September 2026: Key Information Technology Standards Every IT Professional Should Know

In September 2026, the landscape of Information Technology and Office Equipment was reshaped by the release of five groundbreaking standards. Targeted at bolstering digital trust, interoperability, risk-based assurance, and secure data management, these newly published specifications are poised to influence organizations across sectors. For IT professionals, compliance officers, engineers, and procurement specialists, understanding these standards is essential for robust governance, product assurance, and seamless global operations.
Overview / Introduction
The rapid evolution of digital platforms, e-commerce, and AI-powered applications is transforming how organizations interact with data, manage identities, and guarantee product integrity. International standards play a vital role in harmonizing requirements for security, privacy, data interoperability, and conformance. This article introduces five newly released standards, offering actionable insights for implementing next-generation solutions:
- Advanced AI-based image coding (JPEG AI) conformance
- Secure, reliable Digital Product Passports (DPP)
- Comprehensive identity management architectures and practices
- Risk-based quality data interchange for global e-commerce
By mastering these specifications, organizations can elevate their digital readiness, improve trust with stakeholders, and reduce risks in an increasingly interconnected world.
Detailed Standards Coverage
ISO/IEC 6048-4:2026 - JPEG AI Learning-Based Image Coding Conformance
Information technology — JPEG AI learning-based image coding system — Part 4: Conformance
This standard defines the testing frameworks, methodologies, and criteria for conformance with the JPEG AI image coding system (Rec. ITU-T T.840.1/ISO/IEC 6048-1). It introduces test suite files, reference data, and clearly specified procedures to validate decoder implementations against different operational profiles, such as Main@Simple, Main@Base, and Main@High.
Key requirements include:
- Use of executable test suites covering decoded residual tensors, latent space tensors, and final image outputs
- Definition of strict ('Type A') and moderate ('Type B') conformance categories, reflecting variations in hardware and floating-point models
- Step-by-step methodology for conducting decoder tests, comparing the results against reference outputs using objective metrics like Mean Squared Error (MSE) and Peak Signal to Noise Ratio (PSNR)
- Provision of auxiliary test software and sample files for practical implementation
Target organizations include imaging system developers, codec integrators, and compliance teams in media processing industries.
Practical implications:
- Ensures interoperability and reliability in AI-based image coding applications
- Facilitates evidence-based certification through objective conformance benchmarks
- Streamlines validation of both new and updated JPEG AI-based solutions
Key highlights:
- Standardized decoder conformance testing for AI-driven image compression
- Objective metrics and reference test suites for quality assurance
- Clear distinction between strict and soft conformance for varying deployment needs
Access the full standard:View ISO/IEC 6048-4:2026 on iTeh Standards
EN 18246:2026 - Digital Product Passport Data Authentication
Digital product passport - Data authentication, reliability and integrity
In response to growing demands for transparency across supply chains, EN 18246:2026 sets forth requirements and frameworks for securing information in Digital Product Passport (DPP) exchanges. The standard places particular emphasis on data authentication, reliability, and integrity, minimizing risks of product fraud, counterfeiting, and data tampering.
Scope and specifications:
- Establishes frameworks using secure Electronically Signed Data Constructs (ESDCs) for data exchange across multiple actors
- Defines terms and general security assumptions for DPP systems
- Outlines risk management for unique product identifiers, protecting against unauthorized access, profiling, and malicious code
- Covers requirements for accessibility, multilingual environments, and preserving existing traceability/authentication systems
- Provides annexes with examples of ESDC implementations and fair competition considerations
Applicability:
- Manufacturers, importers/exporters, retailers, supply chain managers, and auditing authorities
- Sectors requiring strong data provenance and anti-counterfeiting protocols
Practical implications:
- Enables trusted, interoperable data exchange throughout product lifecycles
- Facilitates legal compliance and supports circular economy initiatives
- Strengthens digital trust among stakeholders, including end-users and regulators
Key highlights:
- Comprehensive ESDC framework for ensuring DPP authenticity
- Risk-based controls for privacy, anti-fraud, and anti-profiling
- Illustrative annexes for implementation and real-world applicability
Access the full standard:View EN 18246:2026 on iTeh Standards
EN ISO/IEC 24760-2:2026 - Identity Management Framework: Reference Architecture
Information security, cybersecurity and privacy protection - A framework for identity management - Part 2: Reference architecture and requirements (ISO/IEC 24760-2:2025)
This foundational document articulates the reference architecture for identity management systems, providing guidelines and explicit requirements for secure, privacy-friendly management of identity data in information systems. It is structured as a horizontal standard, designed to underpin a wide range of identity-related applications.
