Back to the digest
    Digest

    Radar digest: September 2026

    Twenty-eight entries joined the radar this month: guidance, codes, national acts, catalogue moves and seven dated privacy instruments beyond the EU.

    5 Sept 20262 min readUpdated 7 Sept 2026

    Twenty-eight entries joined the radar this month, and most of them describe the same movement: a duty that already existed being handed a method, a deadline, or a document it has to answer to.

    Nothing below widens a scope. The Cyber Resilience Act guidance does not change who has to report; it records how the Commission reads the questions manufacturers kept asking. The AI Act code and guidelines move no date; they set out what a marking or a labelling control has to show. The Dutch acts transpose two directives whose obligations were already known. The two Chinese instruments turn an audit duty and an assessment duty into a published method and a fixed cycle. Even the reissued ransomware profile is an older document re-cut to the framework it now hangs from.

    So the work the month asks for is evidence work: a reporting path that has been rehearsed, a marking rule written down, an assessment cycle with a named owner, a register entry filed. Guidance that binds nobody still sets the reading an authority starts from, which is why the non-binding entries are the ones worth reading twice.

    Twenty-two entries were added on 6–7 September. Two ISO editions were withdrawn and replaced, a NIST quick-start guide made the Framework's informative references checkable, and the Commission's post-quantum roadmap acquired its consultation feedback. Seven privacy instruments beyond the EU joined too: personal-data law in Korea, Japan, India, Chile and California, China's export-certification measures, and the Data Act's switching-charge date. Vietnam's personal data protection law and its implementing decree opened a new jurisdiction. The EDPB approved a Chapter V transfer certification, and HIPAA's Security Rule rulemaking moved to a new stage in the federal agenda. Eight Chinese instruments arrived together, from the financial regulator's AI guidance for banking and insurance to the implementation opinion on AI agents. Each carries its own clock in its row.

    Take the entries whose clock is already running first; each row below carries its own date. The rest change what a supervisor expects to see rather than who is standing in front of one.

    This month on the radar

    • EU PQC

      EU post-quantum roadmap: consultation feedback, 2 September 2026

      Affected
      Operators of public-sector and other critical infrastructure, including entities in scope of the NIS2 Directive, and the suppliers behind their cryptography.
      Action
      Start the cryptographic inventory and the quantum risk analysis now, and put the end-of-2026 first-steps milestone into the plan rather than the backlog.
    • CN small PI

      China: simplified personal information duties for small processors, in force 1 September 2026

      Affected
      Personal information processors in China holding the data of fewer than one hundred thousand people, and the platforms whose rules they sit under.
      Action
      Count the people whose data is held, then move to the annexed forms while the count stays under the threshold.
    • NIST SP 1347

      NIST finalised the CSF 2.0 informative references guide on 25 August 2026

      Affected
      Anyone maintaining a crosswalk between the CSF 2.0 Core and a control set, a questionnaire or a regulation.
      Action
      Re-source the mapping from the published reference data rather than a spreadsheet copied once, and record which release the crosswalk was built from.
    • CN data risk

      China: annual network data risk assessments from 20 August 2026

      Affected
      Network data processors handling important data inside China, and the assessment bodies they engage.
      Action
      Fix the annual assessment cycle, name the owner, and settle the filing route to the competent department or the provincial cyberspace authority.
    • NIS2 NL

      Netherlands: the NIS2 and CER acts took effect on 15 August 2026

      Affected
      Essential and important entities, and critical entities, where those operations sit in the Netherlands.
      Action
      Register in the national register, and, for the listed digital service categories, file the ENISA register information within one month of 15 August 2026.
    • HIPAA SR

      HIPAA Security Rule: the rewrite moved to long-term actions on 14 August 2026

      Affected
      HIPAA regulated entities under the Security Rule, and the programmes already budgeting against the proposed rule.
      Action
      Keep the gap analysis against the proposed text, but move the remediation budget out of 2026 and into a later cycle.
    • CN police check

      China: police cyberspace security inspections apply from 1 October 2026

      Affected
      Network operators, data processors and personal information processors in China, and the security service firms police engage for technical support.
      Action
      Map the eleven inspection topics onto evidence already held, and record which regulator inspected this year so the result can be reused.
    • CRA guidance

      Cyber Resilience Act: the Commission's application guidance, 27 July 2026

      Affected
      Manufacturers of products with digital elements placed on the EU market, and the importers and distributors behind them.
      Action
      Re-test the scope decision and the support period against the guidance, then rehearse the reporting path before 11 September 2026.
    • AI Act Art. 50

      EU AI Act: the transparency code and guidelines arrived before 2 August 2026

      Affected
      Providers and deployers of interactive AI systems, and of systems that generate or manipulate content.
      Action
      Decide whether to sign the code, then map each Article 50 duty to a marking, labelling or disclosure control that can be shown to work.
    • JP APPI 2026

      Japan: the 2026 amendment to the personal information act adds a surcharge

      Affected
      Businesses handling personal information under Japanese law, and the compliance functions that price their exposure.
      Action
      Re-price the exposure against a surcharge tied to the gain, and watch for the Cabinet Order that follows the 17 January 2027 tranche.
    • CN AI companion

      China: rules for anthropomorphic AI interaction services, in force 15 July 2026

      Affected
      Providers of AI services to the public in China that simulate a person and sustain emotional interaction, and the app stores that list them.
      Action
      Test whether the service sustains emotional interaction, then run the security assessment and file the algorithm before the user thresholds arrive.
    • ISO 27000/19011

