<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GRCIDE</title>
    <link>https://grcide.com/insights</link>
    <description>Working methods and regulatory briefings for security governance, risk and compliance practitioners.</description>
    <language>en</language>
    <atom:link href="https://grcide.com/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Thu, 03 Sep 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>AI governance stand-up under the EU AI Act</title>
      <link>https://grcide.com/engagement-patterns/ai-governance-standup</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/ai-governance-standup</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Choosing a GRC framework: what each instrument actually is</title>
      <link>https://grcide.com/reference/grc-framework-selection</link>
      <guid isPermaLink="false">https://grcide.com/reference/grc-framework-selection</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Certifiable standard, outcome framework, attestation report or sector standard: what each GRC instrument produces, and which one a given driver calls for.</description>
      <category>governance</category>
    </item>
    <item>
      <title>Building an ISMS people actually use</title>
      <link>https://grcide.com/playbooks/isms-people-actually-use</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/isms-people-actually-use</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>A method for standing up an ISO/IEC 27001 management system that produces evidence in daily operation instead of a binder assembled before the audit.</description>
      <category>governance</category>
    </item>
    <item>
      <title>ISO 27001 first certification</title>
      <link>https://grcide.com/engagement-patterns/iso27001-first-certification</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/iso27001-first-certification</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>The shape of a first certification cycle: scope, risk assessment and treatment, the operating record, and the evidence an accredited body reads.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>NIS2 for the security officer</title>
      <link>https://grcide.com/briefings/nis2-for-the-security-officer</link>
      <guid isPermaLink="false">https://grcide.com/briefings/nis2-for-the-security-officer</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>NIS2 readiness for an important entity</title>
      <link>https://grcide.com/engagement-patterns/nis2-readiness-important-entity</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/nis2-readiness-important-entity</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Product cybersecurity under R155, ISO 21434 and the CRA</title>
      <link>https://grcide.com/engagement-patterns/product-cybersecurity-r155-cra</link>
      <guid isPermaLink="false">https://grcide.com/engagement-patterns/product-cybersecurity-r155-cra</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Risk register template</title>
      <link>https://grcide.com/templates/risk-register</link>
      <guid isPermaLink="false">https://grcide.com/templates/risk-register</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.</description>
      <category>risk</category>
    </item>
    <item>
      <title>The risk register other people trust</title>
      <link>https://grcide.com/playbooks/risk-register-people-trust</link>
      <guid isPermaLink="false">https://grcide.com/playbooks/risk-register-people-trust</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
      <description>Risk statements that name a source, an event and a consequence; scales that survive argument; and every row closed by a named approver on a dated decision.</description>
      <category>risk</category>
    </item>
    <item>
      <title>EU AI Act: high-risk dates deferred, two prohibitions added</title>
      <link>https://grcide.com/radar#ai-act-high-risk-deferral</link>
      <guid isPermaLink="false">https://grcide.com/radar#ai-act-high-risk-deferral</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Digital Omnibus on AI moves the high-risk obligations to December 2027 and August 2028, and adds two prohibited practices from December 2026.</description>
    </item>
    <item>
      <title>CER Directive: Swedish bill proposes entry into force on 1 January 2027</title>
      <link>https://grcide.com/radar#cer-directive-swedish-bill</link>
      <guid isPermaLink="false">https://grcide.com/radar#cer-directive-swedish-bill</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Sweden's bill implementing the critical entities resilience directive was laid before the Riksdag on 14 July 2026, proposing effect from 1 January 2027.</description>
    </item>
    <item>
      <title>ECE R155 vs ISO 21434: Five Common Misreads That Get Caught in Audit</title>
