Product Roadmap · 2026–2028

Where compliance is going,
and what we are building for it.

The next two years of Iron Fort, reasoned from published regulatory calendars and what buyers are actually asking our customers for. Every item says how certain it is. Every claim says where it came from.

Talk to us about priorities See what ships today

Six Signals We Are Building Against

A roadmap is only as good as its reading of the market. Here is ours, with sources, so you can disagree with the reasoning rather than just the conclusion.

70%+

of enterprise buyers require a SOC 2 report

Buyer demand, not regulation, is what drives this market. Adoption is growing fastest among earlier-stage startups — the teams least able to absorb a $15k–$80k first-year audit.

Source: Agency Insights, SOC 2 statistics 2026
~40%

of EU enterprise AI RFPs now ask about ISO 42001

Around 25% in North America. Certification bodies are backlogged, with Stage 2 audit waits reaching six months or more — so readiness tooling matters before auditor capacity does.

Source: Konfirmity, ISO 42001 (2026)
2 Dec 2027

the EU AI Act high-risk deadline, after the Digital Omnibus

Parliament approved the delay on 16 June 2026. Annex III systems move to December 2027 and Annex I to August 2028 — but Article 50 transparency held its 2 August 2026 date.

Source: Gibson Dunn, EU AI Act Omnibus agreement
$80B

sovereign cloud IaaS spending forecast for 2026

Up 35.6% year on year. Compliance evidence increasingly has to be collected from estates that never touch a hyperscaler — private vSphere, colocated racks, and regional VPS.

Source: Gartner, via Cyber Sierra
$250M

paid for SafeBase, folding trust pages into compliance suites

Drata acquired SafeBase in February 2025. The trust page stopped being a standalone product and became something a compliance platform is expected to publish.

Source: ComplyJet, trust centre market
2026

NIST ships AI control overlays for SP 800-53

RMF 1.1 addenda, the Cyber AI Profile and SP 800-53 control overlays for AI are all tracking through 2026, alongside a critical-infrastructure profile opened in April.

Source: NIST AI Risk Management Framework

How to read this page. Near term is what we expect to reach first and have the clearest picture of. Planned is intended, with the shape largely decided. Exploring means we think it matters and are still working out what it should be — read it as a direction, not a date.

None of this is a contractual commitment, and the dates driven by regulators are theirs to move rather than ours: the EU AI Act high-risk deadline has already shifted once, from August 2026 to December 2027. If a line item is load-bearing for your own plan, tell us — what customers are being asked for is what moves an item up this list.

Time to audit-ready Frameworks Integrations Architecture governance Trust & verification
Q4 2026 Shortening the distance between signing up and being audit-ready.
Time to audit-ready Near term

One-click SOC 2 Type 1 readiness

Pick SOC 2, answer a short scoping interview, and the platform lays down the control set, the policy set drafted against your actual stack, the evidence requests, and the owner for each. The output is a readiness pack an auditor can open on day one.

Why now. A Type 1 is a point-in-time opinion, so the bottleneck is assembly rather than elapsed time. That is the part software can genuinely collapse.

Frameworks Near term

EU AI Act Article 50 transparency pack

Disclosure obligations for AI interaction and AI-generated content, with the content-marking evidence the December 2026 watermarking date requires.

Why now. Article 50 kept its 2 August 2026 date through the Omnibus delay, and marking obligations follow in December — this is the nearest live AI deadline, not the 2027 one.

Integrations Near term

Vercel integration

Read-only checks across projects, environment variables, deployment protection, domain TLS and team access — mapped to SOC 2 CC6 and CC8.

Why now. Vercel is where a large share of our SaaS customers actually ship, and it holds its own SOC 2 Type 2 — so the inherited controls are documentable rather than assumed.

Trust & verification Planned

Trust page verification badges

Framework claims on a published trust page carry the assessment they came from, with the date and the assessing party, instead of an unqualified logo.

Why now. Self-asserted badges are losing credibility with enterprise buyers as trust pages become commodity. Provenance is the differentiator.

H1 2027 AI governance becomes a first-class framework, not an add-on.
Frameworks Near term

ISO/IEC 42001 as a full catalogue

The AI management system standard with its Annex A controls, mapped against your existing ISO 27001 control set so the overlap is reused rather than re-evidenced.

Why now. 42001 is appearing in roughly 40% of EU enterprise AI RFPs. With auditor capacity backlogged, readiness work has to start well before a certification slot exists.

Frameworks Planned

NIST SP 800-53 AI control overlays

Overlay support layered onto our existing NIST AI RMF catalogue, plus the Generative AI Profile (AI 600-1) actions for teams running LLM features.

Why now. NIST has the overlays and RMF 1.1 addenda tracking through 2026. Federal and federal-adjacent buyers will ask for them first.

