Radar digest: September 2026
Six entries joined the radar this month: guidance, codes and national acts that change what a program has to show rather than who is in scope.
5 Sept 20261 min read
Six entries joined the radar this month, and most of them describe the same movement: a duty that already existed being handed a method, a deadline, or a document it has to answer to.
Nothing below widens a scope. The Cyber Resilience Act guidance does not change who has to report; it records how the Commission reads the questions manufacturers kept asking. The AI Act code and guidelines move no date; they set out what a marking or a labelling control has to show. The Dutch acts transpose two directives whose obligations were already known. The two Chinese instruments turn an audit duty and an assessment duty into a published method and a fixed cycle. Even the reissued ransomware profile is an older document re-cut to the framework it now hangs from.
So the work the month asks for is evidence work: a reporting path that has been rehearsed, a marking rule written down, an assessment cycle with a named owner, a register entry filed. Guidance that binds nobody still sets the reading an authority starts from, which is why the non-binding entries are the ones worth reading twice.
Take the entries whose clock is already running first; each row below carries its own date. The rest change what a supervisor expects to see rather than who is standing in front of one.
This month on the radar
CN data risk
China: annual network data risk assessments from 20 August 2026
- Affected
- Network data processors handling important data inside China, and the assessment bodies they engage.
- Action
- Fix the annual assessment cycle, name the owner, and settle the filing route to the competent department or the provincial cyberspace authority.
NIS2 NL
Netherlands: the NIS2 and CER acts took effect on 15 August 2026
- Affected
- Essential and important entities, and critical entities, where those operations sit in the Netherlands.
- Action
- Register in the national register, and, for the listed digital service categories, file the ENISA register information within one month of 15 August 2026.
CRA guidance
Cyber Resilience Act: the Commission's application guidance, 27 July 2026
- Affected
- Manufacturers of products with digital elements placed on the EU market, and the importers and distributors behind them.
- Action
- Re-test the scope decision and the support period against the guidance, then rehearse the reporting path before 11 September 2026.
AI Act Art. 50
EU AI Act: the transparency code and guidelines arrived before 2 August 2026
- Affected
- Providers and deployers of interactive AI systems, and of systems that generate or manipulate content.
- Action
- Decide whether to sign the code, then map each Article 50 duty to a marking, labelling or disclosure control that can be shown to work.
GB/T 46903
China: the personal information audit standard applies from 1 July 2026
- Affected
- Personal information processors operating in China, and the professional bodies engaged to audit them.
- Action
- Set the audit cycle against the ten-million threshold, then re-cut the audit programme against the standard now in force.
NIST IR 8374r1
NIST reissued the ransomware profile against CSF 2.0
- Affected
- Organisations using a shared profile to set ransomware readiness, and anyone whose control mapping still cites the 2022 profile.
- Action
- Replace the 2022 profile wherever it is cited, and add the governance outcomes the older Core did not carry.
This month in insights
5 Sept 2026
Agent governance is a permissions problem before it is a model problem
Singapore's advisory on the OpenClaw agent platform moves AI risk from what a model says to what an agent can do. The controls it lists are identity controls.
5 Sept 2026
CRA in fifteen months: what to do first
Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.
5 Sept 2026
Open-source risk is a maintainer problem, not a CVE count
A Chinese-language piece argues that open-source risk lives in maintainers and funding, not in CVE queues. We agree, and add the control it implies.
5 Sept 2026
The board question is not the CVE count
A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.
The digest by email
One note a month, the same page in your inbox. Nothing else is sent to the list.