Security Controls MCP
An MCP server based on the Security Controls Framework (SCF), providing two-way mapping and search functions for 1,451 security control items across 262 compliance frameworks (including ISO 27001, NIST CSF, DORA, AI governance standards, etc.), enabling AI assistants to directly query and associate the requirements of different security standards.
rating : 2.5 points
downloads : 6.2K
What is the Security Controls MCP Server?
This is a server based on the Model Context Protocol (MCP), specifically designed for the mapping and querying of security control frameworks. It integrates 1,451 security control items from the Secure Controls Framework (SCF) database, covering 262 different security standards and regulatory frameworks. Through this server, AI assistants (such as Claude) can directly query and map the corresponding relationships between different security frameworks, helping users understand complex compliance requirements.How to use the Security Controls MCP Server?
You can use it in three ways: 1) Connect directly to the hosted version (no installation required), 2) Install the local version via npm, 3) Integrate it into MCP-supported clients such as Claude Desktop, VS Code, or Cursor. The server provides various query tools, including searching for control items, obtaining framework details, and mapping different frameworks.Applicable scenarios
Suitable for security compliance professionals, IT auditors, risk management teams, security architects, and organizations that need to handle multi-framework compliance requirements. Particularly suitable for scenarios such as cross-framework compliance mapping, security control gap analysis, compliance assessment, and security control implementation planning.Main features
Comprehensive security control database
Contains 1,451 security control items, covering multiple areas such as governance, risk, compliance, and technology
Multi-framework mapping
Supports two-way mapping between 262 security frameworks, including ISO 27001, NIST CSF, DORA, PCI DSS, CMMC, etc.
AI governance framework support
Newly added mapping of AI governance frameworks such as ISO 42001, NIST AI RMF, and the EU AI Act
Natural language search
Supports using natural language queries instead of framework-specific IDs, such as 'Search for control items related to incident response'
Regional framework coverage
Contains security frameworks from more than 50 countries, such as the Dutch BIO, Finnish KATAKRI, Norwegian NSM, Swedish MSB, etc.
Optional standard integration
Supports importing official standard texts such as ISO and NIST that have been purchased, and using them in combination with SCF descriptions
Advantages
No need to memorize framework-specific IDs, you can query using natural language
A hosted version is provided, which can be used without local installation
Based on the authoritative Secure Controls Framework database
Supports integration with multiple clients (Claude, VS Code, Cursor, etc.)
Provides free publicly available national framework configuration files
Maintains data integrity, and control texts are directly returned from the SCF source
Limitations
It is not legal or compliance advice, and professional compliance personnel should be consulted
The SCF license prohibits the use of AI to generate derivative content based on SCF data
A valid license is required to import purchased standard texts
Not all control items can be mapped one-to-one between frameworks
Some advanced features require local installation and configuration
How to use
Choose the usage method
Decide whether to use the hosted version (no installation required) or the locally installed version. The hosted version is suitable for a quick start, while the local version is suitable for users who need custom configuration.
Configure the client
According to the client you are using (Claude Desktop, VS Code, Cursor, etc.), add the server to the configuration file.
Start querying
In the client integrated with MCP, use natural language to query security control items or framework mappings.
Optional: Import standards
If you need official standard texts, you can import purchased standard documents such as ISO and NIST.
Usage cases
Cross-framework compliance mapping
An organization needs to map existing ISO 27001 control items to new DORA compliance requirements to assess the gaps.
Search for control items in a specific area
A security team needs to identify all control items related to encryption key management to develop a key management strategy.
AI governance compliance assessment
A company needs to assess whether its AI system complies with the requirements of the EU AI Act and understand its correspondence with ISO 42001.
PCI DSS compliance check
A payment processing company needs to ensure that its security controls meet all the requirements of PCI DSS v4.0.1.
Frequently Asked Questions
Can this tool replace a compliance consultant?
What do I need to install to use the hosted version?
How reliable is the data source?
Can I generate policy documents based on the query results?
How do I import the ISO standards I have purchased?
Which clients are supported?
Related resources
Secure Controls Framework official website
The official website of the SCF framework, containing the complete data source and documentation
GitHub repository
The source code and issue tracking of the project
Model Context Protocol official website
The official documentation and specifications of the MCP protocol
Paid standard import guide
A detailed guide on how to import purchased standard documents such as ISO and NIST
Ansvar Systems official website
The official website of the project development company, containing other related MCP servers
Related MCP server projects
Other MCP server projects maintained by Ansvar Systems, such as EU Regulations MCP, US Regulations MCP, etc.

Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
34.2K
5 points

Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
24.4K
4.3 points

Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
71.7K
4.3 points

Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
20.4K
4.5 points

Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
31.0K
5 points

Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
64.3K
4.5 points

Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
47.4K
4.8 points

Context7
Context7 MCP is a service that provides real-time, version-specific documentation and code examples for AI programming assistants. It is directly integrated into prompts through the Model Context Protocol to solve the problem of LLMs using outdated information.
TypeScript
96.7K
4.7 points



