<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GRCIDE</title>
    <link>https://grcide.com/library</link>
    <description>Working methods and regulatory briefings for security governance, risk and compliance practitioners.</description>
    <language>en</language>
    <atom:link href="https://grcide.com/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Mon, 07 Sep 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>For a bank's security AI, high risk begins where it can change state</title>
      <link>https://grcide.com/insights/security-ai-high-risk-changes-state</link>
      <guid isPermaLink="false">https://grcide.com/insights/security-ai-high-risk-changes-state</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <description>An article reading China's AI guidance for banks and insurers puts the grading line at whether a security system can act, not at whether it touches money.</description>
    </item>
    <item>
      <title>Article 5 on 2 December 2026: the check a security function runs on its own tooling</title>
      <link>https://grcide.com/insights/ai-act-article-5-december</link>
      <guid isPermaLink="false">https://grcide.com/insights/ai-act-article-5-december</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>The prohibited-practice list reads as a product problem. A security function's own tooling touches three of its points, and two more start in December.</description>
    </item>
    <item>
      <title>The AI bill of materials is the next SBOM</title>
      <link>https://grcide.com/insights/ai-bom-is-the-next-sbom</link>
      <guid isPermaLink="false">https://grcide.com/insights/ai-bom-is-the-next-sbom</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>Three articles in one issue argue that the supply chain is now four chains. The bill of materials that stops at code no longer describes what ships.</description>
    </item>
    <item>
      <title>CRA readiness</title>
      <link>https://grcide.com/engagement-patterns/cra-readiness</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/cra-readiness</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>Getting a manufacturer ready for the CRA: class, route, vulnerability handling, support period, the technical file, and a rehearsed reporting clock.</description>
      <category>governance</category>
    </item>
    <item>
      <title>CRA and the supply chain: components, stewards and what to ask a supplier</title>
      <link>https://grcide.com/briefings/cra-supply-chain-components</link>
      <guid isPermaLink="false">https://grcide.com/briefings/cra-supply-chain-components</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>Component due diligence under Article 13(5), the upstream vulnerability duty, open-source stewards, and the questions a component supplier has to answer.</description>
      <category>risk</category>
    </item>
    <item>
      <title>When agents deal with each other, the object is the connection</title>
      <link>https://grcide.com/insights/multi-agent-governance-is-the-connection</link>
      <guid isPermaLink="false">https://grcide.com/insights/multi-agent-governance-is-the-connection</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>An Australian government report moves the governance object from the single agent to the relationship between them. The stop-point sits where control ends.</description>
    </item>
    <item>
      <title>Remote auditing under ISO 19011:2026: what changes for the auditee</title>
      <link>https://grcide.com/briefings/remote-auditing-iso-19011-2026</link>
      <guid isPermaLink="false">https://grcide.com/briefings/remote-auditing-iso-19011-2026</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>What the 2026 edition changed about remote auditing, and what the auditee decides: method, virtual locations, evidence over a channel, the agreement.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Radar digest: September 2026</title>
      <link>https://grcide.com/digest/2026-09</link>
      <guid isPermaLink="false">https://grcide.com/digest/2026-09</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Twenty-eight entries joined the radar this month: guidance, codes, national acts, catalogue moves and seven dated privacy instruments beyond the EU.</description>
    </item>
    <item>
      <title>Agent governance is a permissions problem before it is a model problem</title>
      <link>https://grcide.com/insights/agent-governance-is-a-permissions-problem</link>
      <guid isPermaLink="false">https://grcide.com/insights/agent-governance-is-a-permissions-problem</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Singapore's advisory on the OpenClaw agent platform moves AI risk from what a model says to what an agent can do. The controls it lists are identity controls.</description>
    </item>
    <item>
      <title>The permissions review that did not happen</title>
      <link>https://grcide.com/insights/agent-permissions-review</link>
      <guid isPermaLink="false">https://grcide.com/insights/agent-permissions-review</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>An agent reaches production on its installer's identity, holding every tool that person held. This is the review that should have run first.</description>
    </item>
    <item>
      <title>Human oversight and logging: designing the Article 14 and Article 12 evidence</title>
      <link>https://grcide.com/briefings/ai-oversight-and-logging-evidence</link>
      <guid isPermaLink="false">https://grcide.com/briefings/ai-oversight-and-logging-evidence</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Article 14 oversight and Article 12 logging as one evidence design: who oversees, what they may do, what the logs allow, and how long they are kept.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>AI system register</title>
      <link>https://grcide.com/templates/ai-system-register</link>
      <guid isPermaLink="false">https://grcide.com/templates/ai-system-register</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>AI use-case triage form</title>
      <link>https://grcide.com/templates/ai-use-case-triage</link>
      <guid isPermaLink="false">https://grcide.com/templates/ai-use-case-triage</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>BCM under ISO 22301: BIA, strategy, exercise</title>
