Prosecution Insights
Last updated: October 04, 2026
Application No. 19/543,152

SYSTEMS AND METHODS FOR ENHANCING CYBERSECURITY

Non-Final OA §102§103
Filed
Feb 18, 2026
Priority
Mar 14, 2025 — provisional 63/772,261
Examiner
NGUY, CHI D
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Relevant Compliance Inc.
OA Round
1 (Non-Final)
75%
Grant Probability
Favorable
1-2
OA Rounds
2y 10m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
385 granted / 511 resolved
+17.3% vs TC avg
Strong +16% interview lift
Without
With
+15.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
16 currently pending
Career history
539
Total Applications
across all art units

Statute-Specific Performance

§101
9.2%
-30.8% vs TC avg
§103
52.8%
+12.8% vs TC avg
§102
17.6%
-22.4% vs TC avg
§112
11.6%
-28.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 511 resolved cases

Office Action

§102 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The Application number 19/543,152 filed on 7/28/2026 has been considered. Claims 1-13 are pending. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1-4, 6-9 and 11-13 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Szimmetat (US 2026/0017379). Regarding claim 1, Szimmetat discloses a computer system configured to enhance cybersecurity of an information system, the computer system comprising: a network interface (FIG. 1-3); at least one processing device configured to (FIG. 1-3): receive a first document comprising cybersecurity policies related to at least the information system (¶ [0008]-[0015], [0024]; i.e. retrieving/receiving documents encompassing policy manuals); receive a second document comprising cybersecurity procedures related to at least the information system (¶ [0008]-[0015], [0024], [0032]; i.e. retrieving/receiving documents encompassing incident reports, compliance reports, previous Q & A responses to customers, design document, planning/engineering artifacts, etc.); receive a third document comprising a cybersecurity standard comprising at least a first plurality of cybersecurity categories (¶ [0008]-[0015], [0024]; i.e. retrieving/receiving documents encompassing regulatory framework, compliance documentation, security advisories, etc.); identify, for the first plurality of cybersecurity categories, gaps between: the cybersecurity policies and/or procedures and the cybersecurity standard (¶ [0008]-[0015], [0024], [0029]; i.e. performing automated gap analysis by comparing regulatory requirements with organization’s policies and security controls); determine based at least on one of the identified gaps, if cybersecurity remediation techniques are to be recommended (¶ [0008]-[0015], [0029], [0051]; i.e. identifying discrepancies and suggesting improvements/remediations); and at least partly in response to determining that cybersecurity remediation techniques are to be recommended, output cybersecurity remediation techniques and cause, at least in part, the cybersecurity remediation techniques to be implemented (¶ [0008]-[0015], [0029], [0051]; i.e. creating a ticket for the IT security team to apply the recommended patches or remediations). Regarding claim 2, Szimmetat discloses the computer system as defined in Claim 1, wherein the computer system is configured to utilize a generative model augmented with Retrieval-Augmented Generation to identify, for the first plurality of cybersecurity categories, gaps between: the cybersecurity policies and/or procedures, and the cybersecurity standard (¶ [0046]-[0047]). Regarding claim 3, Szimmetat discloses the computer system as defined in Claim 1, wherein the computer system is configured to utilize a generative model augmented with Retrieval-Augmented Generation to generate a set of cybersecurity remediation techniques to remediate identified gaps (¶ [0008]-[0015], [0046]-[0047]). Regarding claim 4, Szimmetat discloses the computer system as defined in Claim 1, wherein the cybersecurity remediation techniques comprise use of: complex passwords, multi-factor authentication, software updates, hardware updates, data backup, data encryption, a network firewall, a VPN, anti-virus and anti-malware software, endpoint protection, intrusion detection/prevention system, and/or a cyberattack recovery procedure (¶ [0034], [0037]). Regarding claim 6, Szimmetat discloses the computer system as defined in Claim 1, wherein the computer system is further configured to: generate a cybersecurity assessment questionnaire; receive responses to the cybersecurity assessment questionnaire (¶ [0010]-[0015]); and use the responses to the cybersecurity assessment questionnaire to identify, for the first plurality of cybersecurity categories, gaps between: the cybersecurity policies and/or procedures, and the cybersecurity standard (¶ [0010]-[0015]). Regarding claim 7, Szimmetat discloses the computer system as defined in Claim 1, wherein the computer system is configured to automatically detect a change in the third document comprising a cybersecurity standard, and at least partly in response to detecting the change in the third document comprising the cybersecurity standard, identify, for the first plurality of cybersecurity categories, gaps between: the cybersecurity policies and/or procedures and the cybersecurity standard included in the changed third document (¶ [0010]-[0015], [0024], [0029]); determine, based at least on one of the identified gaps between the cybersecurity policies and/or procedures and the cybersecurity standard included in the changed third document, if updated cybersecurity remediation techniques are to be recommended (¶ [0010]-[0015], [0024], [0029]); and at least partly in response to determining that updated cybersecurity remediation techniques are to be recommended, output updated cybersecurity remediation techniques and cause, at least in part, the updated cybersecurity remediation techniques to be implemented (¶ [0010]-[0015], [0024], [0029]). Regarding claim 8, Szimmetat discloses a computer-implemented method, the method comprising: receiving over a network, at a computer system comprising a processing device comprising a plurality of cores within a first package, a first document comprising a first set of policies (¶ [0008]-[0015], [0024]; i.e. retrieving/receiving documents encompassing policy manuals); receiving