Regional Field CTO at DigiCert

The operating side
of digital trust.

I write about the decisions behind secure devices, trusted software, and AI systems—and the evidence teams need to get them right.

Latest writing

Questions worth taking
back to your team.

Browse all 36 essays

Four connected subjects

Make trust work
in your environment.

Explore the guide library

Practical guides, field notes, and questions for your team. A personal perspective on the decisions that connect these subjects.

The dates do not move

The Forcing Function Calendar

Open the full calendar

The regulatory deadlines and standards transitions reshaping enterprise digital trust between 2026 and 2030. Know what is adopted, who it affects, and what to ask your team.

  1. EU regulation

    Cyber Resilience Act reporting begins

    Manufacturers must report actively exploited vulnerabilities and severe security incidents. Early warning is due within 24 hours of awareness; the next notification is due within 72 hours. Final reports follow separate clocks.

  2. EU regulation

    Existing AI systems: content-marking transition ends

    Certain providers of synthetic-content AI systems placed on the market before 2 August 2026 must meet Article 50(2) marking requirements by this date.

  3. National security policy

    CNSA 2.0 enters new NSS acquisitions

    New acquisitions for U.S. National Security Systems must be CNSA 2.0 compliant unless an exception applies. Deployment requirements also depend on the relevant validation profile.

Reviewed September 2026 · Quarterly review cadence · Primary sources linked in the full calendar.

Guides & resources

Take the question
into the field.

Practical reading from the archive, with questions and frameworks to use in your own environment.

About Tim

Technical depth.
A field perspective.

I’m Regional Field CTO at DigiCert. My work connects PKI, device identity, software assurance, and AI with the engineering and operating decisions organizations face.

This is my personal publication. Views are my own.

More about my work

Speaking & collaboration

Bring the conversation
to your team.

Keynotes, panels, and workshops on device trust, cryptographic change, software assurance, and the authority we give AI systems.

Past speaking includes Embedded World, CES, and RSA Conference.