<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Infosec Standards News</title>
    <link>https://infosecstandards.org/news</link>
    <description>Plain-language help for anyone facing a security compliance standard: what applies, what it costs, and how to move forward.</description>
    <language>en-us</language>
    <atom:link href="https://infosecstandards.org/news/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Infosec Standards is live</title>
      <link>https://infosecstandards.org/news/site-launch</link>
      <guid>https://infosecstandards.org/news/site-launch</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>The catalog, first-contact standard pages, news follows, and What applies? picker are live. This is an educational site operated by Aeris Secure.</description>
    </item>
    <item>
      <title>Standard pages now say who decides your obligation, and what to ask them</title>
      <link>https://infosecstandards.org/news/who-decides-what-to-ask</link>
      <guid>https://infosecstandards.org/news/who-decides-what-to-ask</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>The HIPAA, PCI DSS, CMMC, and SOC 2 pages each gained a section naming the party that actually sets your obligation and the questions to put to them in writing. HIPAA and SOC 2 also gained a first-decision picker.</description>
    </item>
    <item>
      <title>Infosec Standards now has a free, browser-only risk assessment tool</title>
      <link>https://infosecstandards.org/news/risk-assessment-tool</link>
      <guid>https://infosecstandards.org/news/risk-assessment-tool</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description>Infosec Standards now has a guided, NIST SP 800-30 based risk assessment tool. Everything stays in your browser; you leave with a JSON file to resume from, a spreadsheet register, and a printable report.</description>
    </item>
    <item>
      <title>PCI SSC revises FAQ 1331 on using SAQs to scope ROC assessments</title>
      <link>https://infosecstandards.org/news/pci-dss-roc-saq-guide</link>
      <guid>https://infosecstandards.org/news/pci-dss-roc-saq-guide</guid>
      <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
      <description>On August 4, 2026, PCI SSC updated FAQ 1331 so merchants cannot use SAQ eligibility criteria to decide ROC applicability without Compliance Accepting Entity agreement.</description>
    </item>
    <item>
      <title>OCR settles HIPAA ransomware case with OSF Healthcare for $552,250</title>
      <link>https://infosecstandards.org/news/hipaa-osf-settlement</link>
      <guid>https://infosecstandards.org/news/hipaa-osf-settlement</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <description>HHS OCR resolved a 2021 ransomware investigation with OSF Healthcare System for risk analysis, impermissible disclosure, and late breach-notification failures.</description>
    </item>
    <item>
      <title>Welcome to Infosec Standards</title>
      <link>https://infosecstandards.org/news/welcome</link>
      <guid>https://infosecstandards.org/news/welcome</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <description>Introducing Infosec Standards, a plain-language catalog for security compliance standards.</description>
    </item>
    <item>
      <title>CMMC Phase 2 third-party assessments put on hold</title>
      <link>https://infosecstandards.org/news/cmmc-phase-2-suspended</link>
      <guid>https://infosecstandards.org/news/cmmc-phase-2-suspended</guid>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
      <description>The Defense Department suspended the November 2026 ramp-up of CMMC Level 2 third-party assessments and opened a short review of the program. Phase 1 self-assessment rules stay in force.</description>
    </item>
    <item>
      <title>HIPAA Security Rule overhaul pushed to July 2027 on the federal agenda</title>
      <link>https://infosecstandards.org/news/hipaa-security-rule-delay</link>
      <guid>https://infosecstandards.org/news/hipaa-security-rule-delay</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate>
      <description>HHS OCR’s proposed Security Rule update is now a long-term action with a projected final action date of July 2027. The current Security Rule stays in force.</description>
    </item>
    <item>
      <title>CMMC Program rule published as 32 CFR Part 170</title>
      <link>https://infosecstandards.org/news/cmmc-final-rule</link>
      <guid>https://infosecstandards.org/news/cmmc-final-rule</guid>
      <pubDate>Tue, 15 Oct 2024 00:00:00 GMT</pubDate>
      <description>On October 15, 2024, DoD published the CMMC Program final rule. It took effect December 16, 2024 and is the current CMMC 2.0 program regulation.</description>
    </item>
    <item>
      <title>PCI DSS v4.0.1 is the current standard</title>
      <link>https://infosecstandards.org/news/pci-dss-v4-0-1</link>
      <guid>https://infosecstandards.org/news/pci-dss-v4-0-1</guid>
      <pubDate>Tue, 11 Jun 2024 00:00:00 GMT</pubDate>
      <description>On June 11, 2024, PCI SSC published PCI DSS v4.0.1, a limited revision of v4.0. Future-dated v4 requirements became mandatory on March 31, 2025.</description>
    </item>
    <item>
      <title>SOC 2 Trust Services Criteria points of focus revised in 2022</title>
      <link>https://infosecstandards.org/news/soc-2-2022-points-of-focus</link>
      <guid>https://infosecstandards.org/news/soc-2-2022-points-of-focus</guid>
      <pubDate>Sat, 01 Oct 2022 00:00:00 GMT</pubDate>
      <description>In October 2022, AICPA revised the points of focus that support the 2017 Trust Services Criteria. The criteria themselves did not change. This remains the current SOC 2 basis.</description>
    </item>
    <item>
      <title>HIPAA Omnibus Rule is the current HIPAA rule set</title>
      <link>https://infosecstandards.org/news/hipaa-omnibus-rule</link>
      <guid>https://infosecstandards.org/news/hipaa-omnibus-rule</guid>
      <pubDate>Fri, 25 Jan 2013 00:00:00 GMT</pubDate>
      <description>On January 25, 2013, HHS published the HIPAA Omnibus Final Rule. It took effect March 26, 2013, with a compliance date of September 23, 2013, and remains the rule set in force today.</description>
    </item>
  </channel>
</rss>