over the network, at the computer system, a second document comprising a first set of procedures (¶ [0008]-[0015], [0024], [0032]; i.e. retrieving/receiving documents encompassing incident reports, compliance reports, previous Q & A responses to customers, design document, planning/engineering artifacts, etc.); receiving over the network, at the computer system, a third document comprising a standard comprising at least a first plurality of categories (¶ [0008]-[0015], [0024]; i.e. retrieving/receiving documents encompassing regulatory framework, compliance documentation, security advisories, etc.); identifying using a generative model augmented with Retrieval-Augmented Generation executed using one or more processing devices, for the first plurality of categories, gaps between: the first set of policies and/or first set of procedures and the standard (¶ [0008]-[0015], [0024], [0029], [0046]-0047]; i.e. retrieving and augmenting the documents, and performing automated gap analysis by comparing regulatory requirements with organization’s policies and security controls); determining based on at least one of the identified gaps, if remediation techniques are to be recommended (¶ [0008]-[0015], [0029], [0051]; i.e. identifying discrepancies and suggesting improvements/remediations); and at least partly in response to determining remediation techniques are to be recommended, outputting remediation techniques and enabling the remediation techniques to be implemented (¶ [0008]-[0015], [0029], [0051]; i.e. creating a ticket for the IT security team to apply the recommended patches or remediations). Regarding claim 9, Szimmetat discloses the computer-implemented method as defined in Claim 8, wherein the first set of policies comprises cybersecurity policies, and the first set of procedures comprises cybersecurity procedures and the remediation techniques comprise use of: complex passwords, multi-factor authentication, software updates, hardware updates, data backup, data encryption, a network firewall, a VPN, anti-virus and anti-malware software, endpoint protection, intrusion detection/prevention system, and/or a cyberattack recovery procedure (¶ [0034], [0037]). Regarding claim 11, Szimmetat discloses the computer-implemented method as defined in Claim 8, the method further comprising: generating an assessment questionnaire; receiving responses to the assessment questionnaire (¶ [0010]-[0015]); and using the responses to the assessment questionnaire to identify, for the first plurality of categories gaps between: the first set of policies and/or procedures, and the standard (¶ [0010]-[0015]). Regarding claim 12, Szimmetat discloses the computer-implemented method as defined in Claim 8, the method further comprising: automatically detecting a change in the standard comprising at least the first plurality of categories, and at least partly in response to detecting the change in the standard, identify, for the first plurality of categories gaps between: the policies and/or procedures, and the changed standard (¶ [0010]-[0015], [0024], [0029]); determine, based at least on one of the identified gaps between the policies and/or procedures and the changed standard, if updated remediation techniques are to be recommended (¶ [0010]-[0015], [0024], [0029]); and at least partly in response to determining that updated remediation techniques are to be recommended, output updated remediation techniques and cause, at least in part, the updated remediation techniques to be implemented (¶ [0010]-[0015], [0024], [0029]). Regarding claim 13, Szimmetat discloses the computer-implemented method as defined in Claim 8, the method further comprising automatically generating a plan of action comprising the remediation techniques, milestones and associated timing, and resources needed (¶ [0029]-[0030]). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 5 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Szimmetat (US 2026/0017379) in view of Gupta et al. (US 2026/0170239 hereinafter Gupta). Regarding claim 5, Szimmetat discloses the computer system as defined in Claim 1, wherein identifying, for the first plurality of cybersecurity categories, gaps between: the cybersecurity policies and/or procedures, and the cybersecurity standard (¶ [0008]-[0015], [0024], [0029]). Szimmetat does not explicitly disclose further comprises generating compliance scores for respective categories corresponding to the cybersecurity categories gaps and/or an overall weight-based average compliance score. However, Gupta discloses generating compliance scores for respective categories corresponding to the cybersecurity categories gaps and/or an overall weight-based average compliance score (FIG. 3-8, ¶ [0037]-[0038]). Therefore, it would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to combine Szimmetat and Gupta in order to ensure technical documents are in compliance with the guidelines and criteria (Gupta, ¶ [0001]-[0002], [0022]). Regarding claim 10, see claim 5 above for the same reasons of rejections. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHI D NGUY whose telephone number is (571)270-7311. The examiner can normally be reached Monday-Friday 9-5 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571)270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /C.D.N/Examiner, Art Unit 2435 /AMIR MEHRMANESH/Supervisory Patent Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Feb 18, 2026
Application Filed
Aug 16, 2026
Non-Final Rejection (signed) — §102, §103
Sep 18, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12720311
XAPP INSTANCE REGISTRATION IN CLOUD-NATIVE NETWORKS
2y 7m to grant Granted Aug 25, 2026
Patent 12683983
METHOD AND SYSTEM FOR DETECTING RESTRICTED CONTENT ASSOCIATED WITH RETRIEVED CONTENT
3y 4m to grant Granted Jul 14, 2026
Patent 12664297
Attribute-Based Permissions Groups
2y 11m to grant Granted Jun 23, 2026
Patent 12657284
CODE COVERAGE BASED RISK MITIGATION FOR CONTAINERS
3y 6m to grant Granted Jun 16, 2026
Patent 12657265
PHYSICAL UNCLONABLE FUNCTION READOUT APPARATUS
3y 1m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
75%
Grant Probability
91%
With Interview (+15.8%)
3y 5m (~2y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 511 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month