Infosec Standards is live
The catalog, first-contact standard pages, news follows, and What applies? picker are live. This is an educational site operated by Aeris Secure.
The catalog, first-contact standard pages, news follows, and What applies? picker are live. This is an educational site operated by Aeris Secure.
The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.
Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.
On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.
HHS OCR resolved a 2021 ransomware investigation with OSF Healthcare System for risk analysis, impermissible disclosure, and late breach-notification failures.
Introducing Infosec Standards, a plain-language catalog for security compliance standards.
The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.
HHS OCR’s proposed Security Rule update is now a long-term action with a projected final action date of July 2027. The current Security Rule stays in force.
On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.
On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.
In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.
On January 25, 2013, HHS published the HIPAA Omnibus Final Rule. It took effect March 26, 2013, with a compliance date of September 23, 2013, and remains the rule set in force today.