CISA BOD 26-04 Accelerates Federal Patching

Bright Defense graphic on CISA BOD 26-04 accelerating federal patching requirements.

CISA’s Binding Operational Directive 26-04 has reset federal vulnerability management around risk, exposure and exploitation instead of severity scores alone. Issued on June 10, 2026, the directive requires Federal Civilian Executive Branch agencies to prioritize security updates using asset exposure, Known Exploited Vulnerabilities status, exploit automation and post-exploitation technical impact, with the most urgent cases…

Read More

CISA Pledge Adds Vendor Review Signal

Bright Defense graphic on the CISA Secure by Design pledge becoming a vendor-review signal.

CISA’s Secure By Design Pledge has become a current vendor security review signal after the agency listed 367 organizations as signers, giving software buyers a public checkpoint for supplier due diligence. The pledge remains voluntary, but CISA’s progress-report process and 7 product-security goals now give procurement, security and risk teams a sharper way to question…

Read More

DORA Makes Resilience Testing A Finance Priority

Bright Defense graphic on DORA making resilience testing a priority for financial firms.

DORA has made resilience testing a central compliance priority for Europe’s financial sector, requiring banks, insurers, investment firms, payment providers and other covered entities to prove that critical ICT systems can withstand disruption. The rule moved from preparation to active supervision after January 17, 2025, with threat-led penetration testing and incident reporting now shaping board-level…

Read More

PCI DSS v4.0.1 Sets New Baseline For Cardholder Data Security

Bright Defense graphic on PCI DSS v4.0.1 setting a new baseline for cardholder-data security.

PCI DSS v4.0.1 has become the operative baseline for organizations that store, process, transmit, or affect the security of cardholder data, closing a long transition from PCI DSS v3.2.1 and placing more emphasis on continuous security, payment-page script control, stronger authentication, and evidence-based validation. The latest confirmed update came on June 3, 2026, when the…

Read More

HIPAA Rule Rewrite Puts Cyber Controls On The Clock

Bright Defense graphic warning that a HIPAA rule rewrite puts required cyber controls on a deadline.

HHS has proposed technical corrections and a complete republication of the HIPAA Security Rule text as part of its sweeping cybersecurity overhaul, but the changes have not become law. The correction and republication language comes from the proposed rule published on January 6, 2025, while the latest federal regulatory agenda now targets July 2027 for…

Read More

CMMC 2.0 Starts New Compliance Era For DoD Contractors

Bright Defense graphic announcing a new CMMC 2.0 compliance era for Department of Defense contractors.

The Pentagon’s CMMC 2.0 regime has moved from policy design to contract enforcement, forcing defense contractors and subcontractors to prove cybersecurity controls before they can win or keep many Defense Department awards. The latest confirmed development came on June 17, 2026, when Federal News Network reported that a Senate defense bill would create a grant…

Read More

CISA Advances CIRCIA Reporting Rule Toward 2026 Deadline

CISA compliance briefing graphic announcing the CIRCIA reporting rule's 2026 deadline

The U.S. Cybersecurity and Infrastructure Security Agency’s CIRCIA cyber incident reporting rule remains unfinished after more than 4 years of statutory, regulatory and industry debate, leaving critical infrastructure operators preparing for mandatory reports of covered cyber incidents within 72 hours and ransom payments within 24 hours once the final rule takes effect. CISA’s Spring 2025…

Read More

EU Cyber Resilience Act 2026 Reporting Deadline

EU Cyber Resilience Act compliance briefing graphic with the European Union flag

The EU Cyber Resilience Act will make software and connected-product manufacturers report actively exploited vulnerabilities and severe product security incidents from September 11, 2026, giving software makers a binding notification regime before the broader product security rules apply on December 11, 2027. The law, Regulation (EU) 2024/2847, applies to hardware and software products with digital…

Read More

CMMC 2.0 Becomes A Contract Test For Defense Contractors

Defense compliance briefing graphic announcing CMMC 2.0 as a contractor test

CMMC 2.0 is now a contract requirement for many U.S. defense contractors after the Department of Defense finalized the DFARS rule that lets contracting officers put Cybersecurity Maturity Model Certification requirements directly into solicitations, contracts, task orders and delivery orders starting November 10, 2025. The rule changes CMMC from a long-running compliance planning issue into…

Read More