{
	"version": "https://jsonfeed.org/version/1.1",
	"title": "Infosec Standards News",
	"description": "Plain-language help for anyone facing a security compliance standard: what applies, what it costs, and how to move forward.",
	"home_page_url": "https://infosecstandards.org/news",
	"feed_url": "https://infosecstandards.org/news/feed.json",
	"authors": [
		{
			"name": "Infosec Standards",
			"url": "https://infosecstandards.org"
		}
	],
	"language": "en-US",
	"items": [
		{
			"id": "https://infosecstandards.org/news/site-launch",
			"url": "https://infosecstandards.org/news/site-launch",
			"title": "Infosec Standards is live",
			"summary": "The catalog, first-contact standard pages, news follows, and What applies? picker are live. This is an educational site operated by Aeris Secure.",
			"content_text": "The catalog, first-contact standard pages, news follows, and What applies? picker are live. This is an educational site operated by Aeris Secure.",
			"date_published": "2026-09-03T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"url": "https://infosecstandards.org/news/who-decides-what-to-ask",
			"title": "Standard pages now say who decides your obligation, and what to ask them",
			"summary": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"content_text": "The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.",
			"date_published": "2026-09-03T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/risk-assessment-tool",
			"url": "https://infosecstandards.org/news/risk-assessment-tool",
			"title": "Infosec Standards now has a free, browser-only risk assessment tool",
			"summary": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"content_text": "Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.",
			"date_published": "2026-09-02T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/pci-dss-roc-saq-guide",
			"url": "https://infosecstandards.org/news/pci-dss-roc-saq-guide",
			"title": "PCI SSC revises FAQ 1331 on using SAQs to scope ROC assessments",
			"summary": "On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.",
			"content_text": "On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.",
			"date_published": "2026-08-10T00:00:00.000Z",
			"tags": [
				"program-changes",
				"email-all"
			]
		},
		{
			"id": "https://infosecstandards.org/news/hipaa-osf-settlement",
			"url": "https://infosecstandards.org/news/hipaa-osf-settlement",
			"title": "OCR settles HIPAA ransomware case with OSF Healthcare for $552,250",
			"summary": "HHS OCR resolved a 2021 ransomware investigation with OSF Healthcare System for risk analysis, impermissible disclosure, and late breach-notification failures.",
			"content_text": "HHS OCR resolved a 2021 ransomware investigation with OSF Healthcare System for risk analysis, impermissible disclosure, and late breach-notification failures.",
			"date_published": "2026-08-06T00:00:00.000Z",
			"tags": [
				"enforcement",
				"breaches",
				"email-all"
			]
		},
		{
			"id": "https://infosecstandards.org/news/welcome",
			"url": "https://infosecstandards.org/news/welcome",
			"title": "Welcome to Infosec Standards",
			"summary": "Introducing Infosec Standards, a plain-language catalog for security compliance standards.",
			"content_text": "Introducing Infosec Standards, a plain-language catalog for security compliance standards.",
			"date_published": "2026-07-29T00:00:00.000Z",
			"tags": [
				"site-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/cmmc-phase-2-suspended",
			"url": "https://infosecstandards.org/news/cmmc-phase-2-suspended",
			"title": "CMMC Phase 2 third-party assessments put on hold",
			"summary": "The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.",
			"content_text": "The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.",
			"date_published": "2026-07-13T00:00:00.000Z",
			"tags": [
				"program-changes",
				"version-updates",
				"email-standard"
			]
		},
		{
			"id": "https://infosecstandards.org/news/hipaa-security-rule-delay",
			"url": "https://infosecstandards.org/news/hipaa-security-rule-delay",
			"title": "HIPAA Security Rule overhaul pushed to July 2027 on the federal agenda",
			"summary": "HHS OCR’s proposed Security Rule update is now a long-term action with a projected final action date of July 2027. The current Security Rule stays in force.",
			"content_text": "HHS OCR’s proposed Security Rule update is now a long-term action with a projected final action date of July 2027. The current Security Rule stays in force.",
			"date_published": "2026-07-06T00:00:00.000Z",
			"tags": [
				"program-changes",
				"version-updates",
				"email-standard"
			]
		},
		{
			"id": "https://infosecstandards.org/news/cmmc-final-rule",
			"url": "https://infosecstandards.org/news/cmmc-final-rule",
			"title": "CMMC Program rule published as 32 CFR Part 170",
			"summary": "On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.",
			"content_text": "On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.",
			"date_published": "2024-10-15T00:00:00.000Z",
			"tags": [
				"version-updates",
				"program-changes"
			]
		},
		{
			"id": "https://infosecstandards.org/news/pci-dss-v4-0-1",
			"url": "https://infosecstandards.org/news/pci-dss-v4-0-1",
			"title": "PCI DSS v4.0.1 is the current standard",
			"summary": "On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.",
			"content_text": "On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.",
			"date_published": "2024-06-11T00:00:00.000Z",
			"tags": [
				"version-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/soc-2-2022-points-of-focus",
			"url": "https://infosecstandards.org/news/soc-2-2022-points-of-focus",
			"title": "SOC 2 Trust Services Criteria points of focus revised in 2022",
			"summary": "In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.",
			"content_text": "In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.",
			"date_published": "2022-10-01T00:00:00.000Z",
			"tags": [
				"version-updates"
			]
		},
		{
			"id": "https://infosecstandards.org/news/hipaa-omnibus-rule",
			"url": "https://infosecstandards.org/news/hipaa-omnibus-rule",
			"title": "HIPAA Omnibus Rule is the current HIPAA rule set",
			"summary": "On January 25, 2013, HHS published the HIPAA Omnibus Final Rule. It took effect March 26, 2013, with a compliance date of September 23, 2013, and remains the rule set in force today.",
			"content_text": "On January 25, 2013, HHS published the HIPAA Omnibus Final Rule. It took effect March 26, 2013, with a compliance date of September 23, 2013, and remains the rule set in force today.",
			"date_published": "2013-01-25T00:00:00.000Z",
			"tags": [
				"version-updates"
			]
		}
	]
}
