UINAT
NewsRankingsCompaniesGuidesBreachesCompliance
TagsAbout
Home/Compliance

Compliance & Regulations

GDPR, HIPAA, NIST, SOC2, and other regulatory compliance guides and updates.

HITRUST CSF: Healthcare Security Certification Framework

HITRUST CSF provides a certifiable security framework that harmonizes over 60 regulations including HIPAA, NIST, and ISO 27001. The framework offers three assessment types (e1, i1, r2) for organizations handling healthcare and sensitive data.

February 2, 2026 HITRUSThealthcareHIPAA

NIST SP 800-53 Rev 5: Security and Privacy Controls for Federal Systems

NIST SP 800-53 provides the comprehensive catalog of security and privacy controls required for federal information systems. Rev 5.2.0 includes 1,007 controls across 20 families and serves as the foundation for FedRAMP, FISMA, and federal contractor compliance.

February 2, 2026 NIST 800-53federalFISMA

NY DFS Cybersecurity Regulation (23 NYCRR 500): Financial Services Requirements

New York's cybersecurity regulation for financial services requires covered entities to maintain comprehensive security programs including CISO designation, MFA, encryption, and incident reporting. The 2023 amendments are fully effective as of November 2025.

February 2, 2026 NY DFSfinancial servicescybersecurity

EU NIS2 Directive: Implementation Status and Compliance Requirements in 2026

The NIS2 Directive required EU member state transposition by October 2024, but most states missed the deadline. Germany enacted its law in December 2025. Full compliance landscape overview.

January 29, 2026 NIS2EUcybersecurity regulation

HIPAA Security Rule Overhaul: What the 2026 Proposed Changes Mean for Healthcare

HHS proposed sweeping changes to the HIPAA Security Rule in January 2025, eliminating the addressable vs. required distinction and mandating encryption and MFA. Finalization targeted for May 2026.

January 28, 2026 HIPAAhealthcareencryption

SEC Cybersecurity Disclosure Rules: 2026 Enforcement Outlook and Compliance Update

The SEC's cybersecurity disclosure rules face political uncertainty under the new administration. The SolarWinds case was dismissed, but the new CETU signals continued enforcement focus.

January 25, 2026 SECdisclosurepublic companies

ISO 27001:2022 Transition Complete: What Happens If You Missed the Deadline

The three-year transition period to ISO 27001:2022 ended on October 31, 2025. All ISO 27001:2013 certifications have expired. Here's what organizations need to know now.

January 15, 2026 ISO 27001ISMScertification

NIST Cybersecurity Framework 2.0: Implementation Guide

Practical guidance for implementing NIST CSF 2.0's new Govern function and updated framework components in your organization.

January 21, 2025 NIST CSFgovernancerisk management

PCI DSS 4.0 Migration: What You Need to Know Before March 2025 Deadline

Complete guide to PCI DSS 4.0 requirements, key changes from 3.2.1, and timeline for compliance with the new payment card security standard.

January 12, 2025 PCI DSSpayment securitycompliance

GDPR Data Processing Agreements: Requirements and Best Practices

Understanding the key requirements for GDPR-compliant data processing agreements between controllers and processors.

January 11, 2025 GDPRDPAdata processing

SOC 2 Type II Audit Preparation Checklist

A comprehensive checklist for preparing your organization for a SOC 2 Type II audit, covering all five Trust Service Criteria.

January 4, 2025 SOC 2auditcompliance
‹ Prev
12
Next ›
SYS ONLINE
PAGES 963
UPDATED 2026-02-06
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

// Sections

  • › News
  • › Rankings
  • › Companies
  • › Breaches

// Resources

  • › Guides
  • › Compliance
  • › Tags
  • › About

// Feeds

  • › All Content
  • › News Only
  • › Breaches Only

> © 2026 UINAT. All rights reserved.

[ DEFEND THE PERIMETER ]

Search