· intuitem · News  · 4 min read

What's New in CISO Assistant — Week 30, 2026 (v3.20.0 – v3.20.2)

The v3.20 cycle lands: a new technical posture management capability, a library builder, single logout for OIDC and SAML, GDPR processing export/import, CyFun 2025 import, the ABDO 2019 framework, and complete Czech localization.

The v3.20 cycle lands: a new technical posture management capability, a library builder, single logout for OIDC and SAML, GDPR processing export/import, CyFun 2025 import, the ABDO 2019 framework, and complete Czech localization.

After a quiet week 29, the v3.20 cycle arrived in force: the v3.20.0 minor release landed on July 21, followed the same evening by the v3.20.1 hotfix (which repaired a broken enterprise-edition build pipeline) and the v3.20.2 patch on July 22. Together they bring a brand-new technical posture management capability, a library builder, single logout for SSO, and a healthy round of framework, localization, and quality updates.

Headline Features

  • Technical posture management — A new epic introduces technical posture management, connecting your technical security signals to your governance work (PR #4513), with documentation (PR #4546) and an IAM hardening pass with extra tests following in v3.20.2 (PR #4554). Thanks to @ab-smith.
  • Library builder — A new library builder makes it much easier to author custom frameworks and libraries, from the initial spike (PR #4498) through documentation (PR #4511) to a polish pass that adds requirement weight support (PR #4543). Thanks to @eric-intuitem and @ab-smith.
  • Single logout (SLO) for OIDC and SAML — Logging out of CISO Assistant can now propagate to your identity provider for both OIDC and SAML authentication (PR #4496). Thanks to @tchoumi313.

New Features

  • GDPR processing full export/import — GDPR processing records can now be fully exported and re-imported (PR #4548). Thanks to @ab-smith.
  • CyFun 2025 Excel import — Assessments in the CyberFundamentals (CyFun) 2025 Excel format can now be imported directly (PR #4553). Thanks to @ab-smith.
  • Change the domain of an EBIOS-RM study — EBIOS-RM studies are no longer locked to the domain they were created in (PR #4502). Thanks to @eric-intuitem.
  • CLI domain export — The CLI gains a domain export capability for scripted backups and migrations (PR #4522). Thanks to @ab-smith.
  • Domain managers can edit group members — Group membership can now be managed at the domain-manager level, not just by administrators (PR #4512). Thanks to @eric-intuitem.
  • MCP access to maturity scores — The AI/MCP integration can now read maturity scores, opening them up to assistant-driven analysis (PR #4516). Thanks to @eric-intuitem.

Framework & Library Updates

  • ABDO 2019 — Added the Dutch Ministry of Defence’s ABDO 2019 (Algemene Beveiligingseisen voor Defensieopdrachten) framework, bilingual (Dutch/English) with 435 assessable requirements and the TBB1–TBB4 classification levels modelled as implementation groups (PR #4534). Thanks to @Mohamed-Hacene.
  • MITRE ATT&CK v19.1 — Updated the MITRE ATT&CK library to v19.1 (PR #4514). Thanks to @tarkadia.
  • PART-IS.D.OR completed, with a French version — Added missing requirements to the PART-IS.D.OR framework and shipped a French translation (PR #4529). Thanks to @tarkadia.
  • DORA RoI parameters cleanup — Removed unreferenced decimals parameters from the DORA RoI parameters.csv (PR #4501). Thanks to @mvanhorn.
  • Safer framework updates — Framework updates now correctly handle removed requirement fields and implementation groups (PR #4494). Thanks to @tarkadia.

Internationalization

  • Complete Czech localization — A full update of the Czech translation (PR #4520). Thanks to @zdenek-pergl.
  • Improved Dutch translations — Two rounds of Dutch translation improvements (PRs #4508, #4518). Thanks to @ReViCo-be.

UX & Bug Fixes

  • Reworked audit progress calculation — Audit progress is now computed more accurately, with accompanying documentation explaining the formula (PRs #4517, #4558). Thanks to @Mohamed-Hacene.
  • Risk acceptances in My Assignments (Pro) — Risk acceptances now show up in the my-assignments view (PR #4521). Thanks to @Mohamed-Hacene.
  • Consistent edit/delete actions — The frontend now shows edit and delete actions consistently across objects (PR #4507). Thanks to @eric-intuitem.
  • Classification labels — Object classifications now display their name instead of a raw label (PR #4539). Thanks to @tchoumi313.
  • Longer URLs accepted — Increased the maximum URL length on link fields (PR #4524). Thanks to @eric-intuitem.
  • Simplified user picker — The user picker modal has been streamlined (PR #4527). Thanks to @eric-intuitem.
  • Consistent markdown fields — All markdown fields were rationalized to fix rendering discrepancies (PR #4519). Thanks to @eric-intuitem.
  • Document template locale filter — Fixed the locale filter not updating on document templates (PR #4532). Thanks to @tarkadia.
  • Custom libraries migration hotfix — Fixed a migration issue affecting custom libraries on PostgreSQL (PR #4556). Thanks to @ab-smith.
  • Docker scripts harmonization — A broad cleanup and harmonization of the Docker scripts and files (PR #4442). Thanks to @tarkadia.

Welcome to new contributor @ReViCo-be, who made their first contribution in v3.20.0. For full details, check out the v3.20.0, v3.20.1, and v3.20.2 release notes on GitHub.

Back to Blog

Related Posts

View All Posts »
What's New in CISO Assistant — Week 28, 2026 (v3.19.2)

What's New in CISO Assistant — Week 28, 2026 (v3.19.2)

A feature-rich patch: a reworked risk acceptance workflow, the NCA ECC-2:2024 framework, evidence on data breaches, expanded document management, ServiceNow asset sync, broader audit-log coverage, Slovak localization, and a long list of fixes.