
What the SR 2026 Delay Actually Means for Your ISO 20022 Roadmap
Swift’s SR 2026 delay changes the ISO 20022 roadmap. Learn what banks need to do now on structured addresses, compliance, data quality and migration.
Most organizations can tell you what CVEs they found last quarter. Few can tell you which packages will become a problem next month or which AI skills are running in production without a certified identity. This piece is about closing that gap.
YoY increase in software supply chain attacksSonatype 2024
of critical security debt originates from third-party codeVeracode 2025
ungoverned repositories as a baseline in a typical enterprise estate
CISA, the SEC, and the EU Cyber Resilience Act are now mandating that enterprises address software supply chain risk not as a project, but as an ongoing operational discipline. The regulatory pressure is real, but the technical problem predates it by years.
The pattern is consistent across enterprises at scale: hundreds of ungoverned repositories, developers pulling packages directly from public registries with no policy enforcement, no Software Bill of Materials, no audit trail, and no way to determine whether what is running in production is what was approved. Containers carrying hundreds of OS-layer CVEs are baked into base images before a single line of application code is written.
Now compound this with the emerging agentic attack surface. AI agents, skills, MCP servers, and prompt templates are being packaged and deployed into production pipelines with the same absence of governance that plagued open-source packages a decade ago. The attack surface has expanded; the governance frameworks largely have not.
A typical Xray scan of an enterprise estate surfaces thousands of CVEs. Without EPSS scoring and blast radius analysis, security teams have no principled basis for prioritization so they either attempt to address everything (impossible) or nothing (the actual outcome). The result is a growing backlog that erodes trust in the tooling itself.
Most organizations sit in reactive mode. The goal of a governed supply chain program is to move through proactive and reach predictive where risk is identified and addressed before CVEs are published, not weeks after.
Stage 01
CVE found, ticket opened, maybe fixed weeks later. No SBOM. No audit trail. No visibility into what is in the estate or whether it is safe. Governance is a point-in-time audit, not a continuous signal.
Stage 02
A governed tollgate controls everything that enters the estate. Network enforcement blocks direct registry access. Automated curation evaluates every package before admission. A live SBOM covers the full artifact inventory.
Stage 03
OpenSSF scorecard flags maintainer health before CVEs publish. EPSS + blast radius collapses thousands of findings to the dozen that matter this sprint. VEX attestations suppress false positives at the source. Policy enforced in the IDE, pipeline, and at runtime uniformly.
The architecture begins with a hard constraint: no package enters the estate without passing through a single governed path. Network enforcement Zscaler and proxy configuration eliminates direct registry access at the network layer. Developers and pipelines cannot bypass it. This is not a policy; it is a topology.
Before any package is admitted, JFrog Curation evaluates it against CVE thresholds, malicious package blocklists, and license policy. Low-risk packages auto-approve. Medium-risk packages are escalated to Security or AppSec for review. High-risk packages are hard-blocked. Every decision is logged with a timestamp and decision reason creating the audit trail that compliance requires and that reactive programs lack entirely.
Xray runs asynchronously on everything already inside the estate. As new CVEs are published, Xray rescans, runs impact analysis against affected builds, generates live SBOMs in CycloneDX format, and produces delta reports comparing the live inventory against the approved baseline. The combination of Curation and Xray is deliberate: Curation without Xray misses post-admission vulnerabilities; Xray without Curation lets bad artifacts in before they can be caught.
Chainguard hardened base images ship with near-zero OS-layer CVEs and include VEX (Vulnerability Exploitability eXchange) attestations that declare which CVEs in an image are non-exploitable in that specific context. When Wiz’s runtime analysis confirms what is actually reachable in a running workload, the combination suppresses false positives before they reach the security team. This is not noise reduction through threshold tuning it is accurate signal at the source.
A governed supply chain does not produce fewer findings. It produces accurate findingsand accurate findings are ones teams can act on.
CVSS severity scores are a lagging indicator. They tell you how bad a vulnerability is once it exists. The predictive layer adds three signals that tell you what will become a problem before it does.
A package with zero critical CVEs today is not necessarily safe. If its OpenSSF scorecard is low no signed releases, no branch protection, inactive maintainers, no automated dependency update tooling, weak code review practices it is statistically more likely to carry an exploitable vulnerability within the next 12 months. OpenSSF Scorecard runs 10+ software supply chain hygiene checks and produces a score between 0 and 10. In this architecture, the scorecard is fetched automatically before a package hits the policy engine, so admission decisions are made on enriched risk profiles, not just package metadata. A minimum score threshold is enforced packages below it are flagged for human review regardless of their current CVE status.
EPSS (Exploit Prediction Scoring System) estimates the probability that a given CVE will be exploited in the wild within the next 30 days. Applied alongside CVSS, it answers a different question: not how severe is this, but how urgent. A CVSS 7.5 with an EPSS of 0.82 demands immediate attention. A CVSS 9.1 with an EPSS of 0.003 can be scheduled. This is the basis for intelligent routing: high EPSS findings go directly to a ServiceNow change ticket with an SLA; low EPSS findings can be monitored with a standard cadence.
A CVE in isolation is an incomplete picture. Blast radius analysis maps every build, pipeline, and downstream consumer that would be affected if that vulnerability were exploited. Combined with EPSS, it enables a risk prioritization that security teams can actually execute: address the high-EPSS, high-blast-radius findings first, schedule the rest. This is how an organization moves from a backlog of thousands to a sprint list of twelve.
Every artifact package, container image, AI skill package passes through the same five-gate sequence before promotion to production.
The CI/CD pipeline becomes a hard governance gate. Promotion cannot proceed if a package fails policy validation. Developers receive a clear signal at promotion time not three weeks later when a CVE is disclosed in a production incident.
The same policy engine that enforces gates at the pipeline level surfaces findings in the developer’s IDE before a commit is made. A dependency flagged in the IDE operates under the same rules that govern production it is not a different finding, it is the same finding surfaced earlier. This is what shift left means in practice: not a different set of rules for developers, but the same rules applied at the earliest possible moment in the development lifecycle.
Traditional supply chain governance addresses software packages and container images. The same attack surface now extends to AI artifacts models, skills, MCP server implementations, and prompt templates which are being packaged and deployed into production pipelines with the same absence of governance that characterized open-source dependency management a decade ago.
AIBOM extends the SBOM concept to AI artifacts. For a model: training data sources, architecture, fine-tuning dataset provenance, evaluation benchmark results. For a skill: what tools it can call, what data it can access, what model it invokes, who authored it.
Generated at intake, versioned, and cryptographically signed. This satisfies emerging requirements from NIST AI RMF, EU AI Act Article 13, and anticipated SEC guidance on AI system disclosure.
Traditional CVSS scores software vulnerabilities. AIVSS extends the same scoring discipline to AI-specific risk dimensions:
JFrog’s intake pipeline Curation, Xray, and the policy gate governs AI skill packages before they are registered in the agent catalog, using the same mechanics it applies to software packages. A Python package implementing callable agent behavior, an MCP server implementation, or a prompt template is evaluated at intake, versioned, and cryptographically signed. A skill that has not cleared the intake gate cannot be registered in the catalog. The CI/CD promotion gate is the trust boundary not a separate approval process, not an informal review, but the same governed path that every other artifact in the estate travels.
JFrog Artifactory + Curation + Xray deployed with network enforcement. Direct registry access eliminated. Every package routes through a single governed path.
CycloneDX SBOM covering the full artifact inventory queryable, exportable, feeding downstream tooling and compliance workflows.
AI-assisted classification of all repositories by type, ownership, licensing, and dependency profile. Draft migration plans generated; humans certify and close each one.
OpenSSF scorecard enforcement, EPSS-weighted routing, blast radius analysis, and VEX + Wiz false positive suppression configured and operational at handoff.
Continuous compliance visibility not a point-in-time audit report. Delta reports comparing live inventory against the approved baseline, updated as CVEs are published.
Blueprints that allow new business units to onboard into the governance framework without re-engaging the implementation team. The program scales with the organization.
The SBOM requirement addresses NTIA and CISA mandates directly. The AI artifact governance layer AIBOM, AIVSS, cryptographic signing at intake anticipates NIST AI RMF implementation guidance and EU AI Act Article 13 transparency requirements. The audit trail produced by the five-gate pipeline is the form of evidence SEC cyber disclosure rules require: timestamped, attributable, and queryable on demand.
These requirements are not static. The accelerator is designed to evolve with the regulatory landscape rather than require re-implementation as guidance matures.
A 90-day engagement delivers a governed estate, a live SBOM, and a predictive risk layer — operational at handoff, self-service from day 91.

