September 2026 Standards Update: New Advances in Information Technology

September 2026 Brings Major Innovations in Information Technology Standards
September 2026 ushers in a new chapter for the Information Technology and Office Equipment sector, with five significant international standards newly released. This update is crucial for professionals navigating health informatics, cybersecurity, 3D printing, and emerging technologies such as brain-computer interfaces. Each new standard sets forth requirements and frameworks that advance regulatory alignment, secure data exchange, and system interoperability. This article delivers a comprehensive analysis of the standards, highlighting core changes, practical implementation advice, and the broad industry effects for quality managers, IT architects, compliance officers, engineers, and more.
Overview / Introduction
The Information Technology industry is at the forefront of digital innovation, touching every sector from healthcare to manufacturing and advanced research. Keeping pace with standards is essential: robust specifications underpin secure interoperability, efficient workflows, and safe data management.
In this September 2026 update, five international standards make their debut. They address:
- Audit trails and data integrity for electronic health records (EHRs)
- Secure authentication for OpenID Connect in financial APIs
- Quality assessment methods for 3D printing modeling software
- Reference architecture for brain-computer interfaces (BCIs)
- Security protocols for EHR communication
Readers will gain:
- A clear summary of each standard’s scope and applicability
- Insight into technical and compliance requirements
- Practical guidance for implementation
- Understanding of the broader impacts on industry and organizational best practices
Detailed Standards Coverage
prEN ISO 27789 - Audit Trails for Electronic Health Records
Health informatics - Audit trails for electronic health records (ISO/DIS 27789:2026)
This standard establishes a comprehensive framework for generating, managing, and maintaining audit trails in Electronic Health Record (EHR) systems. It focuses on recording user events—such as data access, creation, updates, and archiving—to ensure all personal health information is auditable across disparate systems and domains.
Scope and Requirements:
- Specifies event logging requirements covering user identification, subject of care, performed functions, and precise timestamps
- Applies to any information system that processes and stores personal health information
- Excludes audit logs for general IT system management and security
- Mandates secure, confidential, and tamper-proof audit records
- Outlines audit record structure, including event/action codes, roles, access points, source identification, and participant object references
Target Audience:
- Hospitals and clinics using EHR systems
- Health IT vendors
- Compliance and privacy managers in healthcare
Implementation Implications:
- Organizations must ensure that every user interaction with the EHR triggers a secure audit trail record
- Supports regulatory alignment with privacy and data protection laws (such as GDPR)
- Assists in governance, supervision, and the defense of patient rights
- Annexes provide real-world audit scenarios and audit log service overviews for practical adoption
Notable Updates:
- Harmonizes audit event recording across national and international health domains
- Simplifies compliance by standardizing audit policy references and data elements
Key highlights:
- Event-driven, detailed audit logging for EHR actions
- Strong emphasis on security and data integrity
- Supports automated, standards-based compliance monitoring
Access the full standard:View prEN ISO 27789 on iTeh Standards
ISO/IEC 25791-1:2026 - OpenID Connect FAPI Security Profile 1.0 — Baseline
Information technology — OpenID Connect FAPI Security Profile 1.0 — Part 1: Baseline
This standard introduces the baseline security profile for OpenID Connect Financial-grade API (FAPI) implementations. It details methods for obtaining OAuth tokens and securing access to protected data through REST APIs.
