OWASP has the SVCS project (1) that may be insightful to map alongside the OSPS Baseline controls. CRob should look into this someday. (1) - https://scvs.owasp.org/scvs/