<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GRCIDE — Regulatory radar</title>
    <link>https://grcide.com/radar</link>
    <description>Changes to the instruments that land in scope: what moved, who it affects, and what it asks of a program.</description>
    <language>en</language>
    <atom:link href="https://grcide.com/radar.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Thu, 03 Sep 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>EU AI Act: high-risk dates deferred, two prohibitions added</title>
      <link>https://grcide.com/radar#ai-act-high-risk-deferral</link>
      <guid isPermaLink="false">https://grcide.com/radar#ai-act-high-risk-deferral</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Digital Omnibus on AI moves the high-risk obligations to December 2027 and August 2028, and adds two prohibited practices from December 2026.</description>
    </item>
    <item>
      <title>CER Directive: Swedish bill proposes entry into force on 1 January 2027</title>
      <link>https://grcide.com/radar#cer-directive-swedish-bill</link>
      <guid isPermaLink="false">https://grcide.com/radar#cer-directive-swedish-bill</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Sweden's bill implementing the critical entities resilience directive was laid before the Riksdag on 14 July 2026, proposing effect from 1 January 2027.</description>
    </item>
    <item>
      <title>Cyber Resilience Act: manufacturer reporting starts on 11 September 2026</title>
      <link>https://grcide.com/radar#cra-reporting-obligations</link>
      <guid isPermaLink="false">https://grcide.com/radar#cra-reporting-obligations</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>Article 14 applies from 11 September 2026, ahead of full application on 11 December 2027, and it reaches products already placed on the market.</description>
    </item>
    <item>
      <title>NIS2: Sweden's Cybersecurity Act took effect on 15 January 2026</title>
      <link>https://grcide.com/radar#nis2-swedish-cybersecurity-act</link>
      <guid isPermaLink="false">https://grcide.com/radar#nis2-swedish-cybersecurity-act</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate>
      <description>Cybersäkerhetslag (2025:1506) entered into force on 15 January 2026, fifteen months after the directive's transposition date of 17 October 2024.</description>
    </item>
    <item>
      <title>GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026</title>
      <link>https://grcide.com/radar#gb-44495-44496-in-force</link>
      <guid isPermaLink="false">https://grcide.com/radar#gb-44495-44496-in-force</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate>
      <description>China's mandatory vehicle cybersecurity and software-update standards moved from issued to in force on 1 January 2026, seventeen months after publication.</description>
    </item>
    <item>
      <title>ISO/IEC 27001:2013 certificates stopped being valid after 31 October 2025</title>
      <link>https://grcide.com/radar#iso-27001-2022-transition-closed</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-27001-2022-transition-closed</guid>
      <pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate>
      <description>The accredited transition period set by IAF MD 26 ended on 31 October 2025; certificates naming the 2013 edition expire or are withdrawn.</description>
    </item>
    <item>
      <title>ISO/IEC 42006:2025 completes the certification route for AI management systems</title>
      <link>https://grcide.com/radar#iso-42006-certification-route</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-42006-certification-route</guid>
      <pubDate>Mon, 07 Jul 2025 00:00:00 +0000</pubDate>
      <description>The requirements standard for bodies auditing AI management systems was published on 7 July 2025, alongside the impact-assessment standard of May 2025.</description>
    </item>
    <item>
      <title>DORA: the subcontracting technical standard was published on 2 July 2025</title>
      <link>https://grcide.com/radar#dora-subcontracting-rts</link>
      <guid isPermaLink="false">https://grcide.com/radar#dora-subcontracting-rts</guid>
      <pubDate>Wed, 02 Jul 2025 00:00:00 +0000</pubDate>
      <description>Delegated Regulation (EU) 2025/532 sets what a financial entity must determine before ICT services supporting critical or important functions are subcontracted.</description>
    </item>
    <item>
      <title>UN Regulation No 155: Supplement 3 entered into force on 10 January 2025</title>
      <link>https://grcide.com/radar#un-r155-supplement-3</link>
      <guid isPermaLink="false">https://grcide.com/radar#un-r155-supplement-3</guid>
      <pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate>
      <description>The consolidated R155 text republished in the Official Journal as 2025/5 incorporates all valid text up to Supplement 3 to the original version.</description>
    </item>
    <item>
      <title>NIST CSF 2.0 restructured the Core around six Functions</title>
      <link>https://grcide.com/radar#nist-csf-2-0</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-csf-2-0</guid>
      <pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate>
      <description>The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29, with Govern at the centre of a six-Function Core.</description>
    </item>
  </channel>
</rss>
