TechNewsReel
Live

Researchers Launch Engineering-Led PRC Model to Fix Software Compliance

The Product Risk and Compliance framework embeds security controls directly into CI/CD pipelines, challenging traditional GRC practices.

TechNewsReel Newsroom · July 28, 2026

Application security researchers have unveiled the Product Risk and Compliance (PRC) model, an engineering-led framework designed to replace traditional Governance, Risk, and Compliance (GRC) practices that developers often view as bureaucratic obstacles.

The initiative aims to close the widening gap between corporate security policy and actual engineering practice in modern software development environments.

The Problem With Traditional GRC

Traditional GRC systems were designed for static corporate assets like office estates and end-user devices, not for software products that change continuously. In modern CI/CD environments where code deploys multiple times per day, compliance processes relying on manual records and spreadsheets create friction that often leads developers to bypass security controls entirely.

"Software products are the lifeblood of modern business, yet we continue to manage their security as if they were corporate laptops on an IT checklist," said Dr. Dag Flachet of Codific, who leads the initiative.

Three Pillars of PRC

The PRC model rests on three engineering-focused pillars. First, product risk assessment uses threat modelling to identify vulnerabilities specific to each application rather than applying blanket corporate controls. Second, supply chain risk management leverages Software Bills of Materials (SBOMs) to track open source and third-party dependencies. Third, process risk management employs maturity models instead of pass/fail audits.

The framework references OWASP SAMM and DSOMM as models for tracking security maturity over time, allowing teams to demonstrate continuous improvement rather than checkbox compliance.

Regulatory Pressure as Catalyst

The push toward engineering-led compliance has accelerated due to the EU Cyber Resilience Act, which mandates strict reporting deadlines for exploited vulnerabilities and requires detailed technical documentation of risk assessments. Under the PRC model, vendors can generate compliance evidence directly from their development workflows rather than maintaining separate documentation.

Research behind the framework included interviews with AppSec program managers, academic researchers, and members of the OWASP SAMM community to validate the approach across different organizational contexts.

Bridging Boardroom and Engineering Floor

Flachet describes the compliance gap as both behavioral and technical. "This is a behavioral failure as much as a technical one. PRC is a movement to bridge the gap between the boardroom and the engineering floor," he said.

By embedding controls into the software development lifecycle itself, the PRC model aims to make compliance a natural byproduct of engineering work rather than an administrative burden that competes with delivery deadlines.

The framework represents a broader shift in how organizations approach security governance, moving from periodic audits toward continuous evidence generation that aligns with how modern software teams actually work.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.