Safeguard
Topic

Compliance

In-depth guides and analysis on compliance from the Safeguard engineering team.

304 articles

Compliance

Board-level reporting on application security risk

Boards now face legal disclosure deadlines on cyber risk. Here's what belongs in a board-level appsec report, how often to deliver it, and what the SEC and NYDFS require.

May 7, 20267 min read
Compliance

Cyber insurance requirements for application security programs

Cyber insurers now require SBOMs, patch SLAs, and audit trails for AppSec programs. Here's what carriers actually ask for and how to pass renewal.

May 7, 20266 min read
Compliance

EO 14144 to EO 14306: How the Federal Software Mandate Evolved

EO 14144 set ambitious supply chain rules for federal software in January 2025. EO 14306 in June reshaped them. Here is what survived, what changed, and what to plan for.

May 6, 20266 min read
Compliance

NIS2 in the Netherlands: Cyberbeveiligingswet Adoption in April 2026

The Dutch Parliament approved the Cyberbeveiligingswet on 15 April 2026, with target entry into force on 1 July 2026 — 21 months after the EU transposition deadline.

May 6, 20267 min read
Compliance

NYDFS Part 500: The November 2025 Deadlines, One Year On

The Second Amendment to NYDFS Part 500 added universal MFA and an asset inventory mandate on November 1, 2025. The April 2026 certification reveals where covered entities stand.

May 6, 20266 min read
Compliance

Software License Examples and Why They Matter for Security

A software license example is more than boilerplate — it defines your obligations and your risk. Here is how to read common licenses and enforce them at scale.

May 6, 20265 min read
Compliance

Can You Use Apache License 2.0 in Commercial Products?

The Apache License 2.0 permits commercial use, modification, and distribution without royalties. The catch is a short list of obligations around notices and patents that you have to honor.

May 5, 20265 min read
Compliance

Does AI pentesting satisfy SOC 2, ISO 27001, HIPAA or PCI...

AI-powered pentesting promises fast compliance checkmarks, but SOC 2, ISO 27001, HIPAA, and PCI DSS 4.0 auditors require more than an automated scan report.

May 4, 20267 min read
Compliance

NIST 800-171 Rev. 3 and the DoD Class Deviation: Stuck on Rev. 2

NIST published 800-171 Rev. 3 on May 14, 2024. Twelve days earlier, DoD froze DFARS 7012 to Rev. 2 via Class Deviation 2024-O0013.

May 3, 20266 min read
Compliance

NIST Secure Coding Standards: What They Require and How to Meet Them

NIST secure coding standards are not one document but a set of practices spread across SSDF, SP 800-53, and the SAMATE guidance. Here is what each one asks of your team.

May 3, 20265 min read
Compliance

NIST SP 800-218: How the Secure Software Development Framework (SSDF) Works

NIST SP 800-218, the Secure Software Development Framework, gives software producers a set of outcome-based practices for building software with fewer vulnerabilities. Here is how to read and apply it.

May 3, 20266 min read
Compliance

Software Licensing Options Explained: A Security and Compliance Guide

Your software licensing options fall into a handful of families, and each one carries obligations that show up in audits. Here is how to read a license before it reads you.

May 2, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Compliance (Page 11) — Supply Chain Security Blog | Safeguard