Radar digest: September 2026
Twenty-eight entries joined the radar this month: guidance, codes, national acts, catalogue moves and seven dated privacy instruments beyond the EU.
5 Sept 20262 min readUpdated 7 Sept 2026
Twenty-eight entries joined the radar this month, and most of them describe the same movement: a duty that already existed being handed a method, a deadline, or a document it has to answer to.
Nothing below widens a scope. The Cyber Resilience Act guidance does not change who has to report; it records how the Commission reads the questions manufacturers kept asking. The AI Act code and guidelines move no date; they set out what a marking or a labelling control has to show. The Dutch acts transpose two directives whose obligations were already known. The two Chinese instruments turn an audit duty and an assessment duty into a published method and a fixed cycle. Even the reissued ransomware profile is an older document re-cut to the framework it now hangs from.
So the work the month asks for is evidence work: a reporting path that has been rehearsed, a marking rule written down, an assessment cycle with a named owner, a register entry filed. Guidance that binds nobody still sets the reading an authority starts from, which is why the non-binding entries are the ones worth reading twice.
Twenty-two entries were added on 6–7 September. Two ISO editions were withdrawn and replaced, a NIST quick-start guide made the Framework's informative references checkable, and the Commission's post-quantum roadmap acquired its consultation feedback. Seven privacy instruments beyond the EU joined too: personal-data law in Korea, Japan, India, Chile and California, China's export-certification measures, and the Data Act's switching-charge date. Vietnam's personal data protection law and its implementing decree opened a new jurisdiction. The EDPB approved a Chapter V transfer certification, and HIPAA's Security Rule rulemaking moved to a new stage in the federal agenda. Eight Chinese instruments arrived together, from the financial regulator's AI guidance for banking and insurance to the implementation opinion on AI agents. Each carries its own clock in its row.
Take the entries whose clock is already running first; each row below carries its own date. The rest change what a supervisor expects to see rather than who is standing in front of one.
This month on the radar
EU PQC
EU post-quantum roadmap: consultation feedback, 2 September 2026
- Affected
- Operators of public-sector and other critical infrastructure, including entities in scope of the NIS2 Directive, and the suppliers behind their cryptography.
- Action
- Start the cryptographic inventory and the quantum risk analysis now, and put the end-of-2026 first-steps milestone into the plan rather than the backlog.
CN small PI
China: simplified personal information duties for small processors, in force 1 September 2026
- Affected
- Personal information processors in China holding the data of fewer than one hundred thousand people, and the platforms whose rules they sit under.
- Action
- Count the people whose data is held, then move to the annexed forms while the count stays under the threshold.
NIST SP 1347
NIST finalised the CSF 2.0 informative references guide on 25 August 2026
- Affected
- Anyone maintaining a crosswalk between the CSF 2.0 Core and a control set, a questionnaire or a regulation.
- Action
- Re-source the mapping from the published reference data rather than a spreadsheet copied once, and record which release the crosswalk was built from.
CN data risk
China: annual network data risk assessments from 20 August 2026
- Affected
- Network data processors handling important data inside China, and the assessment bodies they engage.
- Action
- Fix the annual assessment cycle, name the owner, and settle the filing route to the competent department or the provincial cyberspace authority.
NIS2 NL
Netherlands: the NIS2 and CER acts took effect on 15 August 2026
- Affected
- Essential and important entities, and critical entities, where those operations sit in the Netherlands.
- Action
- Register in the national register, and, for the listed digital service categories, file the ENISA register information within one month of 15 August 2026.
HIPAA SR
HIPAA Security Rule: the rewrite moved to long-term actions on 14 August 2026
- Affected
- HIPAA regulated entities under the Security Rule, and the programmes already budgeting against the proposed rule.
- Action
- Keep the gap analysis against the proposed text, but move the remediation budget out of 2026 and into a later cycle.
CN police check
China: police cyberspace security inspections apply from 1 October 2026
- Affected
- Network operators, data processors and personal information processors in China, and the security service firms police engage for technical support.
