Since 2017, the Customer Security Controls Framework (CSCF) has been helping organizations to effectively secure their SWIFT infrastructure. The aim...
Security Audits
New BSI Criteria Catalogues: Guidelines for the Use of AI in the Financial and Administrative Sectors
The German Federal Office for Information Security (BSI) has published two new sets of criteria for evaluating Artificial Intelligence (AI). They...
KRITIS: Proof of Compliance Will Be Due in These Sectors in 2026
“Critical infrastructures (KRITIS for short) are organizations or facilities with important significance for the state community, the failure or...
NIS-2 Draft Bill under Examination: Everything You Need to Know
A few days ago, the AG KRITIS published the latest draft bill on the NIS-2 Implementation Law (NIS2UmsuCG) on its website. Which requirements could...
SWIFT CSCFv2025: Current Version of the Framework Brings Changes for Architecture Type B
Since its introduction in 2017, the Customer Security Controls Framework (CSCF) has aimed to strengthen the security of the SWIFT network. The aim...
New Requirements of ISO/IEC 27006-1:2024: What Changes Do They Bring for Your Audit?
ISO/IEC 27006-1:2024 contains the formal requirements for certification bodies that must be implemented when auditing an information security...
EPI External Security Evaluator: usd Receives Accreditation from the European Payments Initiative
usd AG has been accredited as a Security Evaluator by the European Payments Initiative (EPI). We are now authorized to carry out security...
Implementation of the NIS-2 Directive Has Been Postponed. What Is the Impact on the KRITIS Compliance Audit?
What's next for NIS-2? Due to the early elections in Germany, the parliamentary procedure for the NIS-2 implementation law NIS2UmsuCG could not be...
PCI Council Released Update of SAQ A: New Eligibility Criteria Replaces Future-dated Requirements
Last updated: 28 February, 2025 A few days ago, the PCI Security Standards Council (PCI SSC) announced important changes to SAQ A. Who is affected...
PCI DSS worldwide: usd AG one of 17 QSA companies with global accreditation
usd AG has once again received all the necessary licenses from the PCI Security Standards Council (PCI SSC) as a PCI DSS Qualified Security Assessor...
SWIFT CSCFv2025 - The Three Most Important Questions About the Update
Users of the SWIFT network are required to demonstrate compliance with the mandatory security controls through an annual independent audit in...
KRITIS: These Sectors Are Required to Provide Proof of Compliance in 2025
According to Section 8a (1) BSIG, operators of critical infrastructures (KRITIS) in Germany are obliged to take appropriate organizational and...









