Topic
US
5 guides on US — practical, audit-tested, and honest about the hard parts.
CCPA & CPRA: California’s Privacy Laws Explained
The CCPA, strengthened by the CPRA, gives Californians broad data rights and creates obligations for businesses worldwide. Who’s in scope, the rights, and how to comply.
8 min read · 29 May 2026
NYDFS Part 500: A Cybersecurity Compliance Guide for Financial Services
New York’s 23 NYCRR Part 500 sets binding cybersecurity rules for licensed financial firms. The core requirements, the Amendment 2 changes, and how to comply.
8 min read · 19 June 2026
NIST AI Risk Management Framework: Governing AI in Practice
The NIST AI RMF manages AI risk through four functions — Govern, Map, Measure, Manage. What it covers and how it complements the EU AI Act and ISO 42001.
7 min read · 1 June 2026
CMMC 2.0: A Defense Contractor’s Roadmap
Cybersecurity is now a contractual gate for US Department of Defense work. The three levels, how Level 2 maps to NIST 800-171, and how to reach certification.
9 min read · 15 June 2026
NIST 800-171: Protecting Controlled Unclassified Information
The control set behind CMMC Level 2. The 14 families, the SPRS score, the mandatory SSP, and how to close the gaps and keep your score defensible.
8 min read · 9 June 2026