Scope and Requirements:
- Defines authorization server requirements, including confidential/public client support, mutual TLS, client secret protection, redirect URI validation, and token entropy
- Specifies privacy and security requirements for moderately sensitive APIs beyond basic OAuth 2.0
- References key normative documents (e.g., RFC 6749, RFC 7636, OIDC Core)
- Stipulates robust mechanisms against replay, integrity, and authentication failures
- Recommends regular assessment of token lifetimes (<10 minutes) and explicit user authorization
Target Audience:
- Financial institutions
- API providers handling sensitive user data
- Cybersecurity teams implementing federated identity solutions
Practical Implications:
- Reduces security risks common in screen scraping by shifting to secure, token-based authorization
- Simplifies cross-market adoption, enabling compliant fintech and open banking operations
- Encourages adoption of standardized user authentication flows, critical for modern API ecosystems
Recent Changes:
- Part 1 sets a moderation threshold for security—advanced requirements are found in Part 2
- Refines error handling and token scoping to mitigate privilege escalation
Key highlights:
- Strong baseline security for OpenID Connect-based APIs
- Explicit obligations for server/client configuration
- Improves user privacy and reduces systemic risks in digital financial services
Access the full standard:View ISO/IEC 25791-1:2026 on iTeh Standards
ISO/IEC 24956:2026 - Phantom-Based Evaluation for 3D Printing Modeling Software
Information technology — 3D printing and scanning — Phantom-based evaluation methods for 3D printing modeling software
This standard introduces a universal, objective method for measuring the accuracy and precision of 3D modeling software used in additive manufacturing. Instead of focusing on the printed product, it addresses the initial digital modeling phase using standardized phantoms—reference objects scanned to assess system performance.
Scope and Requirements:
- Defines phantom-based assessment criteria for 3D modeling workflows
- Outlines mandatory accuracy, precision, repeatability, and software compatibility checks
- Establishes quality management and evaluation templates for reporting
- Standardizes segmentation and 3D reconstruction performance evaluation
Target Audience:
- Software developers and vendors in the 3D printing industry
- Medical device manufacturers employing 3D-printed components
- Research organizations and quality control labs
Implementation Considerations:
- Supports procurement and regulatory review by introducing reproducible benchmarks
- Facilitates comparison across 3D modeling tools
- Enables effective quality assurance throughout the 3D print lifecycle
Recent Advances:
- Brings standardization to phantom use, ensuring test data objectivity, realism, and repeatability
- Enables cost-effective, non-destructive performance validation
Key highlights:
- Standardized assessment for modeling accuracy in 3D printing
- Focus on software performance, not the end-printed object
- Enhances reliability and comparability for quality assurance processes
Access the full standard:View ISO/IEC 24956:2026 on iTeh Standards
ISO/IEC 27572:2026 - Brain-Computer Interfaces — Reference Architecture
Information technology — Brain-computer interfaces — Reference architecture
This pioneering standard offers a unified, high-level reference architecture for Brain-Computer Interface (BCI) systems, supporting developers, vendors, regulators, and end users in achieving safe, consistent, and efficient implementations.
Scope and Structure:
- Defines architectural views: foundational, usage, functional, and implementation
- Examines cross-cutting concerns such as privacy, data security, usability, performance, and regulatory compliance
- Details stakeholder roles, including users, architects, manufacturers, service providers, and regulators
- Supports different BCI types (active, passive, reactive, hybrid), and categorizes concerns for each
- Builds on ISO/IEC/IEEE 42010 system and software architecture terminology
Target Audience:
- BCI device developers and application designers
- Medical device regulators and product certifiers
- System architects and technology innovators
Implementation Notes:
- Provides a standardized approach to describing, analyzing, and developing BCI solutions
- Enables integration with broader health informatics and digital device networks
- Facilitates clearer communication across interdisciplinary BCI teams
Innovative Elements:
- First ISO/IEC standard targeting holistic BCI architecture
- Supports compliance with emerging ethical, safety, and effectiveness requirements
- Lays groundwork for certification, conformance testing, and international collaboration
Key highlights:
- Architectural framework for safe, secure, and usable BCI systems
- Covers direct user interaction, hardware/software design, and data governance
- Advances harmonization and quality assurance in a rapidly evolving field
Access the full standard:View ISO/IEC 27572:2026 on iTeh Standards
EN ISO 13606-4:2026 - EHR Communication Security
Health informatics - Electronic health record communication - Part 4: Security (ISO 13606-4:2026)
This update delivers a detailed methodology for specifying and managing privileges needed to access electronic health record (EHR) data. As part of the broader ISO 13606 suite, Part 4 focuses on secure, standards-based EHR communication—essential for privacy, consent management, and regulatory compliance.
