WORKSTREET BLOG

Insights from Workstreet

Guides, articles, and more on compliance, privacy and security.

Abstract illustration for Colorado SB 26-189 ADMT developer and deployer notice requirements for SaaS
CASE STUDY
Travis Good
decorative
October 2, 2026

Does Colorado's New ADMT Law Apply to Our SaaS - and What Docs / Notices Do We Owe by January 1, 2027?

Colorado SB 26-189 replaces the 2024 AI Act. Developer vs deployer checklist, covered ADMT exclusions, and Jan 1 2027 notice clocks for SaaS.
Illustration for GovRAMP (formerly StateRAMP) for SaaS selling to SLED / SLTT buyers including North Carolina
CASE STUDY
Travis Good
decorative
October 2, 2026

SOC 2 Won't Clear Multi-State SLED Deals - What GovRAMP (Formerly StateRAMP) Actually Requires

SOC 2 is not GovRAMP for multi-state SLED SaaS. Status ladder (Core/Ready/Authorized), StateRAMP rename, FedRAMP Fast Track one-way, NC Apr 2026-2027.
Illustration for TX-RAMP certification versus SOC 2 for SaaS selling to Texas agencies
CASE STUDY
Travis Good
decorative
October 1, 2026

SOC 2 Won't Clear a Texas Agency Deal - What TX-RAMP Actually Requires for SaaS

SOC 2 does not replace TX-RAMP for Texas agency SaaS deals. Level 1 vs 2, Manual 4.0 provisional, Fast Track, and why hyperscaler cert is not yours.
Abstract illustration for EU Data Act switching and portability obligations for SaaS
CASE STUDY
Travis Good
decorative
October 1, 2026

Does the EU Data Act Apply to Our SaaS - and What Do Buyers Expect Before January 2027?

Most B2B SaaS is a Data Act data processing service. Switching clocks, portability, and Trust Center disclosures buyers expect before January 2027.
Illustration for Shared Assessments SIG 2026 remake and AI resilience remapping
CASE STUDY
Travis Good
decorative
September 30, 2026

We Already Completed SIG - Do We Need to Remake It for SIG 2026?

SIG 2026 deepens AI (ISO 42001) and resilience mappings without new domains. Remap AI and ORF rows if buyers ask for 2026 - not a zero rewrite.
Illustration for IRAP assessment versus SOC 2 for US SaaS selling to Australian government
CASE STUDY
Travis Good
decorative
September 30, 2026

SOC 2 Won't Clear an Australian Government Deal - What IRAP Actually Is for US SaaS

SOC 2 does not replace an IRAP assessment for Australian government cloud. What IRAP is, why hyperscaler coverage is not yours, and a US SaaS playbook.
Illustration for CCPA cybersecurity audits and SaaS vendors
CASE STUDY
Travis Good
decorative
September 29, 2026

CCPA Cybersecurity Audits Are Live - Does Your SaaS Need One?

Not every CCPA business needs an annual cyber audit. Significant-risk thresholds, the 2028 certification clock, and what SaaS vendors should prepare.
Illustration for CSA SSCF-CAIQ and SaaS product security controls
CASE STUDY
Travis Good
decorative
September 29, 2026

SOC 2 Doesn't Answer "What Can the Customer Configure?" - CSA's SSCF-CAIQ for SaaS Vendors

SOC 2 covers how your company operates. CSA's SSCF-CAIQ covers customer-facing SaaS controls - SSO, MFA, logs - so buyers stop sending custom packs.
CASE STUDY
Travis Good
decorative
September 29, 2026

FedRAMP 20x Requirements: KSIs, Classes and Key Dates

Learn the how FedRAMP 20x is changing FedRAMP compliance.

Illustration for NYDFS Part 500 and SaaS vendor contract requirements
CASE STUDY
Travis Good
decorative
September 28, 2026

NY Financial Buyers Are Hardening Vendor Contracts - What NYDFS Part 500 Means for SaaS

Private SaaS is not the NYDFS Covered Entity - your NY bank or insurer customer is. Part 500.11 still lands MFA, encryption, and event notice in your MSA.
Illustration for HECVAT vs SOC 2 for higher-ed SaaS vendors
CASE STUDY
Travis Good
decorative
September 28, 2026

Your SOC 2 Won't Clear HECVAT - What Higher-Ed Buyers Actually Want from SaaS Vendors

SOC 2 does not replace HECVAT for higher-ed deals. HECVAT 4 is a self-assessment workbook - accessibility, FERPA privacy, and AI/ML that SOC 2 skips.
Illustration for SEC cyber disclosure and SaaS vendor incident notification SLAs
CASE STUDY
Travis Good
decorative
September 28, 2026

Public Buyers Want 24-48 Hour Incident Notice - What the SEC Cyber Rule Means for Private SaaS

Private SaaS is not the SEC Item 1.05 filer - public buyers are. Expect 24-72h notice in MSAs so they can hit the four-business-day 8-K clock.
Illustration for US state privacy laws and SaaS compliance programs
CASE STUDY
Travis Good
decorative
September 28, 2026

Twenty State Privacy Laws, One SaaS Program - What Actually Changed in 2026

Roughly twenty US state privacy laws now face nationwide SaaS teams. Build one program. 2026 deltas: TDPSA, MODPA, GPC, and unified ops stack.
Illustration for SOC 2 penetration testing cadence for SaaS
CASE STUDY
Travis Good
decorative
September 28, 2026

Is an Annual Pentest Enough for SOC 2? What Auditors and SaaS Buyers Expect in 2026

SOC 2 does not name pentesting, but auditors and buyers expect recent third-party evidence. Cadence, window timing, and the report pack that closes asks.
Illustration for UK Cyber Essentials certification for US SaaS selling into the UK
CASE STUDY
Travis Good
decorative
September 28, 2026

UK Buyer Asked for Cyber Essentials - Does SOC 2 Count, and What Changed in April 2026?

SOC 2 does not replace UK Cyber Essentials for UK bids. Non-UK SaaS can certify remotely - April 2026 MFA and EOL rules, plus G-Cloud 15 stakes.

Ready to Transform Security into a Growth Advantage?

Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.