Recap: dated vendor and standards updates, December 2025 to September 2026
By the Clause Desk ·
This note covers announcements from December 2025 to September 2026 that appear on the vendor and standards pages we reviewed, grouped by theme. It also restates the older standards dates that the rest of the site relies on.
What did the vendors in this lineup announce?
The dated vendor announcements we found on the pages reviewed all come from Scytale's own news list. On 9 December 2025, Scytale reported being named AWS Rising Star Partner of the Year (Technology) for EMEA. On 27 February 2026, it reported being named a G2 Best Software Award winner in GRC. On 21 July 2026, it reported recognition from Frost & Sullivan for 2026 Global Customer Value Leadership. On 15 September 2026, it announced an AI Third-Party Risk Management launch. The other five vendors' pages we reviewed did not show dated announcements in the sections we read, so this recap is not a complete record of their news.
What does the third-party risk launch change?
Supplier management sits in clause 8 of ISO 27001, and third-party risk is a common theme in customer questionnaires. With the 15 September 2026 launch, Scytale joins the other five vendors here in describing third-party or vendor risk features: Vanta a TPRM agent, Drata a new TPRM offering and an Agentic TPRM Assessment on GRC Enterprise, Sprinto Autonomous TPRM, Scrut a Vendor Risk Analyst agent and Secureframe advanced third-party risk management on Complete. On our clause map, the launch is part of Scytale's clause 8 cell.
What did the auditing profession publish?
Four AICPA and Journal of Accountancy items from 2026 concern SOC engagements, which matter if you add SOC 2 to an ISO 27001 program: 1 February, "Promises of 'fast and easy' threaten SOC credibility"; 13 April, AICPA Ethics Staff Insights, "Business arrangements with SOC tool providers"; 30 April, the podcast "The risks of quick-turn SOC engagements and what CPAs should know"; and 14 May, "AICPA guides peer reviewers to address SOC 2 risks". We list titles and dates only. The practical buyer questions are whether your SOC 2 auditor is a licensed CPA firm enrolled in AICPA peer review, and how its business arrangements with the tool vendor are structured.
Which older standards dates does this site rely on?
Three. The Essential Eight maturity model was first published in June 2017, and ASD updates it regularly, with changes in the November 2023 release listed on the page we reviewed. ISO/IEC 27001:2022, Edition 3, was published in October 2022; iso.org lists 19 pages, one amendment and a price of CHF 155. These dates matter when a vendor or customer refers to a version: ask which edition or model release they mean.
What did we observe on the review date?
On 29 September 2026, the date all vendor pages were read for this site, Scrut's pricing URL returned Page Not Found, and Scytale's integrations page and homepage gave different integration counts (100+ and 150+). We record both on the vendor profiles and use the lower integration figure in the score.
What should buyers do with this recap?
Use it to ask better questions, not to rank vendors. An award or a recognition tells you how a vendor presents itself; a launch tells you what it now offers, but a new feature needs a demonstration before it counts for much. For Scytale's third-party risk launch, ask to see a supplier assessment end to end and how the result links to ISO 27001 supplier controls. For the AICPA items, keep them on file if SOC 2 is on your roadmap, and use them to frame questions about auditor standing and business arrangements with tool vendors.
How will we track changes?
Every change to a score, a fact or a weight is logged with its date on the Updates page, and the edition label in the site header changes when a new review round is published.
Filed under: Updates