- Action
- Map the eleven inspection topics onto evidence already held, and record which regulator inspected this year so the result can be reused.
CRA guidance
Cyber Resilience Act: the Commission's application guidance, 27 July 2026
- Affected
- Manufacturers of products with digital elements placed on the EU market, and the importers and distributors behind them.
- Action
- Re-test the scope decision and the support period against the guidance, then rehearse the reporting path before 11 September 2026.
AI Act Art. 50
EU AI Act: the transparency code and guidelines arrived before 2 August 2026
- Affected
- Providers and deployers of interactive AI systems, and of systems that generate or manipulate content.
- Action
- Decide whether to sign the code, then map each Article 50 duty to a marking, labelling or disclosure control that can be shown to work.
JP APPI 2026
Japan: the 2026 amendment to the personal information act adds a surcharge
- Affected
- Businesses handling personal information under Japanese law, and the compliance functions that price their exposure.
- Action
- Re-price the exposure against a surcharge tied to the gain, and watch for the Cabinet Order that follows the 17 January 2027 tranche.
CN AI companion
China: rules for anthropomorphic AI interaction services, in force 15 July 2026
- Affected
- Providers of AI services to the public in China that simulate a person and sustain emotional interaction, and the app stores that list them.
- Action
- Test whether the service sustains emotional interaction, then run the security assessment and file the algorithm before the user thresholds arrive.
ISO 27000/19011
ISO replaced the ISMS overview standard and the auditing guidelines in 2026
- Affected
- Certified organisations, internal audit programmes, and any policy set that defines a term by reference to the ISMS overview standard.
- Action
- Re-point the citations before the next audit cycle: the audit procedure at ISO 19011:2026, the glossary at ISO/IEC 27000:2026.
CN label
China: the cybersecurity label scheme took effect on 1 July 2026
- Affected
- Producers of internet-connected products sold in China once the product class reaches the published catalogue, and the laboratories testing them.
- Action
- Check whether the product class sits in the first catalogue, then decide which star level the security baseline can actually carry.
GB/T 46903
China: the personal information audit standard applies from 1 July 2026
- Affected
- Personal information processors operating in China, and the professional bodies engaged to audit them.
- Action
- Set the audit cycle against the ten-million threshold, then re-cut the audit programme against the standard now in force.
CN AI finance
China: guidance on AI in banking and insurance, issued 18 June 2026
- Affected
- Banking and insurance institutions in China that develop or use artificial intelligence, and the financial holding companies addressed alongside them.
- Action
- Grade every AI use, then hold anything on the guidance's high-risk list until the risk management committee has approved it.
NIST IR 8374r1
NIST reissued the ransomware profile against CSF 2.0
- Affected
- Organisations using a shared profile to set ransomware readiness, and anyone whose control mapping still cites the 2022 profile.
- Action
- Replace the 2022 profile wherever it is cited, and add the governance outcomes the older Core did not carry.
CN AI agents
China: implementation opinion on AI agents, issued 8 May 2026
- Affected
- Agent developers, development platforms, distribution platforms and service providers in China, and the sensitive fields and key sectors whose scenarios the cyberspace departments open.
- Action
- Write down which decisions an agent may take alone, which need the user's authorisation, and which stay with the user.
EDPB seal
EDPB: the Board approved a Chapter V transfer certification on 15 April 2026
- Affected
- Exporters in the European Economic Area looking for a transfer tool other than clauses, and importers outside it that want to be certified.
- Action
- Before relying on a certificate, check that it is current and covers the transfer, and finish any certification under the 2022 criteria before 2026 ends.
KR PIPA
Korea: the PIPA amendment adds a ten per cent surcharge tier from 11 September 2026
- Affected
- Personal information processors subject to the Korean Act, and the boards that appoint and remove their privacy officers.
- Action
- Test the organisation against the Presidential Decree threshold, and put the privacy officer appointment on a board agenda before 11 September 2026.
CN auto export
China: the 2026 automotive data export guidance, issued 30 January 2026
- Affected
- Automotive data processors sending data out of mainland China, from vehicle makers and software suppliers to platform operators, dealers and repair businesses.
