Mercedes-Benz Dealer ISO 27001 & TISAX Certification Deadline 2026
by Robbie Harriman on July 30, 2026 at 11:00 AM
If you lead IT, security, or compliance at a Mercedes-Benz dealership, you have probably already seen the note buried in your dealer communications: Mercedes-Benz now expects its dealer network to stand up a qualified information security program, backed by ISO 27001, TISAX Level 2 ce …
SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means
by Kyle Daun on July 29, 2026 at 4:14 PM
A question has been coming up recently among people who work with e-commerce merchants, and it can be a real head-scratcher the first time you hit it. A small merchant qualifies for SAQ A and notices that Requirements 6.4.3 and 11.6.1 are simply gone from the form. A larger merchant w …
“We Don’t Use AI” Is a Claim, Not a Control
by Kelly O’Brien on July 24, 2026 at 1:53 PM
A question we hear often from clients sounds simple on its face: Our company says it doesn’t use AI, and our acceptable use policy says the same. How do we actually prove our employees aren’t using it? It is a fair question, and the honest answer is uncomfortable. A written policy sta …
How to Define Your Cardholder Data Environment (CDE) Under PCI DSS
by Patrick Hughes on June 28, 2026 at 1:30 PM
Before an organization can implement Payment Card Industry Data Security Standard (PCI DSS) controls, it must answer a foundational question: what is in scope? The answer lies in the definition of the Cardholder Data Environment (CDE). Get it wrong, and everything built on top of it i …
Plan of Action and Milestones (POA&M): A CMMC Level 2 Essential
by Jake Dwares on June 27, 2026 at 11:00 AM
Every CMMC Level 2 compliance program involves two documents that work in tandem: the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M). The SSP describes how practices are implemented. The POA&M documents what is not yet implemented and what the organiz …
Your CMMC SSP Is Not Just a Checkbox: How to Build One That Works
by Derek Boczenowski on June 26, 2026 at 1:24 PM
The System Security Plan (SSP) is the cornerstone document of any CMMC Level 2 compliance program. Yet it is also one of the most underdeveloped artifacts assessors encounter. Organizations preparing for a C3PAO assessment frequently arrive with an SSP that describes their environment …
.webp?width=2169&height=526&name=Compass%20regular%20transparent%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)



%20Under%20PCI%20DSS.jpg)

