September 2026: Major Advances in Information Technology Standards

September 2026: Major Advances in Information Technology Standards
September 2026 sees five influential international standards published for the information technology (IT) community, reshaping practices in health informatics, emerging human-computer interfaces, packaging traceability, medical device maintenance, and cryptographic security. These standards set new expectations for interoperability, data protection, risk management, and technical reliability—making them essential references for quality managers, compliance officers, engineers, and IT procurement leaders.
Overview
In the rapidly evolving field of Information Technology and Office Equipment, international standards are essential to maintain product quality, safeguard data, ensure interoperability, and protect privacy. This month’s five new standards cover advances ranging from healthcare IT security to brain–computer interfaces and secure digital communications. In this article, you’ll learn:
- The scope and impact of each new standard
- Practical requirements for compliance and implementation
- Key changes and technical innovations
- How these standards shape IT operations and business risk
Detailed Standards Coverage
EN ISO 20737:2026 - Health Informatics – Interoperability of Personal Health Decision Support Services
Health informatics - Interoperability of personal health decision support services (ISO 20737:2026)
This standard sets unified requirements for interoperability among personal health decision support (PHDS) services, data providers, and PHDS clients. Its goal is to ensure accurate and reliable health decisions through seamless and secure data exchange, greatly benefitting systems that support self-care, disease management, and chronic condition monitoring.
Key requirements and scope:
- Standardizes data flows between PHDS services, data sources, and end-users.
- Mandates the use of standardized APIs and data formats for data acquisition, transmission, and validation.
- Specifies privacy and security controls, including encryption, access management, consent, and audit logging.
- Defines robust error handling, data synchronization, and reporting protocols.
These requirements are designed for all organizations that provide, integrate, or operate PHDS systems in healthcare environments.
Practical implications:
- Facilitates compatibility between digital health platforms, wearables, and clinical information systems.
- Enables vendors to build PHDS solutions that integrate effortlessly across diverse care settings.
- Promotes user trust through transparent privacy and consent management.
Notable changes:
- Enhanced emphasis on real-time data exchange and semantic interoperability.
- Clearer requirements for error response, incident management, and user-initiated data deletion compared to earlier drafts.
Key highlights:
- Standardized APIs and semantic data mapping for interoperable PHDS solutions
- Privacy, security, and consent management explicitly addressed
- Robust validation, error handling, and audit logging guidelines
Access the full standard:View EN ISO 20737:2026 on iTeh Standards
ISO/IEC 27572:2026 - Reference Architecture for Brain–Computer Interfaces
Information technology - Brain–computer interfaces - Reference architecture
Brain–computer interface (BCI) technology continues to bridge the gap between human cognition and digital systems. ISO/IEC 27572:2026 provides a comprehensive reference architecture (RA) for the design, implementation, and evaluation of BCIs, offering a shared vocabulary for users, architects, manufacturers, regulators, and public stakeholders.
Scope and key requirements:
- Defines key components, workflows, and roles in BCI ecosystems.
- Structures guidance around four architecture viewpoints: foundational, usage, functional, and implementation.
- Addresses stakeholder concerns about usability, reliability, safety, regulation, privacy, system performance, and ethical usage.
- Establishes categories for active, passive, reactive, and hybrid BCI systems with appropriate technical models and best practices.
Compliance targets:
- System architects, BCI vendors, service providers, and organizations assessing regulatory frameworks for neurotechnology.
Practical implications:
- Enables stakeholders to design scalable, secure, and interoperable BCI applications for healthcare, assistive devices, accessibility, and beyond.
- Provides manufacturers with clear guidelines to streamline innovation and ensure safety.
Notable changes:
- Introduces viewpoints for flexible mapping of stakeholder needs to system features.
- Comprehensive consideration of new and hybrid BCI categories.
Key highlights:
- Unified reference architecture for building and evaluating BCI systems
- Explicit coverage of risk, privacy, regulation, and usability
- Actionable models for various BCI implementation types
Access the full standard:View ISO/IEC 27572:2026 on iTeh Standards
ISO/TR 22251-1:2026 - RFID Performance on Returnable Metal Transport Items
Packaging — Measurement results for the use of RFID on returnable transport items — Part 1: Metal returnable transport items
RFID technology is central to supply chain digitization, but presents challenges with metal returnable transport items (RTIs) due to interference and reading range limitations. ISO/TR 22251-1:2026 is a technical report summarizing experimental results, best practices, and proven configurations for using RFID with metal RTIs in logistics and manufacturing.
