Compass IT Compliance Blog

Mercedes-Benz Dealer ISO 27001 & TISAX Certification Deadline 2026

Mercedes-Benz Dealer ISO 27001 & TISAX Certification Deadline 2026

If you lead IT, security, or compliance at a Mercedes-Benz dealership, you have probably already seen the note buried in your dealer communications: Mercedes-Benz now expects its dealer network to stand up a qualified information security program, backed by ISO 27001, TISAX Level 2 ce …

Read Story

SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means

SAQ A, Requirements 6.4.3 & 11.6.1: What the Eligibility Change Means

A question has been coming up recently among people who work with e-commerce merchants, and it can be a real head-scratcher the first time you hit it. A small merchant qualifies for SAQ A and notices that Requirements 6.4.3 and 11.6.1 are simply gone from the form. A larger merchant w …

Read Story

“We Don’t Use AI” Is a Claim, Not a Control

“We Don’t Use AI” Is a Claim, Not a Control

A question we hear often from clients sounds simple on its face: Our company says it doesn’t use AI, and our acceptable use policy says the same. How do we actually prove our employees aren’t using it? It is a fair question, and the honest answer is uncomfortable. A written policy sta …

Read Story

Subscribe by email