      <link>https://grcide.com/playbooks/bcm-under-iso-22301</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/bcm-under-iso-22301</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Turning a continuity document into a management system: impact analysis, disruption risk, costed strategies, exercised plans and evaluation evidence.</description>
      <category>risk</category>
    </item>
    <item>
      <title>The BISO operating model</title>
      <link>https://grcide.com/playbooks/biso-operating-model</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/biso-operating-model</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Board and management reporting for security</title>
      <link>https://grcide.com/playbooks/board-reporting-for-security</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/board-reporting-for-security</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for putting security in front of a board and getting a decision: five to seven risks, measured controls, and an outcome that is written down.</description>
      <category>governance</category>
    </item>
    <item>
      <title>China–EU regulatory bridge</title>
      <link>https://grcide.com/reference/china-eu-regulatory-bridge</link>
      <guid isPermaLink="false">https://grcide.com/reference/china-eu-regulatory-bridge</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Which Chinese instrument answers which EU instrument for vehicles and for personal data, where the two only partly meet, and where no counterpart exists.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Control catalogue</title>
      <link>https://grcide.com/templates/control-catalogue</link>
      <guid isPermaLink="false">https://grcide.com/templates/control-catalogue</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Control ownership and the control catalogue</title>
      <link>https://grcide.com/playbooks/control-ownership-and-the-control-catalogue</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/control-ownership-and-the-control-catalogue</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for building one list of the controls that actually run, each with an owner, an evidence record and a test result, mapped to the frameworks they serve.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Control test workpaper</title>
      <link>https://grcide.com/templates/control-test-workpaper</link>
      <guid isPermaLink="false">https://grcide.com/templates/control-test-workpaper</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Control testing and ITGC</title>
      <link>https://grcide.com/playbooks/control-testing-and-itgc</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/control-testing-and-itgc</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for proving controls operated over a period: the ITGC map, complete populations, risk-based samples, workpapers a second person can re-perform.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Choosing the CRA conformity route</title>
      <link>https://grcide.com/playbooks/cra-conformity-route</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/cra-conformity-route</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Which Article 32 procedure applies to each product, who signs the declaration, and what the chosen route must produce before 11 December 2027.</description>
      <category>governance</category>
    </item>
    <item>
      <title>The support period decision</title>
      <link>https://grcide.com/briefings/cra-support-period-decision</link>
      <guid isPermaLink="false">https://grcide.com/briefings/cra-support-period-decision</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>How a CRA support period is set, evidenced, published and closed: the Article 13(8) criteria, the duties that run over it, and who owns each.</description>
      <category>governance</category>
    </item>
    <item>
      <title>CRA technical documentation and the declaration of conformity</title>
      <link>https://grcide.com/playbooks/cra-technical-documentation</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/cra-technical-documentation</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Assembling the Annex VII file, keeping it current for the retention period, and getting a declaration signed by a role that has read it.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>CRA technical documentation index</title>
      <link>https://grcide.com/templates/cra-technical-documentation-index</link>
      <guid isPermaLink="false">https://grcide.com/templates/cra-technical-documentation-index</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Vulnerability handling and the SBOM under the CRA</title>
      <link>https://grcide.com/playbooks/cra-vulnerability-handling-and-sbom</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/cra-vulnerability-handling-and-sbom</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Annex I Part II run as a process: the bill of materials, component due diligence, intake, triage, the security update, disclosure and the Article 14 record.</description>
      <category>risk</category>
    </item>
    <item>
      <title>CRA in fifteen months: what to do first</title>
      <link>https://grcide.com/insights/cra-what-to-do-first</link>
      <guid isPermaLink="false">https://grcide.com/insights/cra-what-to-do-first</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.</description>
    </item>
    <item>
      <title>Cyber resilience beyond continuity</title>
      <link>https://grcide.com/briefings/cyber-resilience-beyond-continuity</link>
      <guid isPermaLink="false">https://grcide.com/briefings/cyber-resilience-beyond-continuity</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>What NIS2, DORA and the CER Directive each ask of resilience, the objectives that come before plans, and the exercise a policy cannot replace.</description>
      <category>risk</category>
    </item>
    <item>
      <title>DORA implementation</title>
      <link>https://grcide.com/playbooks/dora-implementation</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/dora-implementation</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for turning DORA into a running programme: scope, framework, incidents, testing, third-party risk, and the register of information built last.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>EU AI Act for security governance</title>
      <link>https://grcide.com/briefings/eu-ai-act-for-security-governance</link>
