Back to the digest
    Digest

    Radar digest: September 2026

    Six entries joined the radar this month: guidance, codes and national acts that change what a program has to show rather than who is in scope.

    5 Sept 20261 min read

    Six entries joined the radar this month, and most of them describe the same movement: a duty that already existed being handed a method, a deadline, or a document it has to answer to.

    Nothing below widens a scope. The Cyber Resilience Act guidance does not change who has to report; it records how the Commission reads the questions manufacturers kept asking. The AI Act code and guidelines move no date; they set out what a marking or a labelling control has to show. The Dutch acts transpose two directives whose obligations were already known. The two Chinese instruments turn an audit duty and an assessment duty into a published method and a fixed cycle. Even the reissued ransomware profile is an older document re-cut to the framework it now hangs from.

    So the work the month asks for is evidence work: a reporting path that has been rehearsed, a marking rule written down, an assessment cycle with a named owner, a register entry filed. Guidance that binds nobody still sets the reading an authority starts from, which is why the non-binding entries are the ones worth reading twice.

    Take the entries whose clock is already running first; each row below carries its own date. The rest change what a supervisor expects to see rather than who is standing in front of one.

    This month on the radar

    • CN data risk

      China: annual network data risk assessments from 20 August 2026

      Affected
      Network data processors handling important data inside China, and the assessment bodies they engage.
      Action
      Fix the annual assessment cycle, name the owner, and settle the filing route to the competent department or the provincial cyberspace authority.
    • NIS2 NL

      Netherlands: the NIS2 and CER acts took effect on 15 August 2026

      Affected
      Essential and important entities, and critical entities, where those operations sit in the Netherlands.
      Action
      Register in the national register, and, for the listed digital service categories, file the ENISA register information within one month of 15 August 2026.
    • CRA guidance

      Cyber Resilience Act: the Commission's application guidance, 27 July 2026

      Affected
      Manufacturers of products with digital elements placed on the EU market, and the importers and distributors behind them.
      Action
      Re-test the scope decision and the support period against the guidance, then rehearse the reporting path before 11 September 2026.
    • AI Act Art. 50

      EU AI Act: the transparency code and guidelines arrived before 2 August 2026

      Affected
      Providers and deployers of interactive AI systems, and of systems that generate or manipulate content.
      Action
      Decide whether to sign the code, then map each Article 50 duty to a marking, labelling or disclosure control that can be shown to work.
    • GB/T 46903

      China: the personal information audit standard applies from 1 July 2026

      Affected
      Personal information processors operating in China, and the professional bodies engaged to audit them.
      Action
      Set the audit cycle against the ten-million threshold, then re-cut the audit programme against the standard now in force.
    • NIST IR 8374r1

      NIST reissued the ransomware profile against CSF 2.0

      Affected
      Organisations using a shared profile to set ransomware readiness, and anyone whose control mapping still cites the 2022 profile.
      Action
      Replace the 2022 profile wherever it is cited, and add the governance outcomes the older Core did not carry.

    This month in insights

    The digest by email

    One note a month, the same page in your inbox. Nothing else is sent to the list.