NIST
NIST-style reporting supports risk and control mapping (commonly aligned to Identify/Protect/Detect/Respond/Recover).
DevSecOps Bot by Sttor Outputs
- Risk summaries by severity, repo, branch, and time
- Evidence from scans that map into secure development + vulnerability management controls
- Exception handling evidence (accepted risk tracked separately)