- Action
- Map each export against the nine exemptions, then fix log retention at three years before an inspection asks for it.
CN CSL
China: the amended Cybersecurity Law took effect on 1 January 2026
- Affected
- Network operators in China and the operators of critical information infrastructure, whose protection duties now carry a rewritten penalty scale.
- Action
- Re-read the protection duties against the renumbered articles, then price the exposure against the new upper penalty band.
VN ND 356
Vietnam: Decree 356/2025 replaced the 2023 data protection decree on 1 January 2026
- Affected
- Controllers, processors and third parties caught by the Vietnamese personal data protection law, and the small firms it partly excuses.
- Action
- Move any dossier not yet lodged onto the new annex forms, and re-test whether the small-firm carve-out still holds.
DPDP Rules
India: the DPDP Rules stage their own commencement from 13 November 2025
- Affected
- Data fiduciaries processing digital personal data in India, and those offering goods or services to data principals there.
- Action
- Date the eighteen-month set from 13 November 2025, then test the breach process against the seventy-two-hour report to the Board.
CN PI export
China: the personal information export certification measures, in force 1 January 2026
- Affected
- Processors sending personal information out of mainland China on the certification route, and the certification bodies they engage.
- Action
- Decide which export route each transfer takes, then diarise the renewal application six months before any certificate expires.
CPPA regs
California: the CCPA regulations put dates on audits, risk assessments and ADMT
- Affected
- Businesses in scope of the California Consumer Privacy Act that process at volume, use automated decision-making, or both.
- Action
- Fix which of the four articles reaches the business, then work back from the 1 January 2027 automated decision-making date.
VN PDPL
Vietnam: the personal data protection law has been in force since 1 January 2026
- Affected
- Vietnamese and foreign organisations processing personal data in Vietnam, and foreign bodies and people taking part in or connected with processing Vietnamese citizens' data.
- Action
- Test every cross-border flow against the sixty-day dossier duty, then set the breach process to a seventy-two-hour report.
CL 21.719
Chile: Ley N° 21.719 is in force from 1 December 2026
- Affected
- Controllers and processors handling personal data under Chilean law, and the public bodies the amended regime brings in.
- Action
- Date the programme from 1 December 2026, and settle the security measures and the breach report to the agency before it.
Data Act
EU Data Act: switching charges end on 12 January 2027
- Affected
- Providers of data processing services offered in the Union, and the customers whose exit terms sit in those contracts.
- Action
- Pull the switching and exit clauses out of every cloud contract, and check the pre-contract information duty that already applies.
This month in insights
7 Sept 2026
For a bank's security AI, high risk begins where it can change state
An article reading China's AI guidance for banks and insurers puts the grading line at whether a security system can act, not at whether it touches money.
6 Sept 2026
Article 5 on 2 December 2026: the check a security function runs on its own tooling
The prohibited-practice list reads as a product problem. A security function's own tooling touches three of its points, and two more start in December.
6 Sept 2026
The AI bill of materials is the next SBOM
Three articles in one issue argue that the supply chain is now four chains. The bill of materials that stops at code no longer describes what ships.
6 Sept 2026
When agents deal with each other, the object is the connection
An Australian government report moves the governance object from the single agent to the relationship between them. The stop-point sits where control ends.
5 Sept 2026
Agent governance is a permissions problem before it is a model problem
Singapore's advisory on the OpenClaw agent platform moves AI risk from what a model says to what an agent can do. The controls it lists are identity controls.
5 Sept 2026
The permissions review that did not happen
An agent reaches production on its installer's identity, holding every tool that person held. This is the review that should have run first.
5 Sept 2026
CRA in fifteen months: what to do first
Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.
5 Sept 2026
Open-source risk is a maintainer problem, not a CVE count
A Chinese-language piece argues that open-source risk lives in maintainers and funding, not in CVE queues. We agree, and add the control it implies.
5 Sept 2026
The board question is not the CVE count
A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.
The digest by email
One note a month, the same page in your inbox. Nothing else is sent to the list.