Compliance
In-depth guides and analysis on compliance from the Safeguard engineering team.
304 articles
Board-level reporting on application security risk
Boards now face legal disclosure deadlines on cyber risk. Here's what belongs in a board-level appsec report, how often to deliver it, and what the SEC and NYDFS require.
Cyber insurance requirements for application security programs
Cyber insurers now require SBOMs, patch SLAs, and audit trails for AppSec programs. Here's what carriers actually ask for and how to pass renewal.
EO 14144 to EO 14306: How the Federal Software Mandate Evolved
EO 14144 set ambitious supply chain rules for federal software in January 2025. EO 14306 in June reshaped them. Here is what survived, what changed, and what to plan for.
NIS2 in the Netherlands: Cyberbeveiligingswet Adoption in April 2026
The Dutch Parliament approved the Cyberbeveiligingswet on 15 April 2026, with target entry into force on 1 July 2026 — 21 months after the EU transposition deadline.
NYDFS Part 500: The November 2025 Deadlines, One Year On
The Second Amendment to NYDFS Part 500 added universal MFA and an asset inventory mandate on November 1, 2025. The April 2026 certification reveals where covered entities stand.
Software License Examples and Why They Matter for Security
A software license example is more than boilerplate — it defines your obligations and your risk. Here is how to read common licenses and enforce them at scale.
Can You Use Apache License 2.0 in Commercial Products?
The Apache License 2.0 permits commercial use, modification, and distribution without royalties. The catch is a short list of obligations around notices and patents that you have to honor.
Does AI pentesting satisfy SOC 2, ISO 27001, HIPAA or PCI...
AI-powered pentesting promises fast compliance checkmarks, but SOC 2, ISO 27001, HIPAA, and PCI DSS 4.0 auditors require more than an automated scan report.
NIST 800-171 Rev. 3 and the DoD Class Deviation: Stuck on Rev. 2
NIST published 800-171 Rev. 3 on May 14, 2024. Twelve days earlier, DoD froze DFARS 7012 to Rev. 2 via Class Deviation 2024-O0013.
NIST Secure Coding Standards: What They Require and How to Meet Them
NIST secure coding standards are not one document but a set of practices spread across SSDF, SP 800-53, and the SAMATE guidance. Here is what each one asks of your team.
NIST SP 800-218: How the Secure Software Development Framework (SSDF) Works
NIST SP 800-218, the Secure Software Development Framework, gives software producers a set of outcome-based practices for building software with fewer vulnerabilities. Here is how to read and apply it.
Software Licensing Options Explained: A Security and Compliance Guide
Your software licensing options fall into a handful of families, and each one carries obligations that show up in audits. Here is how to read a license before it reads you.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.