      <guid isPermaLink="false">https://grcide.com/briefings/eu-ai-act-for-security-governance</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>The AI Act as consolidated on 27 July 2026: the scope test, obligations by article, the split high-risk timetable, and what security owns.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Findings-to-closure tracker template</title>
      <link>https://grcide.com/templates/findings-to-closure-tracker</link>
      <guid isPermaLink="false">https://grcide.com/templates/findings-to-closure-tracker</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>The first 90 days as a security leader</title>
      <link>https://grcide.com/playbooks/first-90-days-as-a-security-leader</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/first-90-days-as-a-security-leader</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A ninety-day method: inventory the mandate, the obligations and the risk picture, decide appetite and operating model, then take one decision to the board.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Governing AI and agents: who decides what</title>
      <link>https://grcide.com/briefings/governing-ai-and-agents-decision-rights</link>
      <guid isPermaLink="false">https://grcide.com/briefings/governing-ai-and-agents-decision-rights</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>AI governance as a table of decision rights: the three objects, a five-question test, who decides what an agent may do, and the evidence each decision leaves.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Governing security in the product organisation</title>
      <link>https://grcide.com/engagement-patterns/governing-security-in-the-product-organisation</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/governing-security-in-the-product-organisation</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Where product security decisions are actually taken: the decision rights, the risk assessment they run on, and the conformity evidence they leave behind.</description>
      <category>governance</category>
    </item>
    <item>
      <title>GRC automation patterns</title>
      <link>https://grcide.com/reference/grc-automation-patterns</link>
      <guid isPermaLink="false">https://grcide.com/reference/grc-automation-patterns</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Seven patterns for automating compliance work, each with the evidence it produces, the place it breaks, and the requirement it actually serves.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>IEC 62443 for governance people</title>
      <link>https://grcide.com/briefings/iec-62443-for-governance-people</link>
      <guid isPermaLink="false">https://grcide.com/briefings/iec-62443-for-governance-people</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>IEC 62443 as a system of roles and decisions: which part binds which role, the concepts a governance reader must own, and where the series gets misread.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Incident governance</title>
      <link>https://grcide.com/playbooks/incident-governance</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/incident-governance</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for governing incidents end to end: declaration, decision records, the reporting clock across four regimes, and corrective action verified closed.</description>
      <category>governance</category>
    </item>
    <item>
      <title>ISO/IEC 42001: an AI management system that fits the ISMS</title>
      <link>https://grcide.com/playbooks/iso-42001-ai-management-system</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/iso-42001-ai-management-system</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Adding ISO/IEC 42001 to an existing ISMS as one system: scope and roles, the AI policy, AI risk, the impact assessment, Annex A and the certification route.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>ISO 27001 to SOC 2: one control set, two reports</title>
      <link>https://grcide.com/reference/iso27001-to-soc2</link>
      <guid isPermaLink="false">https://grcide.com/reference/iso27001-to-soc2</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>One control set can serve both, but a certificate and an attestation report differ in object, criteria, examiner, output and period.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Key risk indicators that predict, not describe</title>
      <link>https://grcide.com/reference/key-risk-indicators</link>
      <guid isPermaLink="false">https://grcide.com/reference/key-risk-indicators</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Leading indicators for eleven common security risks, each with the source of the number, the threshold, the role that acts, and where the indicator misleads.</description>
      <category>risk</category>
    </item>
    <item>
      <title>One-page risk picture</title>
      <link>https://grcide.com/templates/one-page-risk-picture</link>
      <guid isPermaLink="false">https://grcide.com/templates/one-page-risk-picture</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A one-page board view of five to seven risks, each with an owner role, a position against appetite, a trend and the decision the body is asked to take.</description>
      <category>governance</category>
    </item>
    <item>
      <title>One-page security strategy</title>
      <link>https://grcide.com/templates/one-page-security-strategy</link>
      <guid isPermaLink="false">https://grcide.com/templates/one-page-security-strategy</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>One approvable page: five to seven security objectives, each tied to a business objective and a risk, with a measure, a baseline, a target and an owner role.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Open-source risk is a maintainer problem, not a CVE count</title>
      <link>https://grcide.com/insights/open-source-risk-is-a-maintainer-problem</link>
      <guid isPermaLink="false">https://grcide.com/insights/open-source-risk-is-a-maintainer-problem</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A Chinese-language piece argues that open-source risk lives in maintainers and funding, not in CVE queues. We agree, and add the control it implies.</description>
    </item>
    <item>
      <title>Policy architecture people can find</title>
