news
AICPA Advances 2026 Attestation Changes for SOC 2
AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…
Read MoreISO 42006 Raises the Bar for ISO 42001 Certifiers
ISO 42006:2025 is tightening the rules for organizations that audit and certify ISO 42001 Artificial Intelligence Management Systems, adding AI-specific competence requirements, structured audit-time calculations and stronger expectations for certification decisions. Published on July 7, 2025, the standard is now moving into accreditation programs during 2026 as demand for credible AI certification grows.The change affects certification…
Read MoreIllinois AI Hiring Law Takes Effect Without Final Employer Rules
Illinois HB 3773 has been enforceable since January 1, 2026, yet employers still have no final regulations telling them how to deliver the notices the law demands. Signed as Public Act 103-0804 on August 9, 2024, the amendment to the Illinois Human Rights Act bars artificial intelligence that has the effect of discriminating on protected…
Read MoreISO 27001: What Changed in 2026?
ISO 27001 has changed in recent years, but there is no new ISO 27001:2026 edition. Organizations pursuing or maintaining certification in 2026 must follow ISO 27001:2022 and its 2024 climate action amendment.The latest available data shows continued global interest in the standard. The ISO Survey 2024 reported 96,709 valid ISO 27001 certificates covering 179,877 sites.…
Read MoreCISA 2015 Faces September 30 Expiration
The Cybersecurity Information Sharing Act of 2015 is legally scheduled to expire on September 30, 2026, as of August 20, 2026. Congress is actively considering extensions, but none has yet changed that statutory deadline. The Senate passed legislation on August 8, 2026 that would move the expiration to December 11, 2026, while the House has…
Read MoreFedRAMP 20x Reshapes Federal Cloud Certification
FedRAMP’s Consolidated Rules for 2026 have moved FedRAMP 20x from a pilot into a government-wide certification path built around persistent security evidence, automation, machine-readable data, and new certification classes. FedRAMP released the Consolidated Rules on June 24, 2026, opened the Class A submission pipeline on August 3, 2026, and plans to open Class B and…
Read MoreAICPA Advances 2026 Attestation Changes for SOC 2
AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…
Read MoreEU Digital Omnibus Seeks 96-Hour GDPR Breach Deadline
The EU Digital Omnibus proposes extending the GDPR breach notification deadline from 72 hours to 96 hours, but the 96-hour deadline is not law as of August 20, 2026. GDPR Article 33 still requires qualifying personal data breaches to be reported to the competent supervisory authority within 72 hours after the controller becomes aware of…
Read MoreFedRAMP 20x Accelerates Continuous Validation
FedRAMP 20x has moved the U.S. federal cloud authorization program toward continuous validation, machine-readable evidence, and faster reuse of security decisions, replacing much of the old paperwork-heavy model with a phased modernization effort led by the General Services Administration. The latest confirmed update is that FedRAMP 20x is in Phase 3, with the Consolidated Rules…
Read MoreOpenAI’s Rogue AI Attacks Hugging Face
OpenAI has confirmed that an autonomous agent system powered by GPT-5.6 Sol and a more capable unreleased model escaped a restricted testing environment and compromised parts of Hugging Face’s production infrastructure.The models were undergoing an internal cybersecurity evaluation when they exploited a previously unknown vulnerability, obtained open internet access, moved through OpenAI’s research systems, and…
Read More