ISO/IEC 27017:2026 cloud security standard published
ISO and IEC publish the second edition of ISO/IEC 27017, updating cloud security controls to align with ISO/IEC 27002:2022.
Updates to the standards and frameworks we consult and audit against.
ISO and IEC publish the second edition of ISO/IEC 27017, updating cloud security controls to align with ISO/IEC 27002:2022.
Stricter Cyber Essentials requirements apply from today, with MFA failures and unpatched critical vulnerabilities now resulting in automatic failure.
The three-year transition to ISO/IEC 27001:2022 has ended; certificates against the 2013 edition are no longer valid.
The CCB has published CyFun 2025, with more emphasis on supply chain and operational technology security.
The revised ISO/IEC 27701 can now be implemented and certified independently of ISO/IEC 27001.
ISO and IEC publish the third edition of ISO/IEC 27018, aligned to ISO/IEC 27002:2022, for protecting PII in public clouds.
CAF v4.0 responds to the growing threat, with new emphasis on threat understanding, secure software and AI-related risks.
Updated Cyber Essentials requirements and the new Willow question set apply to assessments from today.
The future-dated requirements in PCI DSS v4.0 become mandatory, including targeted risk analyses, wider MFA and payment page script controls.
The US launches the Cyber Trust Mark, a voluntary FCC security label for consumer IoT products.
Australia’s Protective Security Policy Framework Release 2024 restructures government security requirements and adds new risk and technology domains.
NIST publishes FIPS 203, 204 and 205, the first finalised post-quantum cryptography standards.