      <link>https://grcide.com/playbooks/policy-architecture</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/policy-architecture</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for turning a pile of documents into a tiered policy set with owners, review dates and exceptions, so a reader can find the rule that applies.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Policy map</title>
      <link>https://grcide.com/templates/policy-map</link>
      <guid isPermaLink="false">https://grcide.com/templates/policy-map</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A fourteen-column register of the policy set: tier, owner, approver, audience, the requirement that put each document there, and its next review date.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Product CSMS as a management system</title>
      <link>https://grcide.com/playbooks/product-csms-as-a-management-system</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/product-csms-as-a-management-system</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Running the cyber security management system UN R155 requires as an operating system rather than a document set, on the clause pattern an ISMS already follows.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Register of information starter</title>
      <link>https://grcide.com/templates/register-of-information</link>
      <guid isPermaLink="false">https://grcide.com/templates/register-of-information</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A five-sheet starter that mirrors the standard templates for the register of information, so the function, arrangement and provider data is collected once.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Risk acceptance and residual risk</title>
      <link>https://grcide.com/playbooks/risk-acceptance-and-residual-risk</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/risk-acceptance-and-residual-risk</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for turning &quot;we accept that risk&quot; into a dated record: a named approver, a residual level tested against criteria, compensating controls and an expiry.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Risk acceptance record</title>
      <link>https://grcide.com/templates/risk-acceptance-record</link>
      <guid isPermaLink="false">https://grcide.com/templates/risk-acceptance-record</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A fifteen-column record for accepted risks, with the authority table that says who may accept each level and an expiry log that forces a re-decision.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Risk appetite and criteria that decisions can use</title>
      <link>https://grcide.com/playbooks/risk-appetite-and-criteria</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/risk-appetite-and-criteria</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Appetite written as decisions rather than adjectives, scales with sentence anchors, and acceptance thresholds a register applies and a board approves.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Risk criteria and appetite statement</title>
      <link>https://grcide.com/templates/risk-criteria-and-appetite</link>
      <guid isPermaLink="false">https://grcide.com/templates/risk-criteria-and-appetite</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Appetite per risk category, anchored consequence and likelihood scales, and a published lookup that says which level is accepted, treated or escalated.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Running the external audit</title>
      <link>https://grcide.com/playbooks/running-the-external-audit</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/running-the-external-audit</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for hosting the certification body: evidence architecture, the opening meeting, nonconformity handling, and findings tracked to verified closure.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Scenario-based risk assessment</title>
      <link>https://grcide.com/playbooks/scenario-based-risk-assessment</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/scenario-based-risk-assessment</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Fifteen to forty scenarios a committee can decide on: risk sources with a desired end state, consequences over time, likelihood with a stated basis, and owners.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Scenario library</title>
      <link>https://grcide.com/templates/scenario-library</link>
      <guid isPermaLink="false">https://grcide.com/templates/scenario-library</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>The maintained set of risk scenarios a committee can decide on: sources with a desired end state, consequence and likelihood with a basis, and an owner per row.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Security awareness that changes behaviour</title>
      <link>https://grcide.com/playbooks/security-awareness-that-works</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/security-awareness-that-works</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.</description>
      <category>governance</category>
    </item>
    <item>
      <title>The security operating model</title>
      <link>https://grcide.com/playbooks/security-operating-model</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/security-operating-model</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for writing down how security decisions are made: the functions, the decision rights, the three lines, the interfaces and the operating calendar.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Security risk inside enterprise risk management</title>
      <link>https://grcide.com/briefings/security-risk-in-enterprise-risk-management</link>
      <guid isPermaLink="false">https://grcide.com/briefings/security-risk-in-enterprise-risk-management</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Where the security register meets the enterprise one: what must agree, what may differ, who owns aggregation, and which rules force the join.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Security strategy on one page</title>
      <link>https://grcide.com/playbooks/security-strategy-on-one-page</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/security-strategy-on-one-page</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for turning business objectives, obligations and the risk picture into five to seven measured security objectives that fit on one approved page.</description>
