Qualysec

Blog

Latest Articles

Page 1 of 151 · 1356 posts

The CTO’s Guide to Passing the Qatar NIA Standard Audit

August 24, 2026

The CTO’s Guide to Passing the Qatar NIA Standard Audit

Your NIA compliance audit is six weeks away. The NCSA-accredited auditors will arrive with a clear checklist built around the National Information Assurance Standard (NIA) V2.1. Your team has been scanning, patching, and reporting “ready.” Then you open the actual requirements and realise the work you have been doing does not map to what they […]

Understanding the FDA Secure Product Development Framework (SPDF) Requirements and 2026 Implementation Guide

August 24, 2026

Understanding the FDA Secure Product Development Framework (SPDF): Requirements and 2026 Implementation Guide

A threat model, SBOM, penetration test, and cybersecurity plan can all be part of an FDA submission. None of them, by themselves, is an SPDF. That distinction matters because the Secure Product Development Framework (SPDF) is much broader. It brings cybersecurity into the processes used to design, develop, release, maintain, and eventually retire a medical […]

Software Bill of Materials (SBOM) for IoMT Software FDA Compliance Guide

August 21, 2026

Software Bill of Materials (SBOM) for IoMT Software: FDA Compliance Guide

A connected medical device submission may be blocked by the U.S. FDA due to insufficient cybersecurity documentation. A software bill of materials sbom for IoMT software provides a precise, machine-readable list of all software components that are used by connected medical devices.  From open-source libraries to transitive dependencies are mentioned inside the SBOM. Even one […]

CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT: Which Scheme Applies to You?

August 21, 2026

CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT: Which Scheme Applies to You?

Many people are confused about the differences between the CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT questions because these are not competitive products. They have varying levels of operation. The accreditation of CHECK is a baseline accreditation, and that of CREST is UK government work. Advanced threat-led regimes for financial institutions are […]

BNM RMiT Penetration Testing Guidelines Mandates, Scope, and Vendor Selection Criteria

August 20, 2026

BNM RMiT Penetration Testing Guidelines: Mandates, Scope, and Vendor Selection Criteria

If you run a bank, insurer, e-wallet, or fintech in Malaysia, Bank Negara Malaysia’s Risk Management in Technology (RMiT) rules are not optional. This is the basic standard that decides whether your systems pass BNM checks. Auditors no longer accept one-time security tests that claim everything is fine for a year. They want clear proof […]

FDA PCCP Guidance for AIML Medical Devices 2026 Submission & Change Control Guide

August 20, 2026

FDA PCCP Guidance for AI/ML Medical Devices: 2026 Submission & Change Control Guide

Quick Summary: A Predetermined Change Control Plan (PCCP) allows medical device manufacturers to pre-specify and validate future AI/ML algorithm modifications within a marketing submission, such as 510(k), PMA, or De Novo. When planned changes remain within the FDA-authorized PCCP boundaries and follow the approved modification protocol, manufacturers can implement those updates without submitting a new premarket […]

The Complete Guide to AI Governance & Compliance in 2026

August 20, 2026

The Complete Guide to AI Governance & Compliance in 2026

Key Takeaways EU AI Act penalties for prohibited practices have been in effect since February 2025, up to €35 million or 7% of global turnover, with GPAI enforcement and transparency duties landing on August 2, 2026. Gartner found 43% of organisations can’t even produce a full AI inventory, which is usually step one for any […]

DESC Cyber Force Penetration Testing: Complete Guide for UAE

August 19, 2026

DESC Cyber Force Penetration Testing: Complete Guide for UAE

Key Takeaways DESC Cyber Force is a certification for providers, not a special type of test. Only Dubai government, semi-government and CII entities must use certified providers. The testing itself is just solid professional penetration testing done by approved companies. Most organisations still find basic problems like weak passwords, missing patches and poor access control. […]

What Is DESC Cyber Force? Requirements & Compliance Guide

August 19, 2026

What Is DESC Cyber Force? Requirements & Compliance Guide

Dubai has built one of the most structured cybersecurity oversight systems in the region. At the center of this system is the Dubai Electronic Security Center, known as DESC, which is a government authority that operates under Digital Dubai. Its mandate comes from Dubai Law No. 11 of 2014. Many people use the term DESC […]

"Don't compromise between depth and speed. Own both. Connect with Swagat, Your trusted penetration testing advisor."

Swagat Kumar Dash

Swagat Kumar Dash

Head Of Business Development