Time to audit-ready Near term

Ready-to-go SOC 2 and ISO infrastructure

Reference architectures — logging, key management, backup, access, change control — published as Terraform for AWS and Azure, with each resource carrying the control it satisfies. Deploy it and the evidence collector already knows what to look for.

Why now. Most first-time failures are not policy failures. They are an environment that was never built to produce the evidence the framework asks for.

Integrations Planned

vSphere and private data-centre collection

Agentless collection against vCenter for host hardening, patch level, role assignments, network segmentation and backup jobs — with a collector that runs inside your perimeter and ships findings, not data.

Why now. Sovereign cloud IaaS is forecast at $80B for 2026, up 35.6%. A growing share of regulated estate is deliberately not on a hyperscaler.

H2 2027 From controls to architecture — governing how systems are allowed to be built.
Architecture governance Planned

Enterprise architecture governance

A live model of systems, data flows and trust boundaries, with architecture standards expressed as checks. Propose a change and the platform tells you which controls it touches, which classification of data it moves, and whose approval it needs.

Why now. Compliance platforms mostly assess what already exists. The expensive failures are architectural and are decided months before an auditor sees them.

Architecture governance Exploring

Architecture review gates in CI

Pull requests that cross a trust boundary, add a sub-processor or move classified data raise a review against the standard, with the decision recorded as evidence.

Why now. The BOLA incident at a major AI app builder in 2026 was an authorisation-design failure, not a missing policy. Governance has to reach the change, not just the report.

Integrations Planned

Lovable and AI-built application governance

Posture checks for applications generated by AI builders: authorisation model, exposed data objects, secret handling and publication state — the failure modes vibe-coded apps actually have.

Why now. These tools put production apps in the hands of people who have never run a security review. The 2026 incidents made that a board-level question.

Trust & verification Planned

Automated trust-directory submission

Publish once and syndicate: your trust page, framework status and sub-processor list pushed to the directories buyers search, and kept current as the programme changes. First integration is the SocBridge trust directory, with an open submission format for others.

Why now. Trust pages are becoming table stakes; being findable is the part still done by hand.

2028 Breadth of estate, and the assurance layer on top.
Integrations Exploring

Hosting and VPS estate: Namecheap, Hostinger and cPanel

Evidence from the infrastructure smaller regulated businesses genuinely run on — VPS instances, cPanel accounts, DNS and mail records, TLS expiry, backup schedules and account-level access.

Why now. Clinics, brokers and agencies carry regulated data on exactly this footing, and no compliance platform reaches it. Depth varies by provider: some expose a full management API, others little more than DNS.

Frameworks Planned

ITSG-33 refresh and CCCS Medium alignment

Tracking the Canadian Centre for Cyber Security as the Protected B / Medium / Medium profile settles under the CCCS Medium name, including the cloud profile in ITSP.50.103 Annex B.

Why now. The naming has already shifted while the control requirements held. Departments will ask for the current vocabulary in submissions regardless.

Frameworks Exploring

ISO 27001 next-edition readiness

No new edition is published; the current standard is ISO/IEC 27001:2022 with Amendment 1:2024 for climate. We track the committee and will map any successor as a delta rather than a rebuild.

Why now. The 2013-to-2022 transition cost customers real money. The next one should be a diff, not a migration project.

Trust & verification Exploring

Assessor and auditor partnerships

A partner network of assessors who can verify a claim on a trust page directly, so a buyer sees who signed off and when — not merely that a badge was switched on.

Why now. Once every platform can publish a trust page, verification is the only remaining signal.

Where Evidence Will Come From

Today we read AWS, Azure, Google Cloud, Microsoft 365, GitHub and Azure DevOps. These are next, in the order we expect to reach them.

TargetWhat we would collectHorizonConfidence
Vercel Project and team access, environment variable handling, deployment protection, domain TLS, audit log. Q4 2026Near term
VMware vSphere Host hardening and patch level, vCenter roles and permissions, network segmentation, snapshot and backup jobs. Collector runs inside your perimeter. H1 2027Planned
Private data centres Physical access records, environmental controls, media handling and destruction certificates — the §164.310 and CC6.4 evidence a cloud API cannot give you. H1 2027Planned
Lovable Authorisation model and object-level access, exposed data objects, secret handling, publication state of generated apps. H2 2027Planned
Hostinger VPS VPS inventory and state, firewall and access configuration, DNS and mail records, TLS expiry, backup schedule. 2028Exploring
Namecheap & cPanel Domain and DNS state, cPanel account inventory, TLS certificate expiry, email routing, backup configuration. 2028Exploring

Every integration is read-only, with no agent to install on a workload. Ask about a target that is not listed →

Building for a deadline we have not listed?

Roadmaps move when customers push them. Tell us what you are being asked for.

Book a Demo Watch the product videos