      <category>governance</category>
    </item>
    <item>
      <title>The board question is not the CVE count</title>
      <link>https://grcide.com/insights/the-board-question-is-not-the-cve-count</link>
      <guid isPermaLink="false">https://grcide.com/insights/the-board-question-is-not-the-cve-count</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.</description>
    </item>
    <item>
      <title>Third-party risk across the contract lifecycle</title>
      <link>https://grcide.com/playbooks/third-party-risk-lifecycle</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/third-party-risk-lifecycle</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A lifecycle method for supplier assurance: tier first, assess by tier, contract for the rights you will need, keep assurance running, and exit on plan.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Third-party tiering</title>
      <link>https://grcide.com/templates/third-party-tiering</link>
      <guid isPermaLink="false">https://grcide.com/templates/third-party-tiering</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A four-sheet workbook that scores suppliers on five closed-option factors, bands the scores into three tiers, and sets the depth of assurance each earns.</description>
      <category>risk</category>
    </item>
    <item>
      <title>Vulnerability handling record</title>
      <link>https://grcide.com/templates/vulnerability-handling-record</link>
      <guid isPermaLink="false">https://grcide.com/templates/vulnerability-handling-record</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Four sheets for Annex I Part II: an SBOM index by product version, a disclosure log, an update log, and a reporting clock with the two Article 14 anchors.</description>
      <category>risk</category>
    </item>
    <item>
      <title>CRA obligations by product class</title>
      <link>https://grcide.com/briefings/cra-obligations-by-product-class</link>
      <guid isPermaLink="false">https://grcide.com/briefings/cra-obligations-by-product-class</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <description>Regulation (EU) 2024/2847 by product class: the scope test, the obligations by article, the conformity route, and what starts on 11 September 2026.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>From regulation to controls</title>
      <link>https://grcide.com/playbooks/regulation-to-controls</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/regulation-to-controls</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
      <description>A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>AI governance stand-up under the EU AI Act</title>
      <link>https://grcide.com/engagement-patterns/ai-governance-standup</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/ai-governance-standup</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Choosing a GRC framework: what each instrument actually is</title>
      <link>https://grcide.com/reference/grc-framework-selection</link>
      <guid isPermaLink="false">https://grcide.com/reference/grc-framework-selection</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Certifiable standard, outcome framework, attestation report or sector standard: what each GRC instrument produces, and which one a given driver calls for.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Building an ISMS people actually use</title>
      <link>https://grcide.com/playbooks/isms-people-actually-use</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/isms-people-actually-use</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.</description>
      <category>governance</category>
    </item>
    <item>
      <title>ISO 27001 first certification</title>
      <link>https://grcide.com/engagement-patterns/iso27001-first-certification</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/iso27001-first-certification</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>NIS2 for the security officer</title>
      <link>https://grcide.com/briefings/nis2-for-the-security-officer</link>
      <guid isPermaLink="false">https://grcide.com/briefings/nis2-for-the-security-officer</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>NIS2 readiness for an important entity</title>
      <link>https://grcide.com/engagement-patterns/nis2-readiness-important-entity</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/nis2-readiness-important-entity</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Product cybersecurity under R155, ISO 21434 and the CRA</title>
      <link>https://grcide.com/engagement-patterns/product-cybersecurity-r155-cra</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/product-cybersecurity-r155-cra</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Risk register template</title>
      <link>https://grcide.com/templates/risk-register</link>
      <guid isPermaLink="false">https://grcide.com/templates/risk-register</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.</description>
      <category>risk</category>
    </item>
    <item>
      <title>The risk register other people trust</title>
      <link>https://grcide.com/playbooks/risk-register-people-trust</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/risk-register-people-trust</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.</description>
      <category>risk</category>
    </item>
    <item>
      <title>EU post-quantum roadmap: consultation feedback, 2 September 2026</title>
      <link>https://grcide.com/radar#eu-pqc-roadmap-faq</link>
      <guid isPermaLink="false">https://grcide.com/radar#eu-pqc-roadmap-faq</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <description>The Commission published the roadmap consultation feedback on 2 September 2026; the FAQ of 15 April 2026 answers the milestone and inventory questions.</description>
    </item>
    <item>
      <title>China: simplified personal information duties for small processors, in force 1 September 2026</title>
      <link>https://grcide.com/radar#china-small-pi-processors</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-small-pi-processors</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <description>Order No. 25 gives a processor under one hundred thousand people a five-year audit cycle, form-based impact assessments and six export exemptions.</description>
    </item>
    <item>