Scope and Provisions:
- Defines a methodology for representing, communicating, and enforcing EHR access policy
- Covers general and EHR-specific security requirements
- Details use of functional roles and granular sensitivity labels for record components
- Enables automated, policy-driven EHR data exchange and audit logging
- Includes technical solutions, UML modeling, and mapping of access policy to EHR extract elements
Target Industries:
- Healthcare providers and EHR software vendors
- Data protection officers and compliance managers
- Developers and integrators of cross-border and inter-organizational EHR systems
Implementation Benefits:
- Supports fine-grained, role-based privilege management
- Reduces manual effort and delays in EHR access decisions
- Improves patient data protection, auditability, and consent management
What's New in This Edition:
- Expanded numeric tables for access and audit constraints
- Improved anonymization for sample cases
- Corrections and clarifications in definitions and scope
Key highlights:
- EHR-specific security and access control methodology
- Automation-friendly access policy definitions
- Designed for interoperability across borders and organizations
Access the full standard:View EN ISO 13606-4:2026 on iTeh Standards
Industry Impact & Compliance
The new releases for September 2026 are reshaping compliance, quality assurance, and interoperability across the Information Technology and Office Equipment sector. Organizations updating to these standards should consider the following impact areas:
- Operational Efficiency: Standardized audit trails and secure communication protocols speed up EHR exchanges while protecting personal data
- Risk Reduction: Robust frameworks for OpenID Connect and BCI design lower exposures to cyber threats, data breaches, and regulatory penalties
- Regulatory Alignment: Adopting these standards demonstrates due diligence and supports certification, especially in heavily regulated sectors such as healthcare and finance
- Competitive Edge: Early compliance boosts trust, interoperability, and market access—critical in cross-border operations or public sector IT procurement
Compliance Considerations:
- Map current processes to the new standard requirements
- Leverage annexes, templates, and technical notes to expedite implementation
- Plan for transition periods and cross-train technical teams
- Consider certification or third-party assessment for critical domains
Failure to comply can increase data breach risk, delay market entry, and result in regulatory actions or loss of trust.
Technical Insights
While the five standards address diverse domains, several common technical themes emerge:
- Auditability and Security by Default: Systematic event logging and secure authentication are foundational for all standards
- Granular Access Control: Fine-grained privileges—whether for EHRs or APIs—protect sensitive assets while supporting business agility
- Phantom-Driven and Objective Testing: The use of reference artifacts (phantoms) in software evaluation introduces repeatability, essential in regulated environments
- Reference Architectures: Codified architectural patterns accelerate development cycles, enable risk management, and clarify stakeholder concerns
Implementation Best Practices:
- Interpret the full requirements in light of system scope, regulatory landscape, and security posture
- Adopt reference policies and evaluation criteria as baseline; tailor as needed
- Invest in strong identity and access management (IAM), including detailed audit and privilege mapping
- Validate software and system conformance through rigorous, scenario-based testing
- Document all changes and maintain a record of compliance actions for audits and certification processes
Conclusion / Next Steps
September 2026’s new wave of Information Technology standards delivers powerful tools to improve security, interoperability, software quality, and innovation readiness. Stakeholders in healthcare, financial services, manufacturing, and beyond must:
- Analyze the full text of each standard
- Map gaps between current practices and new requirements
- Engage with cross-functional teams—compliance, IT, R&D—to plan upgrades and training
- Monitor the iTeh Standards platform for updates, guidance documents, and new releases
Stay ahead of the curve by reviewing, adopting, and leveraging these vital new standards. For detailed technical specifications, implementation templates, and updates, visit iTeh Standards, your authoritative resource for international standardization.
Categories
- Latest News
- New Arrivals
- Generalities
- Services and Management
- Natural Sciences
- Health Care
- Environment
- Metrology and Measurement
- Testing
- Mechanical Systems
- Fluid Systems
- Manufacturing
- Energy and Heat
- Electrical Engineering
- Electronics
- Telecommunications
- Information Technology
- Image Technology
- Precision Mechanics
- Road Vehicles
- Railway Engineering
- Shipbuilding
- Aircraft and Space
- Materials Handling
- Packaging
- Textile and Leather
- Clothing
- Agriculture
- Food technology
- Chemical Technology
- Mining and Minerals
- Petroleum
- Metallurgy
- Wood technology
- Glass and Ceramics
- Rubber and Plastics
- Paper Technology
- Paint Industries
- Construction
- Civil Engineering
- Military Engineering
- Entertainment