Insight Assurance

Insight Assurance Global compliance & risk management firm specializing in cybersecurity audits & AI governance. https://lnk.bio/insightassurance

Last month, a lot of you nailed our orange on the first try 👏Now we're switching it up. Which one is Insight Assurance's...
09/11/2026

Last month, a lot of you nailed our orange on the first try 👏

Now we're switching it up. Which one is Insight Assurance's real purple?

No cheating, no color picker tools. Comment your guess before you scroll to check.

🇧🇷 Faltam 5 dias para a Mind the Sec. Se compliance está na sua lista para esse ano, essa é uma boa desculpa pra finalme...
09/10/2026

🇧🇷 Faltam 5 dias para a Mind the Sec. Se compliance está na sua lista para esse ano, essa é uma boa desculpa pra finalmente conversar sobre isso, em vez de adiar de novo. Eduardo Meléndez estará em São Paulo, de 15 a 17 de setembro, representando a Insight Assurance.

🇺🇸

Mind the Sec is 5 days out. If compliance is somewhere on your radar for this year, this is a good excuse to talk about it instead of putting it off again. Eduardo Meléndez will be in São Paulo, Sept 15–17, representing Insight Assurance.

Compliance in APAC doesn't look like it did two years ago. More frameworks, more buyer questions, more pressure to show ...
09/09/2026

Compliance in APAC doesn't look like it did two years ago. More frameworks, more buyer questions, more pressure to show your work instead of just claiming it.

That's exactly the conversation happening at Vanta Trust Tour Sydney, and we're proud to be a sponsor this year. Ronald Moriya, our APAC & Japan Country Manager, will be there. Come find him if you're going.

Heading to National Cyber Summit later this month? Save the evening of September 21!We'll be at Innerspace Brewing with ...
09/09/2026

Heading to National Cyber Summit later this month? Save the evening of September 21!

We'll be at Innerspace Brewing with SMPL-C and NAC-ISSA for a drink and good conversations. Huntsville, mark it down. 📍

Register here: https://hubs.li/Q04wKThw0

09/07/2026

Happy Labor Day 🧡

"The EU AI Act deadline got pushed back, so we've got time."Not quite. The high-risk system deadline moved to Dec 2027 (...
09/04/2026

"The EU AI Act deadline got pushed back, so we've got time."

Not quite. The high-risk system deadline moved to Dec 2027 (standalone) and Aug 2028 (embedded). But customers and regulators asking for AI governance evidence right now didn't get the same memo.

That gap, between what technically changed and what's being asked of you today, is exactly what we're unpacking with Mario Vlieg (Insight Assurance) and Michelle Strickler (Workstreet) on Sep 23.

Register: https://hubs.li/Q04w7MgP0

We're proud to be part of what https://hubs.li/Q04w7fv80 built at their first Partner Summit in Vancouver last month. No...
09/03/2026

We're proud to be part of what https://hubs.li/Q04w7fv80 built at their first Partner Summit in Vancouver last month.

No single firm can do everything in security and compliance. https://hubs.li/Q04w7fv80 runs the readiness work. We bring the independent CMMC, C3PAO, and FedRAMP/GovRAMP accreditation defense contractors need to move forward.

Different roles, same client, a better outcome than any one firm trying to cover it all.

TechCouver has the full story on how it all came together, worth a read: https://hubs.li/Q04w7wH60

The EU AI Act deadline moved. That doesn't mean the AI governance conversation stopped.Join Mario Vlieg (Insight Assuran...
09/02/2026

The EU AI Act deadline moved. That doesn't mean the AI governance conversation stopped.

Join Mario Vlieg (Insight Assurance) and Michelle Strickler (Workstreet) for a straight, vendor-neutral walkthrough of ISO/IEC 42001, what it is, who it applies to, and what actually happens during an independent assessment.

We'll get into:
→ Did the EU AI Act deadline move? (Yes, here's what changed and what didn't)
→ Do you need ISO 42001, and how scope gets determined
→ Where ISO 42001 overlaps with ISO 27001 and SOC 2, and where it doesn't
→ What Stage 1 and Stage 2 assessment actually looks like
→ The difference between "audit-ready" and actually being assessed

Can't make it live? Register anyway, we'll send the replay.

Register here: https://hubs.li/Q04w61vt0

Big FedRAMP news just dropped 🚨As of August 31, FedRAMP officially opened the 20x Class B and Class C submission pipelin...
09/01/2026

Big FedRAMP news just dropped 🚨

As of August 31, FedRAMP officially opened the 20x Class B and Class C submission pipelines, the next major milestone in the program's shift away from the traditional Rev5 process.
Here's what changed:

The old impact-level system, Low, Moderate, High, is being fully replaced with a new class structure:

Class A → entry-level path for the Marketplace, opened back on August 3
Class B → replaces the old Low impact level
Class C → replaces the old Moderate impact level
Class D → will eventually replace High, still pending, expected to pilot sometime in FY27

But the real shift isn't the renaming. It's how certification itself now works.

No agency sponsor required anymore. Under the legacy Rev5 process, providers needed an agency to sponsor their authorization before they could even begin. FedRAMP 20x removes that requirement entirely, which opens the door for a lot more cloud providers to pursue certification on their own timeline instead of waiting on a sponsor to move first.

Manual document review is being replaced with automated validation 📊 Instead of the traditional, document-heavy audit process everyone associates with FedRAMP, 20x relies on Key Security Indicators, KSIs, 56 of them for the Class B baseline, 61 for Class C, validated through automation and machine-readable evidence rather than long narrative control write-ups.

If you're a cloud service provider who's been waiting on the sidelines for 20x to prove itself past the pilot stage before committing real resources to it, this is that moment. Class B and C are no longer limited or experimental. They're now the path forward for most providers who were previously targeting Low or Moderate impact authorizations under the old system.

A few dates worth keeping on your radar đź“…

August 31, 2026 - Class B and C pipelines officially open (today)
January 1, 2027 - CR26 becomes mandatory for all stakeholders, no more optional adoption
June 11, 2027 - FedRAMP stops accepting brand new Rev5 certification applications entirely

We'll be watching closely how agencies respond to this first real wave of 20x-certified providers under the new class structure. This is one of the more consequential shifts FedRAMP has made since the program began, worth understanding now rather than catching up on later ⏳

"We'll figure out compliance later" doesn't work anymore for companies scaling out of Latin America. Later used to mean ...
08/31/2026

"We'll figure out compliance later" doesn't work anymore for companies scaling out of Latin America. Later used to mean months. Now it means a lost contract. 📉

Insight Assurance will be at Mind the Sec 2026, São Paulo, Sept 15–17, talking SOC 2 and ISO 27001 with companies trying to close deals in the US and Europe. Our LATAM Regional Manager, Eduardo Meléndez, will be on the ground.

🇧🇷

"A gente resolve compliance depois" não funciona mais para empresas latino-americanas que estão crescendo fora da região. Depois costumava significar meses. Agora significa um contrato perdido. 📉

A Insight Assurance estará na Mind the Sec 2026, em São Paulo, de 15 a 17 de setembro, falando sobre SOC 2 e ISO 27001 com empresas que querem fechar negócios nos EUA e na Europa. Nosso Gerente Regional para a América Latina, Eduardo Meléndez, estará por lá.

Address

Tampa, FL
33606

Alerts

Be the first to know and let us send you an email when Insight Assurance posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Insight Assurance:

Shortcuts

Featured

Share