> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates/july-2026.md).

# July 2026

## New built-in compliance standards

The following compliance standards were added to the Standards Catalog. You can now access them from the **Posture Management → Compliance → Catalogs → Standards** page.

| Compliance standard                                                                                                                                                                                                                               | Version | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |   |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| <p>CIS Alibaba Cloud Foundation Benchmark - Level 1<br>CIS Alibaba Cloud Foundation Benchmark - Level 2</p>                                                                                                                                       | 2.0.0   | <p>The CIS Alibaba Cloud Foundations Benchmark v2.0.0 provides a consensus-based framework of security configuration best practices divided into two additive profiles.<br>Level 1 (L1) establishes a practical security baseline designed to meaningfully reduce your attack surface—covering essential hygiene like enforcing MFA for RAM users, enabling ActionTrail logging, and blocking public OSS buckets—without significantly disrupting standard business operations.<br>Level 2 (L2) is a stricter, defense-in-depth profile tailored for highly sensitive or regulated environments, introducing advanced controls such as aggressive network segmentation and customer-managed encryption that offer maximum protection at the cost of higher operational friction. Together, these profiles allow organizations to systematically harden their identity management, network architecture, data storage, and monitoring capabilities based on their specific security needs and risk tolerance.</p><p><strong>Note</strong>: During the July 2026 Cortex production deployment, assessment results for the CIS Alibaba Cloud Foundation Benchmark v2.0.0 compliance standard may temporarily appear as "Not Assessed". This is expected while underlying platform dependencies are updated across all environments. Complete assessment functionality for this standard will be restored once the July deployment concludes.</p> |   |
| CIS Amazon Elastic Kubernetes Service (EKS) Benchmark                                                                                                                                                                                             | 1.8.0   | <p>The CIS Amazon Elastic Kubernetes Service (EKS) Benchmark v1.8.0 provides consensus-driven, prescriptive security guidelines for configuring and securing the customer-managed aspects of Amazon EKS clusters.<br>Aligning with the AWS shared responsibility model, this benchmark outlines essential best practices for hardening worker nodes, enforcing strict Role-Based Access Control (RBAC) alongside AWS IAM, implementing secure network policies, and enabling comprehensive control plane logging to ensure a robust security posture against potential threats.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |   |
| <p>CIS Amazon Web Services Foundations Benchmark - Level 1<br>CIS Amazon Web Services Foundations Benchmark - Level 2</p>                                                                                                                         | 7.0.0   | <p>The CIS Amazon Web Services Foundations Benchmark is an industry-recognized set of prescriptive configuration guidelines published by the Center for Internet Security (CIS) to establish a foundational security baseline for AWS environments.<br>It provides actionable recommendations across key operational domains—including Identity and Access Management (IAM), storage encryption, logging, monitoring, and network configuration—to protect against unauthorized access, data exposure, and misconfigurations. Categorized into essential baseline (Level 1) and high-security (Level 2) controls.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |   |
| <p>CIS Debian Linux 13 - Server Level 1<br>CIS Debian Linux 13 - Server Level 2<br>CIS Debian Linux 13 - Workstation Level 1<br>CIS Debian Linux 13 - Workstation Level 2</p>                                                                     | 1.0.0   | <p>The CIS Debian Linux 13 v1.0.0 Benchmark provides a prescriptive, industry-consensus framework for securely configuring and hardening Debian 13 systems.<br>It outlines specific, actionable controls across critical areas—such as identity and access management, network restrictions, file system permissions, and auditing—designed to reduce the operating system's attack surface, mitigate common vulnerabilities, and help organizations align with broader regulatory compliance and security standards.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |   |
| <p>CIS Microsoft Azure Foundations Benchmark - Level 1<br>CIS Microsoft Azure Foundations Benchmark - Level 2</p>                                                                                                                                 | 6.0.0   | <p>The CIS Microsoft Azure Foundations Benchmark is an industry-recognized set of prescriptive configuration guidelines published by the Center for Internet Security (CIS) to establish a foundational security baseline for Azure tenant and resource environments.<br>It provides actionable controls across key operational domains—including Microsoft Entra ID governance, Microsoft Defender for Cloud threat protection, storage encryption, continuous logging, and network perimeter security—to guard against credential compromise and cloud misconfigurations. Categorized into essential baseline (Level 1) and high-security (Level 2) recommendations.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |   |
| <p>CIS Red Hat Openshift Container Platform Benchmark - Level 1<br>CIS Red Hat Openshift Container Platform Benchmark - Level 2</p>                                                                                                               | 1.9.0   | <p>The CIS Red Hat OpenShift Container Platform Benchmark is the foundational security hardening guide published by the Center for Internet Security (CIS) for securing Red Hat OpenShift container clusters.<br>Level 1 establishes a basic security baseline that is practical for most organizations, covering essential controls for critical components like etcd, the API server, kubelet, control plane, and worker nodes without significantly impacting functionality. It focuses on core security requirements such as proper access control, audit logging, certificate management, and basic network policies.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |   |
| <p>CIS Ubuntu Linux 24.04 LTS Benchmark - Server Level 1<br>CIS Ubuntu Linux 24.04 LTS Benchmark - Server Level 2<br>CIS Ubuntu Linux 24.04 LTS Benchmark - Workstation Level 1<br>CIS Ubuntu Linux 24.04 LTS Benchmark - Workstation Level 2</p> | 1.0.0   | The CIS Ubuntu Linux 24.04 LTS Benchmark v1.0.0 is an industry-standard hardening guide designed to secure Ubuntu 24.04 LTS environments against modern cybersecurity threats. Developed by security experts and the Center for Internet Security (CIS), it delivers actionable, step-by-step recommendations to reduce a system's attack surface—covering everything from restricting unused network protocols and tightening SSH access to configuring file permissions and system logging—ensuring systems align with rigorous regulatory compliance standards.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |   |
| NIST SP 800-190                                                                                                                                                                                                                                   | -       | <p>NIST Special Publication 800-190 provides guidance on the security concerns associated with application container technologies and makes practical recommendations for addressing those concerns.<br>It covers the potential security risks for the core components of container technologies—images, registries, orchestrators, containers, and host operating systems—and recommends countermeasures for those risks.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |   |