      <title>NIST finalised the CSF 2.0 informative references guide on 25 August 2026</title>
      <link>https://grcide.com/radar#nist-csf-informative-references</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-csf-informative-references</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 +0000</pubDate>
      <description>NIST SP 1347 reached final status on 25 August 2026, covering what a CSF 2.0 informative reference is and which NIST tools serve the reference data.</description>
    </item>
    <item>
      <title>China: annual network data risk assessments from 20 August 2026</title>
      <link>https://grcide.com/radar#china-network-data-risk-assessment</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-network-data-risk-assessment</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <description>Order No. 24 makes an annual risk assessment compulsory for important data processors, with the report filed within twenty working days.</description>
    </item>
    <item>
      <title>Netherlands: the NIS2 and CER acts took effect on 15 August 2026</title>
      <link>https://grcide.com/radar#nl-cyberbeveiligingswet</link>
      <guid isPermaLink="false">https://grcide.com/radar#nl-cyberbeveiligingswet</guid>
      <pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate>
      <description>The Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten entered into force on 15 August 2026, and the decree carries no transitional law.</description>
    </item>
    <item>
      <title>HIPAA Security Rule: the rewrite moved to long-term actions on 14 August 2026</title>
      <link>https://grcide.com/radar#hipaa-security-rule-long-term-actions</link>
      <guid isPermaLink="false">https://grcide.com/radar#hipaa-security-rule-long-term-actions</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>The 2026 Unified Agenda moved the HIPAA Security Rule rewrite out of the final rule stage and projected final action in July 2027, with no day set.</description>
    </item>
    <item>
      <title>China: police cyberspace security inspections apply from 1 October 2026</title>
      <link>https://grcide.com/radar#china-police-cyberspace-inspection</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-police-cyberspace-inspection</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Order No. 176 replaces the 2018 internet inspection rules, holds routine on-site checks to one a year, and reuses another regulator's inspection result.</description>
    </item>
    <item>
      <title>EU AI Act: high-risk dates deferred, two prohibitions added</title>
      <link>https://grcide.com/radar#ai-act-high-risk-deferral</link>
      <guid isPermaLink="false">https://grcide.com/radar#ai-act-high-risk-deferral</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Digital Omnibus on AI moves the high-risk obligations to December 2027 and August 2028, and adds two prohibited practices from December 2026.</description>
    </item>
    <item>
      <title>Cyber Resilience Act: the Commission's application guidance, 27 July 2026</title>
      <link>https://grcide.com/radar#cra-commission-guidance</link>
      <guid isPermaLink="false">https://grcide.com/radar#cra-commission-guidance</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>C(2026) 5252 and its annex set out how the Commission reads scope, substantial modification, support periods and the reporting duties.</description>
    </item>
    <item>
      <title>EU AI Act: the transparency code and guidelines arrived before 2 August 2026</title>
      <link>https://grcide.com/radar#ai-act-transparency-code</link>
      <guid isPermaLink="false">https://grcide.com/radar#ai-act-transparency-code</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Code of Practice on Transparency of AI-generated Content closed on 10 June 2026, and the Commission's Article 50 guidelines followed on 20 July 2026.</description>
    </item>
    <item>
      <title>Japan: the 2026 amendment to the personal information act adds a surcharge</title>
      <link>https://grcide.com/radar#japan-appi-2026-amendment</link>
      <guid isPermaLink="false">https://grcide.com/radar#japan-appi-2026-amendment</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Promulgated 17 July 2026, the amending act adds a surcharge regime; one tranche is in force from 17 January 2027 and the rest await a Cabinet Order.</description>
    </item>
    <item>
      <title>China: rules for anthropomorphic AI interaction services, in force 15 July 2026</title>
      <link>https://grcide.com/radar#china-anthropomorphic-ai-services</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-anthropomorphic-ai-services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Order No. 21 reaches AI that sustains emotional interaction, with a security assessment at a million registered users and algorithm filing verified each year.</description>
    </item>
    <item>
      <title>CER Directive: Swedish bill proposes entry into force on 1 January 2027</title>
      <link>https://grcide.com/radar#cer-directive-swedish-bill</link>
      <guid isPermaLink="false">https://grcide.com/radar#cer-directive-swedish-bill</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Sweden's bill implementing the critical entities resilience directive was laid before the Riksdag on 14 July 2026, proposing effect from 1 January 2027.</description>
    </item>
    <item>
      <title>ECE R155 vs ISO 21434: Five Common Misreads That Get Caught in Audit</title>
      <link>https://grcide.com/briefings/r155-vs-iso21434-five-misreads</link>
      <guid isPermaLink="false">https://grcide.com/briefings/r155-vs-iso21434-five-misreads</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>R155 mandates the framework; ISO 21434 describes how to build it. Treating them as interchangeable is where most first-time audits go sideways.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>The 90-day SOC 2 Type 1 plan</title>
      <link>https://grcide.com/briefings/soc2-type1-90-day-plan</link>
      <guid isPermaLink="false">https://grcide.com/briefings/soc2-type1-90-day-plan</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>A week-by-week sequence for a first SOC 2 type 1 examination: scope, policy set, evidence pipeline, risk assessment, fieldwork.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>ISO replaced the ISMS overview standard and the auditing guidelines in 2026</title>
