This website uses cookies

Read our Privacy policy and Terms of use for more information.

ITRADE works with STEM organizations to close Technology, Talent, & Security gaps. See how →

The ITRADE Dispatch Issue #5 · July 28, 2026
ITRADE
The Dispatch · Intelligence for STEM Leaders
Security · Week 5
Your "Out of Scope" List Just Got Shorter
PCI DSS, CMMC, NIST CSF, and NERC CIP all expanded scope in 2026. Cloud infrastructure, VMs, third-party access, and AI workloads are no longer exempt.
Security Compliance Risk Management
The Lead

Every security team has a list of systems they've quietly agreed to ignore.

Nobody writes it down. Nobody puts "we chose not to protect these" in a slide deck. But practically - cloud instances spun up by developers. Virtual machines cloned from templates that haven't been patched in two years. Vendors with persistent VPN tunnels straight into production. AI tools trained on production data with zero access controls.

Two years ago, most compliance frameworks let you get away with it.

That grace period is over.

In the first half of 2026, the compliance landscape shifted faster than at any point in the past decade. Not one framework. Nearly all of them.

PCI DSS 4.0 - the standard governing payment card security - went into full enforcement on March 31, 2026. Risk analysis is now mandatory, not optional. Anti-phishing controls, script integrity for payment pages, and continuous security testing all moved into scope. Organizations that were "mostly compliant" under the old version are finding gaps they didn't budget for.

CMMC 2.0 - the cybersecurity certification required for defense contracts - is now enforced for all new DoD awards. Over 73,000 defense supply chain companies need third-party certification against 110 security controls. Cloud environments, subcontractor access, and sensitive data flows that used to be self-assessed are now audit targets.

NIST CSF 2.0 added Governance as the sixth core function - officially elevating cybersecurity from an IT concern to a board-level risk management responsibility. Supply chain risk management is now a top-tier requirement, not an afterthought.

NERC CIP 2026 - the cybersecurity standard for the North American power grid - is pushing the most aggressive expansion in critical infrastructure compliance history. Three new standards hit enforcement this year alone.

The pattern across all of them is identical: assets that were previously exempt are becoming audit targets. Cloud infrastructure. Virtualized systems. Third-party access pathways. AI and machine learning workloads. Remote operations.

Your "out of scope" list is becoming your risk register.

What Happens When Compliance Catches Up: The NERC CIP Blueprint

The energy sector is going through the most dramatic version of this pattern right now - and it's worth studying even if you never touch a power grid, because it previews what every other framework is heading toward.

CIP-003-9 went into effect April 1, 2026. It extends governance and vendor access controls to low-impact assets - the systems that utilities had been largely exempt from formal requirements. Every vendor with remote access now needs individual authentication, supply chain risk documentation, and detection of malicious communications.

This is the exact same pattern: PCI DSS 4.0 just did this to payment-adjacent systems. CMMC 2.0 just did this to subcontractor access. SOC 2 auditors have been pushing this on SaaS vendors for two years.

CIP-015-1 made Internal Network Security Monitoring (INSM) mandatory for critical systems. Network traffic capture and analysis - the kind of visibility most organizations still treat as a "nice to have" - is now a regulatory requirement. Implementation deadlines run through 2030, and FERC has already ordered the scope to expand further.

The parallel outside energy: NDR and network traffic analysis deployments that security teams have been requesting budget for are on track to become compliance requirements across industries, not just operational improvements.

CIP-012-2 went into effect July 1, 2026. It extended encryption and integrity protections to any communications crossing public networks. The same requirement healthcare organizations face under HIPAA for patient data in transit, and PCI DSS 4.0 mandates for cardholder data.

In March, FERC approved 11 updated standards covering virtualization - formally recognizing VMs, containers, and software-defined infrastructure as in-scope assets. The energy sector just did what every industry will do: admit that virtual infrastructure carries the same risk as physical infrastructure and must be governed accordingly.

The Threat Pressure Driving the Expansion

Regulators don't expand compliance scope for the exercise. They do it because the threat landscape forced their hand:

  • Cyberattacks targeting U.S. utilities increased roughly 70% in 2024 (Check Point Research)
  • 67% of energy organizations faced ransomware in 2024, with 80% resulting in data encryption (Sophos)
  • 60% of critical infrastructure attacks attributed to nation-state actors
  • In December 2025, Russia's Sandworm group deployed destructive malware against 30 distributed energy facilities in Poland via internet-exposed equipment

But the broader point: that same threat pressure exists everywhere. Ransomware hit 59% of organizations globally in 2024. Supply chain attacks grew 320% between 2021 and 2025. AI-powered phishing is outperforming human-crafted campaigns in click-through rates.

Compliance frameworks are expanding because the threats already did.