Scope and requirements:
- Outlines types and features of metal RTIs and corresponding RFID tag technologies (passive, active, semi-active).
- Presents detailed measurements for communication distance, durability, and reliability under real-world and laboratory conditions.
- Discusses factors influencing performance: tag type, mounting methods, environmental factors, and tag antenna design.
Who should comply:
- Logistics operators, packaging engineers, RFID vendors, and supply chain professionals concerned with asset tracking and inventory accuracy.
Practical implications:
- Provides actionable criteria for selecting, installing, and validating RFID tags on metal RTIs.
- Reduces costly errors and inventory blind spots by choosing optimal tag types and configurations.
Notable advances:
- Validation of new metal-compatible tags, including communication time and durability over prolonged use.
- Analysis of real-world scenarios, including mass reading, manufacturing, and varied mounting approaches.
Key highlights:
- Experimental data on communication range and tag durability for metal RTIs
- Recommendations for RFID system configuration and deployment
- Facilitates more reliable and cost-effective RFID operations in challenging environments
Access the full standard:View ISO/TR 22251-1:2026 on iTeh Standards
ISO/TS 11633-1:2026 - Security for Remote Maintenance of Medical Devices
Health informatics — Information security management for remote maintenance of medical devices and medical information systems — Part 1: Requirements and risk analysis
With the broad adoption of networked medical equipment and remote maintenance capabilities, security and privacy risks have grown in complexity. ISO/TS 11633-1:2026 is a critical specification outlining legal and technical requirements, risk assessment methods, and management controls for secure remote support of medical devices and information systems.
Scope and specifications:
- Explains how to analyze and address risks during remote maintenance operations spanning both healthcare facilities (HCFs) and remote service centers (RSCs).
- Details requirements for asset identification, risk estimation (following ISO 31000 and ISO/IEC 27005), and practical joint risk analysis processes.
- Mandates secure communication (e.g., VPNs, firewalls), authentication (multi-factor, call-back functions), data confidentiality, incident response, and auditability.
- Provides contract management templates and best practices aligning with legal and privacy regulations.
Compliant organizations:
- Healthcare facilities, vendors, service providers, and any business responsible for or involved in remote maintenance of medical devices or healthcare IT systems.
Implementation considerations:
- Reduces downtime and maintenance costs while ensuring compliance and safety.
- Establishes a robust foundation for legal defensibility and audit readiness.
Notable changes:
- Revision aligns with current ISO/IEC 27001, ISO/IEC 27002, and modern privacy frameworks.
- Expanded examples of threats, risk analysis steps, and control selection.
Key highlights:
- Joint risk assessment and control framework for remote medical maintenance
- Secure communications, authentication, and continuous monitoring protocols
- Alignment with regulatory compliance and privacy requirements
Access the full standard:View ISO/TS 11633-1:2026 on iTeh Standards
ISO/IEC 29128-2:2026 - Evaluation of Cryptographic Protocols
Information security, cybersecurity, and privacy protection — Verification of cryptographic protocols — Part 2: Evaluation methods and activities for cryptographic protocols
Cryptographic protocols form the security backbone of digital communications and data protection. ISO/IEC 29128-2:2026 provides a robust methodological framework extending ISO/IEC 15408-4, defining roles, activities, and tools for protocol security assessment using both manual and automated analysis.
Scope and technical content:
- Maps work items for cryptographic protocol evaluation to associated verification activities.
- Establishes four assurance levels and confidence levels for automated provers, ensuring a measurable and reproducible evaluation process.
- Specifies the Dolev-Yao adversarial model as the threat baseline for comprehensive assessment.
- Provides guidance for model preparation, submission, and validation, including third-party and double-blind verification.
Applicable professionals:
- Cryptography engineers, security assessors, protocol designers, and organizations requiring verifiable, high-assurance digital security.
Implementation impact:
- Elevates the reliability of cryptographic assessments, reducing vulnerabilities in practical deployments.
- Enables detailed and standardized documentation during testing and certification phases.
New features:
- Enhanced classification of assurance and confidence levels for provers.
