What Normdiff is and how it works
Normdiff is a change feed for security standards and regulations: it watches 187 official sources and publishes what changed, when it takes effect and who it affects.
In industry terms, this is regulatory change monitoring: the part of regulatory change management that finds a change in a standard or a law and says what it means. It is written for CISOs, security engineers, compliance consultants and teams working toward SOC 2 or ISO 27001.
Normdiff tracks 162 frameworks from 187 official sources in 34 jurisdictions
The frameworks are security standards, laws and regulations. The sources are the channels their publishers use: regulators, standards bodies and national authorities.
- Global: 43 frameworks, including PCI DSS, CIS Benchmarks, NIST CSF, SPARTA and CIS Controls.
- EU: 18 frameworks, including GDPR, PSD2 SCA, CRA, EU AI Act and ENISA.
- US: 41 frameworks, including FedRAMP, CISA, TIC 3.0, GovRAMP and FINRA Cybersecurity.
- UK: 7 frameworks, including UK GDPR, NCSC, UK NIS Regulations, CAP 1850 and Cyber Essentials.
- Ukraine: 10 frameworks, including UA Cybersecurity Law, NBU Regulation 95, UA Cloud Services Law, DSSZZI KSZI Requirements and UA Personal Data Law.
- Other countries: 43 frameworks, including LGPD, Singapore PDPA, CCCS guidance, Korea PIPA and Japan APPI.
Every framework has a page in the catalogue, with its description and a link to the publisher. The catalogue also names 37 planned frameworks. They are not monitored yet: no change is published for them, so an empty page for one of them does not mean nothing changed.
How it works
We continuously monitor official publications from regulators, standards bodies and national authorities. When something changes, AI models write a short description of it: what changed, who it affects and when it takes effect, with a link to the original.
Not everything that changes is published. Commentary about rules that did not change, such as blog posts, explainers and event announcements, is left out, and so are changes that concern no framework in the catalogue. Enforcement actions, such as a regulator's fine, are published when they concern a framework in the catalogue.
When a published entry turns out to be wrong, it is withdrawn, and its page says so.
For paid standards, such as those of ISO and IEC, we publish the fact of a change, its version and date, and a link to the publisher. The text of the standard itself is not stored or reproduced.
Severity says how soon a change needs action
Each change gets one of five severity levels, from the type of change, whether it requires action, and its dates.
- Critical: action is required, and the deadline or effective date is 30 days away or less.
- High: action is required, and the date is 31 to 90 days away or passed within the last 30 days. A withdrawn document is always at least High.
- Medium: action is required, with no date or a date further away. A regulator's action against another organisation is never above Medium.
- Low: the change requires no action.
- Info: a draft or consultation, or a change whose type cannot be determined.
Changes are published in the feed, in RSS and in Telegram alerts
- The feed lists published changes and filters them by framework, jurisdiction and severity. Without an account it shows the last 90 days; every change keeps its own public page.
- RSS: the whole feed, and a separate feed for each monitored framework, such as PCI DSS.
- The deadlines page, and the same dates as a calendar file to subscribe to.
- With a free account, a private feed for up to 2 frameworks, on the web and in RSS, without alerts.
- On Pro, alerts in Telegram for up to 5 frameworks, a weekly check-in and a quarterly evidence pack for auditors.
What Normdiff is not
- Not legal advice. A description summarises an official document, and the document always prevails over it. See the terms.
- Not a GRC or compliance automation suite. It does not map changes to your controls, assign tasks or track remediation. The evidence pack records what changed and when you were told; it does not attest compliance.
- Not a page-change watcher. Instead of showing which lines of a web page moved, it says what the change requires, of whom and from when, and leaves out changes that alter nothing.
Questions
How to get notified when PCI DSS, ISO 27001 or NIST publish a change
Subscribe to the framework's RSS feed from its page: PCI DSS, ISO 27001, NIST CSF or NIST SP 800-53. This is free and needs no account. For alerts in Telegram, sign in, choose your frameworks and turn on Pro.
Is Normdiff free?
The public feed, every change page, the RSS feeds and the deadline calendar are free and need no account. Alerts are part of Pro, $29 per month, which is free during early access. See pricing.
Where the data comes from
From the publishers of the standards and laws: regulators, standards bodies and national authorities. Every published change links to its source.
How fast a change appears
Sources are monitored continuously. A change appears in the feed, in RSS and in alerts as soon as its description is published.