Major features:
- Clearly distinguishes between 'identity' and 'identifier' in data systems
- Details the roles of principals, identity authorities, relying parties, auditors, and regulatory bodies
- Presents key processes—such as identity registration, authentication, auditing, and delegation—in a modular architecture
- Specifies requirements for management, storage, archiving, and deletion of identity data in compliance with privacy and legal mandates
Target audiences:
- IT architects, identity/governance teams, risk, and compliance officers
- Organizations deploying enterprise, federated, or cloud-based identity frameworks
Practical implications:
- Enables robust, interoperable identity systems at scale
- Ensures foundational privacy and compliance for personal and organizational data
- Streamlines evaluation of conformance to regulatory requirements
Key highlights:
- Comprehensive reference architecture for identity information management
- Role-based stakeholder modeling and deployment scenarios
- Horizontal framework supporting diverse identity-centric applications
Access the full standard:View EN ISO/IEC 24760-2:2026 on iTeh Standards
EN ISO/IEC 24760-3:2026 - Identity Management: Best Practice Guidance
Information security, cybersecurity and privacy protection - A framework for identity management - Part 3: Practice (ISO/IEC 24760-3:2025)
As a vital companion to Part 2, this standard delivers in-depth guidance and requirements for managing identity information in practical settings. It aligns with both ISO/IEC 24760-1 and 24760-2, making it universal for any IT ecosystem processing identity-related data.
Scope and specifics:
- Details processes for risk assessment, assurance levels, credential management, and identity proofing
- Distinguishes 'identity' vs. 'identifier' to mitigate privacy and data integrity risks
- Recommends control objectives and architectural controls for the full lifecycle of identity management systems
- Emphasizes the need for privacy-by-design, trustworthy credentialing, and regular auditing
Applicability:
- Any organization processing or storing identity information—corporate, governmental, cloud service providers, and integrators
Practical implications:
- Strengthens implementation practices for privacy and security in identity management
- Provides audit frameworks and assurance models for trustworthy identity systems
- Guides operational hardening and regulatory compliance
Key highlights:
- Detailed operational best practices for robust identity management
- Risk-based control sets for identity assurance and privacy protection
- Aligns practical implementation with architecture and policy standards
Access the full standard:View EN ISO/IEC 24760-3:2026 on iTeh Standards
ISO/TR 20180:2026 - Risk-Based Product Quality Data Interchange in E-Commerce
Risk-based product quality data interchange in e-commerce
This technical report addresses the pressing challenges of managing consumer product safety in rapidly growing e-commerce environments. It establishes a framework for identifying, exchanging, and evaluating product quality data based on risk assessment methodologies tailored for e-commerce supply chains.