      <link>https://grcide.com/briefings/r155-vs-iso21434-five-misreads</link>
      <guid isPermaLink="false">https://grcide.com/briefings/r155-vs-iso21434-five-misreads</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>R155 mandates the framework; ISO 21434 describes how to build it. Treating them as interchangeable is where most first-time audits go sideways.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>The 90-day SOC 2 Type 1 plan</title>
      <link>https://grcide.com/briefings/soc2-type1-90-day-plan</link>
      <guid isPermaLink="false">https://grcide.com/briefings/soc2-type1-90-day-plan</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>A week-by-week sequence for a first SOC 2 type 1 examination: scope, policy set, evidence pipeline, risk assessment, fieldwork.</description>
      <category>compliance</category>
    </item>
    <item>
      <title>Cyber Resilience Act: manufacturer reporting starts on 11 September 2026</title>
      <link>https://grcide.com/radar#cra-reporting-obligations</link>
      <guid isPermaLink="false">https://grcide.com/radar#cra-reporting-obligations</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>Article 14 applies from 11 September 2026, ahead of full application on 11 December 2027, and it reaches products already placed on the market.</description>
    </item>
    <item>
      <title>NIS2: Sweden's Cybersecurity Act took effect on 15 January 2026</title>
      <link>https://grcide.com/radar#nis2-swedish-cybersecurity-act</link>
      <guid isPermaLink="false">https://grcide.com/radar#nis2-swedish-cybersecurity-act</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate>
      <description>Cybersäkerhetslag (2025:1506) entered into force on 15 January 2026, fifteen months after the directive's transposition date of 17 October 2024.</description>
    </item>
    <item>
      <title>GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026</title>
      <link>https://grcide.com/radar#gb-44495-44496-in-force</link>
      <guid isPermaLink="false">https://grcide.com/radar#gb-44495-44496-in-force</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate>
      <description>China's mandatory vehicle cybersecurity and software-update standards moved from issued to in force on 1 January 2026, seventeen months after publication.</description>
    </item>
    <item>
      <title>ISO/IEC 27001:2013 certificates stopped being valid after 31 October 2025</title>
      <link>https://grcide.com/radar#iso-27001-2022-transition-closed</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-27001-2022-transition-closed</guid>
      <pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate>
      <description>The accredited transition period set by IAF MD 26 ended on 31 October 2025; certificates naming the 2013 edition expire or are withdrawn.</description>
    </item>
    <item>
      <title>ISO/IEC 42006:2025 completes the certification route for AI management systems</title>
      <link>https://grcide.com/radar#iso-42006-certification-route</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-42006-certification-route</guid>
      <pubDate>Mon, 07 Jul 2025 00:00:00 +0000</pubDate>
      <description>The requirements standard for bodies auditing AI management systems was published on 7 July 2025, alongside the impact-assessment standard of May 2025.</description>
    </item>
    <item>
      <title>DORA: the subcontracting technical standard was published on 2 July 2025</title>
      <link>https://grcide.com/radar#dora-subcontracting-rts</link>
      <guid isPermaLink="false">https://grcide.com/radar#dora-subcontracting-rts</guid>
      <pubDate>Wed, 02 Jul 2025 00:00:00 +0000</pubDate>
      <description>Delegated Regulation (EU) 2025/532 sets what a financial entity must determine before ICT services supporting critical or important functions are subcontracted.</description>
    </item>
    <item>
      <title>UN Regulation No 155: Supplement 3 entered into force on 10 January 2025</title>
      <link>https://grcide.com/radar#un-r155-supplement-3</link>
      <guid isPermaLink="false">https://grcide.com/radar#un-r155-supplement-3</guid>
      <pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate>
      <description>The consolidated R155 text republished in the Official Journal as 2025/5 incorporates all valid text up to Supplement 3 to the original version.</description>
    </item>
    <item>
      <title>NIST CSF 2.0 restructured the Core around six Functions</title>
      <link>https://grcide.com/radar#nist-csf-2-0</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-csf-2-0</guid>
      <pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate>
      <description>The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29, with Govern at the centre of a six-Function Core.</description>
    </item>
  </channel>
</rss>
