For this update, focus has been on MCP and A2A protocol security, third-party risk management, and agent identity and access management. This quarter’s refresh updates 14 requirements and 23 controls.
Introduced new controls for MCP and A2A protocol security, standardizing authentication, transport, runtime containment, and logging across agentic interfaces
Expanded third-party risk controls including making third-party access monitoring mandatory
Expanded controls for agent identity, permissions, and access management
Q2 2026
Q2 2026
Detailed comparison of previous standards (October 1, 2025 and January 15, 2026) and current standard (April 15, 2026) is available on Github here