What The 2026 FedRAMP RFCs Mean For Cloud Providers

A digital cloud with a red light shining on it from a security camera.

With the January 2026 release of multiple RFCs tied to the FedRAMP Authorization Act, the program is shifting from incremental process tweaks to structural modernization. This has been on the horizon for a while now, with the announcement of the FedRAMP 20x program. But this string of RFCs signals that the program is finalizing the finer points of this transformation. For CSPs and their compliance leaders, this is the point at which the realities of FedRAMP over the next decade come into sharper focus.

 

Read More

HIPAA Updates in 2026

a keyboard with a stethoscope on it.

The core HIPAA Privacy and Security Rules were written in a very different era, before cloud computing, large-scale data exchange, and ransomware became a systemic risk to healthcare. While there have been updates to address the digital age (namely, HITECH), there are still gaps in HIPAA’s approach to distributed cloud systems.  

The latest round of HIPAA updates, including proposed updates to both the Privacy Rule and the Security Rule, represents the most consequential modernization effort since the launch of HITECH. 

 

Read More

Developing Key Risk Indicators in GRC

Trusted risk management program by Lazarus Alliance  

Organizations in regulated industries can’t just meet security standards; they need to predict them one, three, or five years down the road. The ability to predict, measure, and manage risks is becoming a core competency, and Key Risk Indicators are foundational to this effort.

Key Risk Indicators, when properly developed, empower organizations to move from reactive compliance postures to proactive governance strategies. This article outlines the methodology and value of developing effective KRIs within the domains of governance, risk, compliance, and cybersecurity, especially for decision-makers shaping enterprise security programs.

 

Read More