#compliance

Security awareness tips, industry news, and product updates.

Hospital staff working at computer workstations subject to HIPAA Security Rule requirements
Security Awareness TipsCompliance & Regulations

HIPAA Security Rule Update Slips to 2027: Now What?

HHS has pushed final action on the proposed HIPAA Security Rule overhaul to July 2027, and more than 100 hospital systems want it withdrawn entirely. But the current rule remains actively enforced, including its security awareness training requirement. Relaxing now is the wrong lesson.

Natalie Hoffmann·9/1/2026·5 min read
Engineer working in a defense manufacturing facility preparing for CMMC Level 2 assessment
Compliance & RegulationsFor MSPs & Partners

CMMC Phase 2 Countdown: Level 2 Audits From November

On November 10, 2026, CMMC Phase 2 begins: DoD contracts involving CUI can require third-party Level 2 certification instead of self-assessment. With roughly 80,000 companies needing certification and only about 80 authorized assessors, the countdown is very real.

Elena Vasquez·8/30/2026·5 min read
The Houses of Parliament in Westminster, where the UK Cyber Security and Resilience Bill is being debated
Compliance & RegulationsFor MSPs & Partners

UK Cyber Resilience Bill Puts MSPs Under Regulation

For the first time, UK managed service providers face statutory security duties and a two-stage incident reporting regime. The Cyber Security and Resilience Bill has cleared the Commons and is progressing through the Lords. Here is what MSPs should be doing now.

Lisa Brennan·8/28/2026·6 min read
Employees in a workplace training session building the AI literacy skills required by the EU AI Act
Security Awareness TipsCompliance & Regulations

EU AI Literacy Duty: Enforcement Arrives in August 2026

Every other EU AI Act headline in 2026 has been about delay, but the Article 4 AI-literacy duty was never postponed. It has applied since February 2025, and from early August 2026 national authorities gain the powers to enforce it. Here is how to build a defensible program.

Sarah Mitchell·8/20/2026·6 min read
German office building representing NIS2-regulated entities facing the BSI enforcement phase
Compliance & RegulationsFor MSPs & Partners

Germany NIS2: Grace Deadline Expired, Enforcement Begins

The BSI's final grace deadline for NIS2 registration expired on 31 July 2026 with thousands of in-scope German entities still unregistered. Germany's NIS2 regime now enters its enforcement phase, and registration failures alone can draw fines of up to EUR 500,000.

David Kowalski·8/16/2026·5 min read
A manager configuring access permissions for team members on a laptop
Compliance & RegulationsProduct Updates

Custom Roles and Granular Permissions in empowsec Explained

empowsec lets company admins build custom roles with granular permissions, renders a dashboard with only the tabs each user may see, and gives reseller teams an equivalent permission system - so nobody needs full admin access just to do one job.

David Kowalski·8/15/2026·7 min read
HR and IT team reviewing an automated training enrollment plan
Compliance & RegulationsProduct Updates

Automated Recurring Training Enrollment for Compliance

Compliance frameworks expect regular, evidenced security training - but manual re-enrollment does not scale. empowsec automation rules enroll new hires automatically and re-run courses every 3, 6, 12 or 24 months, hands-off.

Rachel Andersen·8/14/2026·5 min read
Reviewing audit logs and compliance records
Compliance & RegulationsProduct Updates

empowsec Audit Logs, Impersonation, and GDPR Deletion

empowsec maintains comprehensive audit logs, records every impersonation session, and provides a compliant account deletion workflow - giving organizations the accountability, traceability, and GDPR evidence they need.

Natalie Hoffmann·8/4/2026·8 min read
Managing plans, seats, and billing
For MSPs & PartnersProduct Updates

empowsec Plans, Seats, and True-Up Billing Explained

empowsec bundles features into plans, charges seat-based billing through Stripe, and reconciles seat overages with a transparent true-up process - so your organization can grow without hard blocks or billing surprises.

Rachel Andersen·8/2/2026·8 min read
Managing notification preferences
Product Updates

empowsec Notifications: Right Alert to the Right Person

empowsec delivers role-aware notifications across every actor in the platform - end users, admins, managers, and resellers - while letting users control preferences per notification type, and protecting critical alerts that cannot be switched off.

Elena Vasquez·7/31/2026·8 min read
Configuring single sign-on for empowsec
Compliance & RegulationsProduct Updates

Single Sign-On for empowsec: SAML, OIDC, and OAuth Explained

empowsec supports single sign-on via SAML 2.0, OIDC, and OAuth, with per-domain configuration, attribute mapping, auto-provisioning on first login, and cross-domain authentication for white-label deployments - centralizing access and reducing password risk.

David Kowalski·7/15/2026·9 min read
« Previous12Next »