- Guidance for model reusability and third-party tool integration.
Key highlights:
- Standardized and layered process for verifying cryptographic protocols
- Reference models support reproducibility and benchmarking
- Supports automation and continuous improvement in protocol evaluation
Access the full standard:View ISO/IEC 29128-2:2026 on iTeh Standards
Industry Impact & Compliance
Adopting these latest information technology standards brings significant benefits and responsibilities:
- Enhanced interoperability: Adherence to standardized APIs, data formats, and reference models ensures compatibility across platforms and service providers.
- Strengthened security and privacy: Standards require stronger authentication, encryption, risk assessment, and privacy controls—vital for healthcare, supply chain, and cryptography operations.
- Regulatory alignment: Updated process and audit requirements make demonstrating legal compliance easier, streamlining audits, and reducing the risk of regulatory action.
- Operational efficiency: Risk management frameworks and robust technical recommendations help organizations minimize downtime, reduce maintenance costs, and increase supply chain transparency.
Compliance roadmap:
- Assess applicability and gaps between current practices and new standard requirements.
- Engage cross-functional teams (IT, compliance, procurement, operations) to implement recommended controls and configuration changes.
- Schedule internal audits and staff training to ensure ongoing compliance.
- Monitor for further updates and engage with vendors to ensure standard-aligned solutions.
Failure to comply can increase vulnerability to cyberattacks, compromise patient/consumer trust, and lead to legal or financial penalties.
Technical Insights
Though spanning health IT, neurotechnology, logistics, and cybersecurity, these standards share common technical themes:
- Reliance on formal models: Both in BCI and cryptographic protocol evaluation, the standards call for well-defined, auditable models that facilitate transparency and trust.
- Emphasis on risk management: Whether in remote medical system maintenance or cryptography, risk identification and analysis are central, using structured frameworks derived from ISO/IEC 27001, 27005, and 31000.
- Automation and interoperability: RFID systems and protocol analysis benefit from external tools and automated processes, speeding up verification and increasing confidence in outcomes.
- Testing and certification: Each standard provides explicit guidance on validation (lab/field tests, third-party provers, or simulated attacks) and audit trails to demonstrate compliance.
Implementation best practices:
- Stay current with related supporting standards (e.g., ISO/IEC 27001/27002, 29128-1, 15408-4), as referenced within and required for full compliance.
- When deploying security controls, use layered defense—strong authentication, encryption, monitoring, and incident response.
- Regularly review supplier and vendor alignment with new requirements, especially for BCIs, health informatics, and RFID equipment.
Conclusion / Next Steps
The five new information technology standards launched in September 2026 set a clear path for IT innovation, safety, and responsible management. Medical and health technology professionals should focus on integrating PHDS interoperability, robust risk analysis for remote device maintenance, and compliance with data protection standards. Engineers and designers in the emerging field of brain–computer interfaces now have a universal reference architecture to guide their work, while cybersecurity teams gain a granular methodology to evaluate and assure cryptographic protocols. For logistics and manufacturing, the new RFID guidance brings measurable improvements to traceability and asset management on metal RTIs.
Recommendations:
- Assess your organization’s needs against these standards and close any compliance gaps.
- Standardize processes for risk assessment, testing, and certification to benefit from efficiency and security improvements.
- Use iTeh Standards to access full documents, stay updated, and participate in future industry-driven updates.
Explore the full standards and enhance your IT compliance and capability at iTeh Standards.
Categories
- Latest News
- New Arrivals
- Generalities
- Services and Management
- Natural Sciences
- Health Care
- Environment
- Metrology and Measurement
- Testing
- Mechanical Systems
- Fluid Systems
- Manufacturing
- Energy and Heat
- Electrical Engineering
- Electronics
- Telecommunications
- Information Technology
- Image Technology
- Precision Mechanics
- Road Vehicles
- Railway Engineering
- Shipbuilding
- Aircraft and Space
- Materials Handling
- Packaging
- Textile and Leather
- Clothing
- Agriculture
- Food technology
- Chemical Technology
- Mining and Minerals
- Petroleum
- Metallurgy
- Wood technology
- Glass and Ceramics
- Rubber and Plastics
- Paper Technology
- Paint Industries
- Construction
- Civil Engineering
- Military Engineering
- Entertainment