EU Cyber Resilience Act reporting rules kick in September 2026: what engineers need to know
The EU Cyber Resilience Act's incident reporting obligations take effect on 11 September 2026, requiring any company selling a product with digital elements in Europe to notify ENISA within 24 hours of discovering an actively exploited vulnerability. The piece traces how SOC 2 emerged from the misuse of the AICPA's 1992 SAS 70 auditing standard, which was originally designed for financial reporting controls but was wrongly treated by vendors as proof of security. In 2010, the AICPA split the standard into SOC 1, covering financial controls, and SOC 2, which introduced a defined set of security criteria. Unlike SOC 1, SOC 2 specifies what must be true about a system's security posture but leaves implementation choices to the organisation. A key distinction is drawn between Type I reports, which assess controls at a single point in time, and Type II reports, which evaluate whether controls operated effectively over a sustained period — typically six months — making continuous evidence collection essential.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in