ProofLayer: Control Coverage Screening for Government Cybersecurity Policies via Multi-LLM Orchestration
DOI:
https://doi.org/10.65879/3070-5789.2026.02.07Keywords:
Cybersecurity policy analysis, control coverage screening, NIST SP 800-53, government cybersecurity, keyword matching, measurement validity, large language models, MarylandAbstract
ProofLayer is a two-stage system for screening government cybersecurity policy documents against control catalogues: a keyword stage that maps policy text to a twenty-two control set crosswalked to NIST SP 800-53 Revision 5, and a language-model stage intended to resolve the cases keyword matching cannot, with a cost-aware orchestration layer routing between models. This paper evaluates the first stage on ten Maryland state and local government policy documents and separates what is measured from what is only described. Reading each document in full gives a mean control coverage of 62.8 percent (standard deviation 24.1). An earlier analysis of this corpus truncated each document at fifteen pages and reported 49.1 percent; seven of the ten documents exceed fifteen pages, and the two longest gain 36 and 41 points when read in full. Both figures are reported, because a screening metric that moves this far with extraction depth is itself informative. Coverage correlates with document length at against log word count, so 48 percent of its variance is explained by length alone. Of 138 covered document-control pairs, 18.1 percent carry a negation cue within 130 characters of the match and 44.2 percent rest on a single keyword out of a mean 6.1 available. A worked error analysis gives four cases, among them a footnote URL scored as transport encryption and an incident-reporting requirement carrying a two-business-day deadline scored as absent because the keyword list lacked the word notifying. The second-stage classifier is described but not evaluated: establishing whether it resolves these failures requires expert-annotated ground truth for this corpus, which does not yet exist, and model-generated labels are declined as a substitute. The orchestration cost saving is a token-price projection rather than instrumented spend. We therefore report policy-vocabulary coverage, not compliance, and release all 220 document-control pairs with matched keywords and text snippets.
References
[1] Maryland Cybersecurity Council. Maryland Cybersecurity Council biennial activities report. Adelphi (MD): University of Maryland Global Campus; 2025. Available from: https://www.umgc.edu/mdcybersecuritycouncil
[2] Ad Hoc Committee on State and Local Cybersecurity, Maryland Cybersecurity Council. Maryland state and local government cybersecurity: analysis and recommendations. Adelphi (MD): University of Maryland Global Campus; 2021. Available from: https://www.umgc.edu/content/dam/umgc/documents/upload/maryland-state-and-local-government-cybersecurity-analysis-and-recommendations.pdf
[3] Joint Task Force. Security and privacy controls for information systems and organizations. Gaithersburg (MD): National Institute of Standards and Technology; 2020. Report No.: NIST SP 800-53 Rev. 5. Includes updates as of 10 December 2020. doi:10.6028/NIST.SP.800-53r5
[4] FedRAMP Program Management Office. FedRAMP authorization boundary guidance. Washington (DC): U.S. General Services Administration; 2022. Rescinded and replaced by the FedRAMP Minimum Assessment Scope standard, 2025. Available from: https://www.fedramp.gov/
[5] Office of the Under Secretary of Defense for Acquisition and Sustainment. Cybersecurity Maturity Model Certification (CMMC) model overview, version 2.0. Washington (DC): U.S. Department of Defense; 2021. Superseded in part by the CMMC Program final rule, 32 CFR Part 170, effective 16 December 2024. Available from: https://dodcio.defense.gov/CMMC/
[6] Hassani S, Sabetzadeh M, Amyot D, Liao J. Rethinking legal compliance automation: opportunities with large language models. In: Proceedings of the 32nd IEEE International Requirements Engineering Conference (RE). Piscataway (NJ): IEEE; 2024. p. 432–40. doi:10.1109/RE59067.2024.00051
[7] Oh Huan Lin, Jay Yong Jun Jie, Mandy Lee Ling Siu, Jonathan Pan. Automated post-incident policy gap analysis via threat-informed evidence mapping using large language models. arXiv:2601.03287 [preprint]. 2026. Available from: https://arxiv.org/abs/2601.03287
[8] Guo D, Wu J, Yiu SM. ComplianceNLP: knowledge-graph-augmented RAG for multi-framework regulatory gap detection. arXiv:2604.23585 [preprint]. 2026. Available from: https://arxiv.org/abs/2604.23585
[9] Kumar B, Roussinov D. NLP-based regulatory compliance: using GPT-4.0 to decode regulatory documents. In: Proceedings of the Georg Nemetschek Institute Symposium on Artificial Intelligence for the Built World; 2024. Available from: https://arxiv.org/abs/2412.20602
[10] Maryland Department of Information Technology. State minimum cybersecurity standards best practices guidebook [Internet]. Annapolis (MD): Maryland Department of Information Technology; 2023 [cited 2026 Jun]. Available from: https://doit.maryland.gov/policies/ci/Pages/state-minimum-cybersecurity-standards-best-practices-guidebook.aspx
[11] Motlagh FN, Hajizadeh M, Majd M, Najafi P, Cheng F, Meinel C. Large language models in cybersecurity: state-of-the-art. arXiv:2402.00891 [preprint]. 2024. Available from: https://arxiv.org/abs/2402.00891
[12] Salman A, Creese S, Goldsmith M. Position paper: leveraging large language models for cybersecurity compliance. In: Proceedings of the IEEE European Symposium on Security and Privacy Workshops. Piscataway (NJ): IEEE; 2024. p. 496–503.
[13] Qian C, et al. xRouter: training cost-aware LLMs orchestration system via reinforcement learning. arXiv:2510.08439 [preprint]. 2025. Available from: https://arxiv.org/abs/2510.08439
[14] Kulkarni S, Kulkarni Y. Benchmarking multi-agent LLM architectures for financial document processing: a comparative study of orchestration patterns, cost-accuracy tradeoffs and production scaling strategies. arXiv:2603.22651 [preprint]. 2026. Available from: https://arxiv.org/abs/2603.22651
[15] Singer-Vine J. pdfplumber: plumb a PDF for detailed information about each char, rectangle, line, and so on, and easily extract text and tables [Internet]. 2024 [cited 2026 Jun]. Available from: https://github.com/jsvine/pdfplumber
[16] ReportLab Inc. ReportLab PDF library [Internet]. 2024 [cited 2026 Jun]. Available from: https://www.reportlab.com/
[17] Trivedi D. Benchmarking municipal cybersecurity readiness through automated policy analytics: evidence from Maryland local governments. J Comput Sci Coll. 2026;42(3). In press. Presented at the CCSC Eastern Conference 2026.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Devharsh Trivedi (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.