## Updated built-in compliance standards

The underlying rules were updated for the following compliance standards:

{% hint style="info" %}
Updates to compliance standards may affect assessment results.
{% endhint %}

| Change summary                                                                              | Version | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Updates to CIS Microsoft Windows Server 2019 Benchmark                                      | 3.0.1   | Introduced our first set of network scanning rules to audit hardened configurations for Windows Server 2019. This allows for automated discovery of OS-level configuration drifts and security gaps across server endpoints via network scanning.                                                                                                                                                                                                                                                                                                                                           |
| Updates to CIS Microsoft Windows Server 2016 Benchmark                                      | 3.0.0   | Introduced our first set of network scanning rules to audit hardened configurations for Windows Server 2016. This allows for automated discovery of OS-level configuration drifts and security gaps across server endpoints via network scanning.                                                                                                                                                                                                                                                                                                                                           |
| Mapped SaaS-specific security configurations rules to existing standards.                   | -       | <p>Introduced our first set of SaaS-specific security configurations rules and enabled rule mapping on existing benchmarks.</p><p>This delivers enhanced visibility into SaaS misconfigurations and identity risks, ensuring full alignment with enterprise security frameworks and cloud compliance standards.</p><p>The following standards were updated:</p><ul><li>CIS Critical Security Controls v8</li><li>HIPAA</li><li>NIST Cybersecurity Framework (CSF) v1.1</li><li>NIST SP 800-53 Rev. 5</li><li>PCI DSS v4.0.1</li><li>SOC 2</li></ul>                                         |
| Mapped AI-focused cloud security posture management rules to all existing AI standards.     | -       | <p>Appended new AI-related configuration rules to the existing standards to strengthen the governance and management of AI systems.</p><p>This provides a more comprehensive assessment of AI risk management practices, ensuring alignment with international safety and ethical standards.</p><p>The following standards were updated:</p><ul><li>EU AI Act</li><li>ISO/IEC 42001:2023</li><li>NIST AI 600-1</li><li>OWASP Top 10 for LLM Applications 2025</li><li>OWASP Top 10 for Agentic Applications 2026</li></ul>                                                                  |
| Mapped AI-focused Application Security rules to all existing AI standards.                  | -       | <p>Appended new AI-related Application Security rules to existing standards to strengthen the governance, security, and risk management of AI systems.</p><p>This provides a more comprehensive assessment of AI security risks, ensuring your applications maintain continuous alignment with emerging international safety, privacy, and ethical standards.</p><p>The following standards were updated:</p><ul><li>EU AI Act</li><li>ISO/IEC 42001:2023</li><li>NIST AI 600-1</li><li>OWASP Top 10 for LLM Applications 2025</li><li>OWASP Top 10 for Agentic Applications 2026</li></ul> |
| Updates to NIST SP 800-53 Rev. 5                                                            | -       | Expanded the workload security ruleset with direct mappings to the NIST SP 800-53 Rev. 5 framework. This allows security and GRC teams to automatically detect runtime and configuration risks across virtual machines, containers, and cloud workloads, ensuring continuous alignment with federal security controls.                                                                                                                                                                                                                                                                      |
| Mapped workload security ruleset to General Data Protection Regulation (GDPR) requirements. | -       | Expanded the workload security ruleset with direct mappings to General Data Protection Regulation (GDPR) requirements. This helps security and privacy teams continuously monitor cloud workloads handling personal data, ensuring technical safeguards—like data minimization, access restrictions, and encryption—are enforced automatically.                                                                                                                                                                                                                                             |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/compliance-standards-updates/july-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
