Trends

Developments we are actively tracking. Each trend keeps a dated log of what changed and links every article we publish about it.

active

EU Cyber Resilience Act reporting begins

Manufacturers of products with digital elements sold in the EU must now report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. Full CRA obligations follow in December 2027.

Updated 11 Sept 20261 articles
emerging

ISO 9001:2026 transition

ISO 9001:2026 replaces the 2015 edition. Certified organisations have until 30 September 2029 to transition, and certification bodies must plan three years of transition audits.

Updated 16 Sept 20261 articles
active

DPDP Rules phased rollout

India's DPDP Rules, 2025 phase in over 18 months. The Data Protection Board is operational, consent managers follow in November 2026, and core fiduciary obligations apply from May 2027.

Updated 13 Nov 20251 articles
emerging

RBI cyber security directions 2026

RBI's 2026 directions replace the 2016 cyber security framework for regulated entities. Seed trend: confirm scope and dates with the RBI circular before publishing.

Updated 31 Jul 20260 articles
active

NIS2 transposition across the EU

NIS2 was due in national law by October 2024; most member states have now transposed it and supervisors are moving from policy reviews to evidence.

Updated 31 May 20260 articles
active

HIPAA Security Rule update

HHS proposed the first major update to the HIPAA Security Rule in over a decade. Seed trend: confirm the rule's current status before publishing.

Updated 6 Jan 20250 articles
active

AI management systems move into audit scope

Organisations building or deploying AI are being asked for the same evidence discipline they already apply to information security. ISO/IEC 42001 gives auditors a certifiable management-system baseline, and customer questionnaires increasingly ask for it.

Updated 20 Sept 20263 articles
active

DORA moves from rulebook to supervision

The Digital Operational Resilience Act has applied since 17 January 2025. Attention has moved from reading the rules to proving them: registers of information, incident reporting and oversight of critical ICT providers.

Updated 15 Sept 20261 articles