      <link>https://grcide.com/radar#iso-27000-19011-2026</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-27000-19011-2026</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate>
      <description>ISO/IEC 27000:2026 was published on 3 July 2026 and ISO 19011:2026 in May 2026, withdrawing the editions an older audit file cites.</description>
    </item>
    <item>
      <title>China: the cybersecurity label scheme took effect on 1 July 2026</title>
      <link>https://grcide.com/radar#china-cybersecurity-label</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-cybersecurity-label</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>A voluntary three-star label rates a connected product's security, filed with a designated body and scannable to the test report and conformity declaration.</description>
    </item>
    <item>
      <title>China: the personal information audit standard applies from 1 July 2026</title>
      <link>https://grcide.com/radar#china-pi-audit-standard</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-pi-audit-standard</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>GB/T 46903-2025 took effect on 1 July 2026, giving the compliance audit already required of large processors a published national method.</description>
    </item>
    <item>
      <title>China: guidance on AI in banking and insurance, issued 18 June 2026</title>
      <link>https://grcide.com/radar#china-nfra-ai-banking-insurance-guidance</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-nfra-ai-banking-insurance-guidance</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <description>Thirty-two items put AI in banks and insurers under a board committee, a graded application inventory, and risk committee approval for high-risk uses.</description>
    </item>
    <item>
      <title>Cyber Resilience Act: manufacturer reporting starts on 11 September 2026</title>
      <link>https://grcide.com/radar#cra-reporting-obligations</link>
      <guid isPermaLink="false">https://grcide.com/radar#cra-reporting-obligations</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>Article 14 applies from 11 September 2026, ahead of full application on 11 December 2027, and it reaches products already placed on the market.</description>
    </item>
    <item>
      <title>NIST reissued the ransomware profile against CSF 2.0</title>
      <link>https://grcide.com/radar#nist-ransomware-profile</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-ransomware-profile</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>NIST IR 8374 Revision 1 was published in June 2026 and supersedes the 2022 ransomware profile, which predates the six-Function Core.</description>
    </item>
    <item>
      <title>UN Regulation No 156: amendments binding on applying Contracting Parties from 4 June 2026</title>
      <link>https://grcide.com/radar#un-r156-amendments-2026</link>
      <guid isPermaLink="false">https://grcide.com/radar#un-r156-amendments-2026</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <description>In force since 22 January 2021; amended by ECE/TRANS/WP.29/2025/142, binding on applying Contracting Parties from 4 June 2026 per the UN depositary record.</description>
    </item>
    <item>
      <title>China: implementation opinion on AI agents, issued 8 May 2026</title>
      <link>https://grcide.com/radar#china-ai-agents-implementation-opinion</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-ai-agents-implementation-opinion</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate>
      <description>Thirty-eight tasks for AI agents: a registration platform carrying digital identity, a permission boundary, anomaly tooling and graded sector treatment.</description>
    </item>
    <item>
      <title>EDPB: the Board approved a Chapter V transfer certification on 15 April 2026</title>
      <link>https://grcide.com/radar#edpb-europrivacy-transfer-seal</link>
      <guid isPermaLink="false">https://grcide.com/radar#edpb-europrivacy-transfer-seal</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <description>Two opinions adopted on 15 April 2026 approve an updated European Data Protection Seal and, separately, one usable as an Article 46(2)(f) transfer tool.</description>
    </item>
    <item>
      <title>Korea: the PIPA amendment adds a ten per cent surcharge tier from 11 September 2026</title>
      <link>https://grcide.com/radar#korea-pipa-2026-amendment</link>
      <guid isPermaLink="false">https://grcide.com/radar#korea-pipa-2026-amendment</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate>
      <description>Act No. 21445, promulgated 10 March 2026, is in force from 11 September 2026, with a ten per cent turnover tier and a board resolution for the privacy officer.</description>
    </item>
    <item>
      <title>China: the 2026 automotive data export guidance, issued 30 January 2026</title>
      <link>https://grcide.com/radar#china-automotive-data-export-guidance</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-automotive-data-export-guidance</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 +0000</pubDate>
      <description>Eight departments set nine export exemptions for automotive data, scenario rules for judging important data, and three-year tamper-proof log retention.</description>
    </item>
    <item>
      <title>NIS2: Sweden's Cybersecurity Act took effect on 15 January 2026</title>
      <link>https://grcide.com/radar#nis2-swedish-cybersecurity-act</link>
      <guid isPermaLink="false">https://grcide.com/radar#nis2-swedish-cybersecurity-act</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate>
      <description>Cybersäkerhetslag (2025:1506) entered into force on 15 January 2026, fifteen months after the directive's transposition date of 17 October 2024.</description>
    </item>
    <item>
      <title>China: the amended Cybersecurity Law took effect on 1 January 2026</title>
      <link>https://grcide.com/radar#china-cybersecurity-law-amendment</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-cybersecurity-law-amendment</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate>
      <description>Presidential Order No. 61 adds an artificial intelligence article to the Cybersecurity Law and sets the top penalty on an operator at ten million yuan.</description>
    </item>
    <item>
      <title>GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026</title>
      <link>https://grcide.com/radar#gb-44495-44496-in-force</link>