What to Do

1. Audit your "out of scope" assets against the current enforceable version of your framework. Not the version you certified against - the version that's live today. PCI DSS 4.0, CMMC Level 2, and NERC CIP all expanded scope in 2026.

2. Map every third-party access pathway. Vendors with persistent remote access are the number one newly in-scope asset across frameworks. Document who has access, what protocol, whether it requires individual authentication, and whether you can disable it within 15 minutes.

3. Start network monitoring before it becomes mandatory. NERC CIP made it a requirement. In 12 to 18 months, expect similar language in SOC 2 and FedRAMP. Build the capability now while it's a competitive advantage, not a scramble.

4. Treat virtual infrastructure like physical infrastructure. VMs, containers, and cloud workloads carry the same governance requirements. Change management, patching, and access controls apply equally.

5. Brief the board on compliance expansion as a budget driver. New scope means new controls means new budget. NIST CSF 2.0 made governance a core function for a reason. Frame it as risk, not IT.

The organizations that scale compliance successfully don't treat framework expansion as a surprise. They treat it as a predictable risk management cycle and fund accordingly.

Signals · This Week in STEM
Technology
Enterprise AI spending hit $13.8B in Q1 2026, up 62% year over year. In security operations, AI is being deployed for automated compliance evidence collection, anomaly detection, and adaptive access control. The governance gap: only 23% of organizations have formal AI risk management frameworks in place (ISACA).
Talent
Compliance expansion is deepening the talent shortage. GRC analyst demand spiked 41% in the first half of 2026 as organizations staff up for new framework versions. The fastest-growing specialty: compliance engineers who can map controls across multiple frameworks simultaneously. If you have one, hold on to them.
Security
CISA released 7 industrial control system advisories in January 2026 alone - Rockwell ControlLogix, Johnson Controls, Schneider Electric. The advisory velocity is accelerating: 2025 averaged 4.2 per month, 2026 is on pace for 7+. Each one represents a vulnerability that was already being exploited before the advisory dropped.
Wellness
Burnout rates among GRC and compliance professionals hit 62% in 2025 (Gartner). The teams responsible for implementing expanded framework requirements are the same ones already stretched thin. Organizations investing in structured recovery protocols - scheduled downtime, cognitive load management, and physical stress resilience practices - report 23% lower attrition in security operations roles. Compliance expansion is a people problem before it's a controls problem.
ONE STAT THAT MATTERS
4/5
compliance frameworks enforced in the U.S. expanded their scope in 2026. The assets your team classified as "out of scope" last year are this year's audit findings.
Your "out of scope" list is now your risk register.
The ITRADE Lens
Your 90-Minute Compliance Expansion Readiness Audit

This works for any framework - PCI DSS, CMMC, SOC 2, HIPAA, NERC CIP. Run it quarterly.

1 Scope Drift Analysis (25 min) - Pull your last certification or audit scope document. Compare it against the current enforceable version of your framework. List every asset category that moved from "out of scope" to "in scope." Common finds: cloud environments, virtual machines, third-party remote access, mobile endpoints, AI/ML workloads. Any gap is an immediate remediation target.
2 Third-Party Access Inventory (20 min) - Document every vendor, contractor, and partner with remote access into your environment. For each one: What protocol? Individually authenticated? MFA required? Can you disable within 15 minutes? Persistent or session-based? If you can't answer all five in under 60 seconds per vendor, your vendor access management is a compliance gap.
3 Network Monitoring Coverage (15 min) - Can you capture and store network traffic inside your critical segments? Do you have baseline traffic profiles? Do you have analyst capacity for anomaly investigation? If network monitoring became mandatory for your framework tomorrow, how many months would you need? That number is your exposure window.
4 Virtualization and Cloud Governance (15 min) - Are VMs and containers subject to the same change management, patching, and access control policies as physical infrastructure? Is snapshot management documented? Hypervisor patching on schedule? If the answer is "we treat cloud differently" - that answer no longer flies under most frameworks.
5 Board-Ready Risk Summary (15 min) - Draft a one-page brief: (a) What moved into scope since your last audit, (b) estimated cost to close gaps, (c) timeline to remediation, (d) risk exposure if you don't act. This is the document that turns compliance expansion from an IT problem into a funded priority.

If you identified gaps in 3 or more areas: your compliance readiness budget needs to catch up with framework reality.

Bianca Diosdado
Founder & CEO, ITRADE Innovations · Education Programs Chair, SIM South Florida

Bianca architects the systems most leaders buy in pieces - talent, technology, and security, designed to work as one.

ITRADE
The Dispatch · Weekly Intelligence for STEM Leaders
Fort Lauderdale's founding STEM security circle.

Keep Reading