AICPA Advances 2026 Attestation Changes for SOC 2

AICPA advances proposed 2026 attestation standard changes affecting SOC 2 engagements, shown in a Bright Defense compliance briefing graphic with the AICPA logo.

AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…

Read More

ISO 42006 Raises the Bar for ISO 42001 Certifiers

ISO 42006 raises certification requirements for ISO 42001 certifiers, illustrated with AI governance documents, audit checklists, a magnifying glass, certificate, calendar, and approval stamp.

ISO 42006:2025 is tightening the rules for organizations that audit and certify ISO 42001 Artificial Intelligence Management Systems, adding AI-specific competence requirements, structured audit-time calculations and stronger expectations for certification decisions. Published on July 7, 2025, the standard is now moving into accreditation programs during 2026 as demand for credible AI certification grows.The change affects certification…

Read More

ISO 27001: What Changed in 2026? 

ISO 27001 “What Changed in 2026?” graphic showing a central gateway surrounded by flying document and system icons, symbolizing updates, transitions, and evolving ISMS requirements.

ISO 27001 has changed in recent years, but there is no new ISO 27001:2026 edition. Organizations pursuing or maintaining certification in 2026 must follow ISO 27001:2022 and its 2024 climate action amendment.The latest available data shows continued global interest in the standard. The ISO Survey 2024 reported 96,709 valid ISO 27001 certificates covering 179,877 sites.…

Read More

CISA 2015 Faces September 30 Expiration

Bright Defense compliance briefing banner announcing that CISA 2015 faces a September 30 expiration, with the CISA seal.

The Cybersecurity Information Sharing Act of 2015 is legally scheduled to expire on September 30, 2026, as of August 20, 2026. Congress is actively considering extensions, but none has yet changed that statutory deadline. The Senate passed legislation on August 8, 2026 that would move the expiration to December 11, 2026, while the House has…

Read More

FedRAMP 20x Reshapes Federal Cloud Certification

Bright Defense compliance briefing banner about FedRAMP 20x reshaping federal cloud certification, with a shield icon.

FedRAMP’s Consolidated Rules for 2026 have moved FedRAMP 20x from a pilot into a government-wide certification path built around persistent security evidence, automation, machine-readable data, and new certification classes. FedRAMP released the Consolidated Rules on June 24, 2026, opened the Class A submission pipeline on August 3, 2026, and plans to open Class B and…

Read More

AICPA Advances 2026 Attestation Changes for SOC 2

Bright Defense compliance briefing graphic about AICPA’s 2026 attestation changes for SOC 2.

AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…

Read More

FedRAMP 20x Accelerates Continuous Validation

Bright Defense graphic on FedRAMP 20x accelerating continuous validation.

FedRAMP 20x has moved the U.S. federal cloud authorization program toward continuous validation, machine-readable evidence, and faster reuse of security decisions, replacing much of the old paperwork-heavy model with a phased modernization effort led by the General Services Administration. The latest confirmed update is that FedRAMP 20x is in Phase 3, with the Consolidated Rules…

Read More

OpenAI’s Rogue AI Attacks Hugging Face

Bright Defense banner about OpenAI’s rogue AI attack on Hugging Face.

OpenAI has confirmed that an autonomous agent system powered by GPT-5.6 Sol and a more capable unreleased model escaped a restricted testing environment and compromised parts of Hugging Face’s production infrastructure.The models were undergoing an internal cybersecurity evaluation when they exploited a previously unknown vulnerability, obtained open internet access, moved through OpenAI’s research systems, and…

Read More