–TBB4 classification levels modelled as implementation groups (PR #4534). Thanks to @Mohamed-Hacene.
  • MITRE ATT&CK v19.1 — Updated the MITRE ATT&CK library to v19.1 (PR #4514). Thanks to @tarkadia.
  • PART-IS.D.OR completed, with a French version — Added missing requirements to the PART-IS.D.OR framework and shipped a French translation (PR #4529). Thanks to @tarkadia.
  • DORA RoI parameters cleanup — Removed unreferenced decimals parameters from the DORA RoI parameters.csv (PR #4501). Thanks to @mvanhorn.
  • Safer framework updates — Framework updates now correctly handle removed requirement fields and implementation groups (PR #4494). Thanks to @tarkadia.

Internationalization

  • Complete Czech localization — A full update of the Czech translation (PR #4520). Thanks to @zdenek-pergl.
  • Improved Dutch translations — Two rounds of Dutch translation improvements (PRs #4508, #4518). Thanks to @ReViCo-be.

UX & Bug Fixes

  • Reworked audit progress calculation — Audit progress is now computed more accurately, with accompanying documentation explaining the formula (PRs #4517, #4558). Thanks to @Mohamed-Hacene.
  • Risk acceptances in My Assignments (Pro) — Risk acceptances now show up in the my-assignments view (PR #4521). Thanks to @Mohamed-Hacene.
  • Consistent edit/delete actions — The frontend now shows edit and delete actions consistently across objects (PR #4507). Thanks to @eric-intuitem.
  • Classification labels — Object classifications now display their name instead of a raw label (PR #4539). Thanks to @tchoumi313.
  • Longer URLs accepted — Increased the maximum URL length on link fields (PR #4524). Thanks to @eric-intuitem.
  • Simplified user picker — The user picker modal has been streamlined (PR #4527). Thanks to @eric-intuitem.
  • Consistent markdown fields — All markdown fields were rationalized to fix rendering discrepancies (PR #4519). Thanks to @eric-intuitem.
  • Document template locale filter — Fixed the locale filter not updating on document templates (PR #4532). Thanks to @tarkadia.
  • Custom libraries migration hotfix — Fixed a migration issue affecting custom libraries on PostgreSQL (PR #4556). Thanks to @ab-smith.
  • Docker scripts harmonization — A broad cleanup and harmonization of the Docker scripts and files (PR #4442). Thanks to @tarkadia.

Welcome to new contributor @ReViCo-be, who made their first contribution in v3.20.0. For full details, check out the v3.20.0, v3.20.1, and v3.20.2 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 31, 2026 (v3.20.3 – v3.20.4)

What's New in CISO Assistant — Week 31, 2026 (v3.20.3 – v3.20.4)

A native Power BI connector ships as a signed, standalone artifact, third-party risk management joins domain export/import, posture management gains observations and attachments, and the AI chat learns to import spreadsheets. Plus the TISAX v2027 and ENISA SME cyber resilience frameworks, Slovenian localization, and an IAM hardening fix.

What's New in CISO Assistant — Week 28, 2026 (v3.19.2)

What's New in CISO Assistant — Week 28, 2026 (v3.19.2)

A feature-rich patch: a reworked risk acceptance workflow, the NCA ECC-2:2024 framework, evidence on data breaches, expanded document management, ServiceNow asset sync, broader audit-log coverage, Slovak localization, and a long list of fixes.