@windsheep Agreed, unrealistic for smaller orgs to get some of this lined up (properly). It makes sense to include newish developments but maybe it is time to create “protection profiles” or implementation levels to account for that.