      ISO replaced the ISMS overview standard and the auditing guidelines in 2026

      Affected
      Certified organisations, internal audit programmes, and any policy set that defines a term by reference to the ISMS overview standard.
      Action
      Re-point the citations before the next audit cycle: the audit procedure at ISO 19011:2026, the glossary at ISO/IEC 27000:2026.
    • CN label

      China: the cybersecurity label scheme took effect on 1 July 2026

      Affected
      Producers of internet-connected products sold in China once the product class reaches the published catalogue, and the laboratories testing them.
      Action
      Check whether the product class sits in the first catalogue, then decide which star level the security baseline can actually carry.
    • GB/T 46903

      China: the personal information audit standard applies from 1 July 2026

      Affected
      Personal information processors operating in China, and the professional bodies engaged to audit them.
      Action
      Set the audit cycle against the ten-million threshold, then re-cut the audit programme against the standard now in force.
    • CN AI finance

      China: guidance on AI in banking and insurance, issued 18 June 2026

      Affected
      Banking and insurance institutions in China that develop or use artificial intelligence, and the financial holding companies addressed alongside them.
      Action
      Grade every AI use, then hold anything on the guidance's high-risk list until the risk management committee has approved it.
    • NIST IR 8374r1

      NIST reissued the ransomware profile against CSF 2.0

      Affected
      Organisations using a shared profile to set ransomware readiness, and anyone whose control mapping still cites the 2022 profile.
      Action
      Replace the 2022 profile wherever it is cited, and add the governance outcomes the older Core did not carry.
    • CN AI agents

      China: implementation opinion on AI agents, issued 8 May 2026

      Affected
      Agent developers, development platforms, distribution platforms and service providers in China, and the sensitive fields and key sectors whose scenarios the cyberspace departments open.
      Action
      Write down which decisions an agent may take alone, which need the user's authorisation, and which stay with the user.
    • EDPB seal

      EDPB: the Board approved a Chapter V transfer certification on 15 April 2026

      Affected
      Exporters in the European Economic Area looking for a transfer tool other than clauses, and importers outside it that want to be certified.
      Action
      Before relying on a certificate, check that it is current and covers the transfer, and finish any certification under the 2022 criteria before 2026 ends.
    • KR PIPA

      Korea: the PIPA amendment adds a ten per cent surcharge tier from 11 September 2026

      Affected
      Personal information processors subject to the Korean Act, and the boards that appoint and remove their privacy officers.
      Action
      Test the organisation against the Presidential Decree threshold, and put the privacy officer appointment on a board agenda before 11 September 2026.
    • CN auto export

      China: the 2026 automotive data export guidance, issued 30 January 2026

      Affected
      Automotive data processors sending data out of mainland China, from vehicle makers and software suppliers to platform operators, dealers and repair businesses.
      Action
      Map each export against the nine exemptions, then fix log retention at three years before an inspection asks for it.
    • CN CSL

      China: the amended Cybersecurity Law took effect on 1 January 2026

      Affected
      Network operators in China and the operators of critical information infrastructure, whose protection duties now carry a rewritten penalty scale.
      Action
      Re-read the protection duties against the renumbered articles, then price the exposure against the new upper penalty band.
    • VN ND 356

      Vietnam: Decree 356/2025 replaced the 2023 data protection decree on 1 January 2026

      Affected
      Controllers, processors and third parties caught by the Vietnamese personal data protection law, and the small firms it partly excuses.
      Action
      Move any dossier not yet lodged onto the new annex forms, and re-test whether the small-firm carve-out still holds.
    • DPDP Rules

      India: the DPDP Rules stage their own commencement from 13 November 2025

      Affected
      Data fiduciaries processing digital personal data in India, and those offering goods or services to data principals there.
      Action
      Date the eighteen-month set from 13 November 2025, then test the breach process against the seventy-two-hour report to the Board.
    • CN PI export

      China: the personal information export certification measures, in force 1 January 2026

      Affected
      Processors sending personal information out of mainland China on the certification route, and the certification bodies they engage.
      Action
      Decide which export route each transfer takes, then diarise the renewal application six months before any certificate expires.
    • CPPA regs

      California: the CCPA regulations put dates on audits, risk assessments and ADMT

      Affected
      Businesses in scope of the California Consumer Privacy Act that process at volume, use automated decision-making, or both.
      Action
      Fix which of the four articles reaches the business, then work back from the 1 January 2027 automated decision-making date.
    • VN PDPL

      Vietnam: the personal data protection law has been in force since 1 January 2026

      Affected
      Vietnamese and foreign organisations processing personal data in Vietnam, and foreign bodies and people taking part in or connected with processing Vietnamese citizens' data.
      Action
      Test every cross-border flow against the sixty-day dossier duty, then set the breach process to a seventy-two-hour report.
    • CL 21.719

      Chile: Ley N° 21.719 is in force from 1 December 2026

      Affected
      Controllers and processors handling personal data under Chilean law, and the public bodies the amended regime brings in.
      Action
      Date the programme from 1 December 2026, and settle the security measures and the breach report to the agency before it.
    • Data Act

      EU Data Act: switching charges end on 12 January 2027

      Affected
      Providers of data processing services offered in the Union, and the customers whose exit terms sit in those contracts.
      Action
      Pull the switching and exit clauses out of every cloud contract, and check the pre-contract information duty that already applies.

    This month in insights

    The digest by email

    One note a month, the same page in your inbox. Nothing else is sent to the list.