WORKSTREET BLOG
Insights from Workstreet
Guides, articles, and more on compliance, privacy and security.
Does Colorado's New ADMT Law Apply to Our SaaS - and What Docs / Notices Do We Owe by January 1, 2027?
Colorado SB 26-189 replaces the 2024 AI Act. Developer vs deployer checklist, covered ADMT exclusions, and Jan 1 2027 notice clocks for SaaS.
SOC 2 Won't Clear Multi-State SLED Deals - What GovRAMP (Formerly StateRAMP) Actually Requires
SOC 2 is not GovRAMP for multi-state SLED SaaS. Status ladder (Core/Ready/Authorized), StateRAMP rename, FedRAMP Fast Track one-way, NC Apr 2026-2027.
SOC 2 Won't Clear a Texas Agency Deal - What TX-RAMP Actually Requires for SaaS
SOC 2 does not replace TX-RAMP for Texas agency SaaS deals. Level 1 vs 2, Manual 4.0 provisional, Fast Track, and why hyperscaler cert is not yours.
Does the EU Data Act Apply to Our SaaS - and What Do Buyers Expect Before January 2027?
Most B2B SaaS is a Data Act data processing service. Switching clocks, portability, and Trust Center disclosures buyers expect before January 2027.
We Already Completed SIG - Do We Need to Remake It for SIG 2026?
SIG 2026 deepens AI (ISO 42001) and resilience mappings without new domains. Remap AI and ORF rows if buyers ask for 2026 - not a zero rewrite.
SOC 2 Won't Clear an Australian Government Deal - What IRAP Actually Is for US SaaS
SOC 2 does not replace an IRAP assessment for Australian government cloud. What IRAP is, why hyperscaler coverage is not yours, and a US SaaS playbook.
CCPA Cybersecurity Audits Are Live - Does Your SaaS Need One?
Not every CCPA business needs an annual cyber audit. Significant-risk thresholds, the 2028 certification clock, and what SaaS vendors should prepare.
SOC 2 Doesn't Answer "What Can the Customer Configure?" - CSA's SSCF-CAIQ for SaaS Vendors
SOC 2 covers how your company operates. CSA's SSCF-CAIQ covers customer-facing SaaS controls - SSO, MFA, logs - so buyers stop sending custom packs.

FedRAMP 20x Requirements: KSIs, Classes and Key Dates
Learn the how FedRAMP 20x is changing FedRAMP compliance.
NY Financial Buyers Are Hardening Vendor Contracts - What NYDFS Part 500 Means for SaaS
Private SaaS is not the NYDFS Covered Entity - your NY bank or insurer customer is. Part 500.11 still lands MFA, encryption, and event notice in your MSA.
Your SOC 2 Won't Clear HECVAT - What Higher-Ed Buyers Actually Want from SaaS Vendors
SOC 2 does not replace HECVAT for higher-ed deals. HECVAT 4 is a self-assessment workbook - accessibility, FERPA privacy, and AI/ML that SOC 2 skips.
Public Buyers Want 24-48 Hour Incident Notice - What the SEC Cyber Rule Means for Private SaaS
Private SaaS is not the SEC Item 1.05 filer - public buyers are. Expect 24-72h notice in MSAs so they can hit the four-business-day 8-K clock.
Twenty State Privacy Laws, One SaaS Program - What Actually Changed in 2026
Roughly twenty US state privacy laws now face nationwide SaaS teams. Build one program. 2026 deltas: TDPSA, MODPA, GPC, and unified ops stack.
Is an Annual Pentest Enough for SOC 2? What Auditors and SaaS Buyers Expect in 2026
SOC 2 does not name pentesting, but auditors and buyers expect recent third-party evidence. Cadence, window timing, and the report pack that closes asks.
UK Buyer Asked for Cyber Essentials - Does SOC 2 Count, and What Changed in April 2026?
SOC 2 does not replace UK Cyber Essentials for UK bids. Non-UK SaaS can certify remotely - April 2026 MFA and EOL rules, plus G-Cloud 15 stakes.
Ready to Transform Security into a Growth Advantage?
Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.
