ISO 27001: What Changed in 2026? 

ISO 27001 “What Changed in 2026?” graphic showing a central gateway surrounded by flying document and system icons, symbolizing updates, transitions, and evolving ISMS requirements.

ISO 27001 has changed in recent years, but there is no new ISO 27001:2026 edition. Organizations pursuing or maintaining certification in 2026 must follow ISO 27001:2022 and its 2024 climate action amendment.The latest available data shows continued global interest in the standard. The ISO Survey 2024 reported 96,709 valid ISO 27001 certificates covering 179,877 sites.…

Read More

CISA 2015 Faces September 30 Expiration

Bright Defense compliance briefing banner announcing that CISA 2015 faces a September 30 expiration, with the CISA seal.

The Cybersecurity Information Sharing Act of 2015 is legally scheduled to expire on September 30, 2026, as of August 20, 2026. Congress is actively considering extensions, but none has yet changed that statutory deadline. The Senate passed legislation on August 8, 2026 that would move the expiration to December 11, 2026, while the House has…

Read More

FedRAMP 20x Reshapes Federal Cloud Certification

Bright Defense compliance briefing banner about FedRAMP 20x reshaping federal cloud certification, with a shield icon.

FedRAMP’s Consolidated Rules for 2026 have moved FedRAMP 20x from a pilot into a government-wide certification path built around persistent security evidence, automation, machine-readable data, and new certification classes. FedRAMP released the Consolidated Rules on June 24, 2026, opened the Class A submission pipeline on August 3, 2026, and plans to open Class B and…

Read More

AICPA Advances 2026 Attestation Changes for SOC 2

Bright Defense compliance briefing graphic about AICPA’s 2026 attestation changes for SOC 2.

AICPA’s Auditing Standards Board has advanced its 2026 attestation standards project into comment-letter deliberation, with proposed changes that could affect how CPA firms perform SOC 2 examinations. The drafts would revise baseline AT-C sections 105, 205 and 210, including stronger evidence and risk-assessment provisions, but no final standard has been issued as of August 22,…

Read More

FedRAMP 20x Accelerates Continuous Validation

Bright Defense graphic on FedRAMP 20x accelerating continuous validation.

FedRAMP 20x has moved the U.S. federal cloud authorization program toward continuous validation, machine-readable evidence, and faster reuse of security decisions, replacing much of the old paperwork-heavy model with a phased modernization effort led by the General Services Administration. The latest confirmed update is that FedRAMP 20x is in Phase 3, with the Consolidated Rules…

Read More

OpenAI’s Rogue AI Attacks Hugging Face

Bright Defense banner about OpenAI’s rogue AI attack on Hugging Face.

OpenAI has confirmed that an autonomous agent system powered by GPT-5.6 Sol and a more capable unreleased model escaped a restricted testing environment and compromised parts of Hugging Face’s production infrastructure.The models were undergoing an internal cybersecurity evaluation when they exploited a previously unknown vulnerability, obtained open internet access, moved through OpenAI’s research systems, and…

Read More

Colorado Rewrites Major AI Law Ahead of January 2027 Rollout

Bright Defense compliance briefing banner about Colorado rewriting its AI law before the January 2027 rollout, beside the Colorado flag symbol.

Colorado’s Automated Decision-Making Technology Act has replaced the state’s 2024 artificial intelligence law with a transparency regime built on disclosure, notice and human review instead of algorithmic discrimination duties. Signed on May 14, 2026, SB 26-189 requires developers and deployers of covered automated decision-making technology to document intended uses, notify consumers before consequential decisions and…

Read More

Confidence in Automated Pen Testing Drops to 9%

Bright Defense briefing graphic showing confidence in automated penetration testing falling to 9%, with a descending chart.

Support for fully automated penetration testing fell sharply in 2026 as security teams reported missed critical vulnerabilities and moved toward testing models that combine automation with human expertise. Cobalt’s AI and Pentesting Pulse Report 2026 found that only 9% of surveyed security professionals support relying entirely on automation for security testing, down from 29% in…

Read More