· intuitem · News · 4 min read
What's New in CISO Assistant — Week 30, 2026 (v3.20.0 – v3.20.2)
The v3.20 cycle lands: a new technical posture management capability, a library builder, single logout for OIDC and SAML, GDPR processing export/import, CyFun 2025 import, the ABDO 2019 framework, and complete Czech localization.
After a quiet week 29, the v3.20 cycle arrived in force: the v3.20.0 minor release landed on July 21, followed the same evening by the v3.20.1 hotfix (which repaired a broken enterprise-edition build pipeline) and the v3.20.2 patch on July 22. Together they bring a brand-new technical posture management capability, a library builder, single logout for SSO, and a healthy round of framework, localization, and quality updates.
Headline Features
- Technical posture management — A new epic introduces technical posture management, connecting your technical security signals to your governance work (PR #4513), with documentation (PR #4546) and an IAM hardening pass with extra tests following in v3.20.2 (PR #4554). Thanks to @ab-smith.
- Library builder — A new library builder makes it much easier to author custom frameworks and libraries, from the initial spike (PR #4498) through documentation (PR #4511) to a polish pass that adds requirement weight support (PR #4543). Thanks to @eric-intuitem and @ab-smith.
- Single logout (SLO) for OIDC and SAML — Logging out of CISO Assistant can now propagate to your identity provider for both OIDC and SAML authentication (PR #4496). Thanks to @tchoumi313.
New Features
- GDPR processing full export/import — GDPR processing records can now be fully exported and re-imported (PR #4548). Thanks to @ab-smith.
- CyFun 2025 Excel import — Assessments in the CyberFundamentals (CyFun) 2025 Excel format can now be imported directly (PR #4553). Thanks to @ab-smith.
- Change the domain of an EBIOS-RM study — EBIOS-RM studies are no longer locked to the domain they were created in (PR #4502). Thanks to @eric-intuitem.
- CLI domain export — The CLI gains a domain export capability for scripted backups and migrations (PR #4522). Thanks to @ab-smith.
- Domain managers can edit group members — Group membership can now be managed at the domain-manager level, not just by administrators (PR #4512). Thanks to @eric-intuitem.
- MCP access to maturity scores — The AI/MCP integration can now read maturity scores, opening them up to assistant-driven analysis (PR #4516). Thanks to @eric-intuitem.
Framework & Library Updates
- ABDO 2019 — Added the Dutch Ministry of Defence’s ABDO 2019 (Algemene Beveiligingseisen voor Defensieopdrachten) framework, bilingual (Dutch/English) with 435 assessable requirements and the TBB1–TBB4 classification levels modelled as implementation groups (PR #4534). Thanks to @Mohamed-Hacene.
- MITRE ATT&CK v19.1 — Updated the MITRE ATT&CK library to v19.1 (PR #4514). Thanks to @tarkadia.
- PART-IS.D.OR completed, with a French version — Added missing requirements to the PART-IS.D.OR framework and shipped a French translation (PR #4529). Thanks to @tarkadia.
- DORA RoI parameters cleanup — Removed unreferenced decimals parameters from the DORA RoI
parameters.csv(PR #4501). Thanks to @mvanhorn. - Safer framework updates — Framework updates now correctly handle removed requirement fields and implementation groups (PR #4494). Thanks to @tarkadia.
Internationalization
- Complete Czech localization — A full update of the Czech translation (PR #4520). Thanks to @zdenek-pergl.
- Improved Dutch translations — Two rounds of Dutch translation improvements (PRs #4508, #4518). Thanks to @ReViCo-be.
UX & Bug Fixes
- Reworked audit progress calculation — Audit progress is now computed more accurately, with accompanying documentation explaining the formula (PRs #4517, #4558). Thanks to @Mohamed-Hacene.
- Risk acceptances in My Assignments (Pro) — Risk acceptances now show up in the my-assignments view (PR #4521). Thanks to @Mohamed-Hacene.
- Consistent edit/delete actions — The frontend now shows edit and delete actions consistently across objects (PR #4507). Thanks to @eric-intuitem.
- Classification labels — Object classifications now display their name instead of a raw label (PR #4539). Thanks to @tchoumi313.
- Longer URLs accepted — Increased the maximum URL length on link fields (PR #4524). Thanks to @eric-intuitem.
- Simplified user picker — The user picker modal has been streamlined (PR #4527). Thanks to @eric-intuitem.
- Consistent markdown fields — All markdown fields were rationalized to fix rendering discrepancies (PR #4519). Thanks to @eric-intuitem.
- Document template locale filter — Fixed the locale filter not updating on document templates (PR #4532). Thanks to @tarkadia.
- Custom libraries migration hotfix — Fixed a migration issue affecting custom libraries on PostgreSQL (PR #4556). Thanks to @ab-smith.
- Docker scripts harmonization — A broad cleanup and harmonization of the Docker scripts and files (PR #4442). Thanks to @tarkadia.
Welcome to new contributor @ReViCo-be, who made their first contribution in v3.20.0. For full details, check out the v3.20.0, v3.20.1, and v3.20.2 release notes on GitHub.