Swift’s SR 2026 delay changes the ISO 20022 roadmap. Learn what banks need to do now on structured addresses, compliance, data quality and migration.

Code generation got fast. Getting an autonomous workflow into a bank’s production control environment did not. In Banking & Financial Services (BFS), the blocker is rarely the model; it’s trust. A risk officer will not sign off on a system that cannot say why it flagged something, that does its arithmetic inside a language model, or that leaves no audit trail an examiner can open. That is exactly the gap most agentic pilots die in.
Over the last two quarters, we built a portfolio of ten BFS agentic offerings on Alti AIOS™, Altimetrik’s AI Operating System, and deployed them on two stacks: Google Cloud with Gemini and AWS with OpenAI. This piece is the architecture and design principle behind them.

Here is something most life sciences organizations already know but rarely say out loud: Snowflake did its job. The data lake is full. Batch records, deviation logs, CAPA histories, COA repositories, clinical trial evidence, it is all there, unified, queryable, and beautifully governed. And yet the quality director is still chasing approvals through email threads. The compliance team is still manually cross-referencing batch records against specifications before a release decision. The CAPA cycle is still measured in weeks, not hours.
Data centralization was never the finish line. It was the foundation. The question now is whether that foundation does work or just sits there.
USA (Southfield) - HQ
2000 Town Center, Suite 170
Southfield, MI 48075
+1 248-281-2500