Coverage includes:
- Analysis of the e-commerce supply chain context, including roles of suppliers, platform operators, logistics providers, and authorities
- Detailed steps for risk identification, analysis, and evaluation of product safety hazards and vulnerabilities
- Use cases for risk-driven product quality data sharing and real-world implementation guidance
- General process models for data interchange, augmented with examples and XML schema references for interoperability
Applicability:
- E-commerce platform operators, sellers, logistics and warehouse managers, customs and regulatory agencies
Practical implications:
- Improves product safety and regulatory compliance via risk-informed data exchange
- Promotes interoperability and stakeholder collaboration in transnational e-commerce
- Assists organizations in prioritizing quality control and data management resources
Key highlights:
- Framework for risk assessment and quality data sharing in e-commerce
- Role-based process models, datasets, and use case analysis for real-world adoption
- Technical guidance for harmonizing e-commerce risk data globally
Access the full standard:View ISO/TR 20180:2026 on iTeh Standards
Industry Impact & Compliance
With these standards now in force, organizations face a new level of clarity and confidence in addressing data security, privacy, quality assurance, and operational risk. Adoption is essential for:
- Enhancing digital trust—providing verifiable, tamper-evident records for image coding, product data, and identity management
- Achieving regulatory compliance—meeting European, international, and cross-sector mandates for data protection, transparency, and anti-fraud
- Facilitating business agility—ensuring that products and services can interoperate across borders, sectors, and organizational boundaries with confidence
Compliance timelines are typically based on national adoption of international standards and sector-specific requirements. Early adopters gain marketplace reputational advantages and are better positioned to avoid penalties related to data breaches, non-conformances, and fraud.
Risks of non-compliance include:
- Product recalls or restricted market access
- Reputational harm from security incidents or privacy violations
- Disruption of digital and physical supply chains due to interoperability failures
Technical Insights
Across these standards, several technical themes emerge:
Conformance and Verification: Objective test suites, executable reference data, and strict/soft verification criteria support reliable validation in AI-based coding and identity environments.
Digital Trust: Authenticated, electronically signed data constructs underpin secure data exchange in DPP and e-commerce models, expanding trusted supply chain infrastructures.
Identity & Privacy: The differentiation between 'identity' and 'identifier' clarifies governance models and supports privacy-friendly frameworks. Control objectives, risk assessment, and lifecycle management embed privacy-by-design.
Risk Management: E-commerce and identity frameworks require context-driven risk assessment to align controls, prioritize data sharing, and manage evolving threats.
Implementation Best Practices:
- Regularly audit and validate conformance in line with test suite guidance
- Use standardized digital signatures and ESDC templates to ensure data authenticity
- Practice least-privilege data access, data minimization, and robust logging in identity and e-commerce workflows
- Train personnel on risk assessment and data governance aligned with current standards
Testing and Certification: Organizations are encouraged to pursue third-party certifications based on these standards and participate in interoperability testing initiatives.
Conclusion / Next Steps
These five new standards fundamentally elevate the benchmarks for information security, digital trust, and operational efficiency in the Information Technology sector. By comprehensively addressing conformance, authentication, identity, and e-commerce risk, they offer an actionable roadmap for IT professionals, compliance teams, and business leaders aiming to future-proof their digital strategies.
Key takeaways:
- Ensure up-to-date compliance—review policies and implementation plans against current standards
- Conduct internal gap analyses and participate in pilot conformance and interoperability exercises
- Leverage iTeh Standards for authoritative access to documentation, updates, and support tools
- Remain engaged with ongoing standardization to anticipate and influence further developments
Explore the full texts and begin your compliance journey today:
- Visit iTeh Standards Information Technology Catalog
- Browse September 2026 Information Technology Standards
Stay ahead by investing in standards that shape tomorrow’s IT landscape.
Categories
- Latest News
- New Arrivals
- Generalities
- Services and Management
- Natural Sciences
- Health Care
- Environment
- Metrology and Measurement
- Testing
- Mechanical Systems
- Fluid Systems
- Manufacturing
- Energy and Heat
- Electrical Engineering
- Electronics
- Telecommunications
- Information Technology
- Image Technology
- Precision Mechanics
- Road Vehicles
- Railway Engineering
- Shipbuilding
- Aircraft and Space
- Materials Handling
- Packaging
- Textile and Leather
- Clothing
- Agriculture
- Food technology
- Chemical Technology
- Mining and Minerals
- Petroleum
- Metallurgy
- Wood technology
- Glass and Ceramics
- Rubber and Plastics
- Paper Technology
- Paint Industries
- Construction
- Civil Engineering
- Military Engineering
- Entertainment