      <guid isPermaLink="false">https://grcide.com/radar#gb-44495-44496-in-force</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate>
      <description>China's mandatory vehicle cybersecurity and software-update standards moved from issued to in force on 1 January 2026, seventeen months after publication.</description>
    </item>
    <item>
      <title>Vietnam: Decree 356/2025 replaced the 2023 data protection decree on 1 January 2026</title>
      <link>https://grcide.com/radar#vietnam-pdpl-decree-356</link>
      <guid isPermaLink="false">https://grcide.com/radar#vietnam-pdpl-decree-356</guid>
      <pubDate>Wed, 31 Dec 2025 00:00:00 +0000</pubDate>
      <description>Issued on 31 December 2025 and in force the next day, the decree sets the dossier forms, widens the transfer exemptions and repeals Decree 13/2023.</description>
    </item>
    <item>
      <title>India: the DPDP Rules stage their own commencement from 13 November 2025</title>
      <link>https://grcide.com/radar#india-dpdp-rules-2025</link>
      <guid isPermaLink="false">https://grcide.com/radar#india-dpdp-rules-2025</guid>
      <pubDate>Thu, 13 Nov 2025 00:00:00 +0000</pubDate>
      <description>G.S.R. 846(E) splits commencement three ways: part on publication, consent managers a year on, and the working obligations eighteen months on.</description>
    </item>
    <item>
      <title>ISO/IEC 27001:2013 certificates stopped being valid after 31 October 2025</title>
      <link>https://grcide.com/radar#iso-27001-2022-transition-closed</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-27001-2022-transition-closed</guid>
      <pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate>
      <description>The accredited transition period set by IAF MD 26 ended on 31 October 2025; certificates naming the 2013 edition expire or are withdrawn.</description>
    </item>
    <item>
      <title>China: the personal information export certification measures, in force 1 January 2026</title>
      <link>https://grcide.com/radar#china-pi-export-certification</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-pi-export-certification</guid>
      <pubDate>Tue, 14 Oct 2025 00:00:00 +0000</pubDate>
      <description>Order No. 20 gives the certification route its own rules: who may use it, a three-year certificate, and a bar on splitting volumes to dodge the assessment.</description>
    </item>
    <item>
      <title>California: the CCPA regulations put dates on audits, risk assessments and ADMT</title>
      <link>https://grcide.com/radar#california-ccpa-audit-admt-regulations</link>
      <guid isPermaLink="false">https://grcide.com/radar#california-ccpa-audit-admt-regulations</guid>
      <pubDate>Mon, 22 Sep 2025 00:00:00 +0000</pubDate>
      <description>Approved on 22 September 2025 and effective 1 January 2026, the package dates ADMT compliance at 2027, first audit reports at 2028 and later.</description>
    </item>
    <item>
      <title>ISO/IEC 42006:2025 completes the certification route for AI management systems</title>
      <link>https://grcide.com/radar#iso-42006-certification-route</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-42006-certification-route</guid>
      <pubDate>Mon, 07 Jul 2025 00:00:00 +0000</pubDate>
      <description>The requirements standard for bodies auditing AI management systems was published on 7 July 2025, alongside the impact-assessment standard of May 2025.</description>
    </item>
    <item>
      <title>DORA: the subcontracting technical standard was published on 2 July 2025</title>
      <link>https://grcide.com/radar#dora-subcontracting-rts</link>
      <guid isPermaLink="false">https://grcide.com/radar#dora-subcontracting-rts</guid>
      <pubDate>Wed, 02 Jul 2025 00:00:00 +0000</pubDate>
      <description>Delegated Regulation (EU) 2025/532 sets what a financial entity must determine before ICT services supporting critical or important functions are subcontracted.</description>
    </item>
    <item>
      <title>Vietnam: the personal data protection law has been in force since 1 January 2026</title>
      <link>https://grcide.com/radar#vietnam-personal-data-protection-law</link>
      <guid isPermaLink="false">https://grcide.com/radar#vietnam-personal-data-protection-law</guid>
      <pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate>
      <description>Law No. 91/2025/QH15, passed on 26 June 2025, took effect on 1 January 2026 and caps cross-border transfer fines at five per cent of turnover.</description>
    </item>
    <item>
      <title>UN Regulation No 155: Supplement 3 entered into force on 10 January 2025</title>
      <link>https://grcide.com/radar#un-r155-supplement-3</link>
      <guid isPermaLink="false">https://grcide.com/radar#un-r155-supplement-3</guid>
      <pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate>
      <description>The consolidated R155 text republished in the Official Journal as 2025/5 incorporates all valid text up to Supplement 3 to the original version.</description>
    </item>
    <item>
      <title>Chile: Ley N° 21.719 is in force from 1 December 2026</title>
      <link>https://grcide.com/radar#chile-ley-21719</link>
      <guid isPermaLink="false">https://grcide.com/radar#chile-ley-21719</guid>
      <pubDate>Fri, 13 Dec 2024 00:00:00 +0000</pubDate>
      <description>Published on 13 December 2024, the law rewrites Chile's data protection regime and creates a supervisory agency, in force from 1 December 2026.</description>
    </item>
    <item>
      <title>NIST CSF 2.0 restructured the Core around six Functions</title>
      <link>https://grcide.com/radar#nist-csf-2-0</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-csf-2-0</guid>
      <pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate>
      <description>The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29, with Govern at the centre of a six-Function Core.</description>
    </item>
    <item>
      <title>EU Data Act: switching charges end on 12 January 2027</title>
      <link>https://grcide.com/radar#eu-data-act-switching-charges</link>
      <guid isPermaLink="false">https://grcide.com/radar#eu-data-act-switching-charges</guid>
      <pubDate>Wed, 13 Dec 2023 00:00:00 +0000</pubDate>
      <description>Article 29 bars any switching charge for cloud and other data processing services from 12 January 2027, and already caps the reduced charges allowed until then.</description>
    </item>
  </channel>
</rss>
