THIRD PARTYCURRENT
News topic

Regulation & Standards

Current reporting and analysis with clear distinctions between primary-source facts, provider-reported claims, and Third Party Current interpretation.

Standards Watch

ISO supplier-security standard enters systematic review

ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.

Regulatory Analysis

CPS 230 puts service-provider resilience into force in Australia

APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.

Analysis

NIST pulls supply-chain risk into the system planning record

SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.

Market context

Coverage is attached to the companies, capabilities, and standards it affects so that market records change with evidence rather than headlines alone.