news
CIRCIA Rulemaking Keeps Federal Cyber Reporting In Motion
The U.S. government’s long-delayed CIRCIA rulemaking is still moving toward a final federal cyber incident reporting regime for critical infrastructure operators, after CISA revived public town halls in June 2026 to refine a draft rule criticized as broad, costly, and hard to reconcile with existing sector rules. No final rule had been published as of…
Read MoreCISA BOD 26-04 Accelerates Federal Patching
CISA’s Binding Operational Directive 26-04 has reset federal vulnerability management around risk, exposure and exploitation instead of severity scores alone. Issued on June 10, 2026, the directive requires Federal Civilian Executive Branch agencies to prioritize security updates using asset exposure, Known Exploited Vulnerabilities status, exploit automation and post-exploitation technical impact, with the most urgent cases…
Read MoreCISA Pledge Adds Vendor Review Signal
CISA’s Secure By Design Pledge has become a current vendor security review signal after the agency listed 367 organizations as signers, giving software buyers a public checkpoint for supplier due diligence. The pledge remains voluntary, but CISA’s progress-report process and 7 product-security goals now give procurement, security and risk teams a sharper way to question…
Read MoreDORA Makes Resilience Testing A Finance Priority
DORA has made resilience testing a central compliance priority for Europe’s financial sector, requiring banks, insurers, investment firms, payment providers and other covered entities to prove that critical ICT systems can withstand disruption. The rule moved from preparation to active supervision after January 17, 2025, with threat-led penetration testing and incident reporting now shaping board-level…
Read MorePCI DSS v4.0.1 Sets New Baseline For Cardholder Data Security
PCI DSS v4.0.1 has become the operative baseline for organizations that store, process, transmit, or affect the security of cardholder data, closing a long transition from PCI DSS v3.2.1 and placing more emphasis on continuous security, payment-page script control, stronger authentication, and evidence-based validation. The latest confirmed update came on June 3, 2026, when the…
Read MoreHIPAA Rule Rewrite Puts Cyber Controls On The Clock
HHS has proposed technical corrections and a complete republication of the HIPAA Security Rule text as part of its sweeping cybersecurity overhaul, but the changes have not become law. The correction and republication language comes from the proposed rule published on January 6, 2025, while the latest federal regulatory agenda now targets July 2027 for…
Read MoreCMMC 2.0 Starts New Compliance Era For DoD Contractors
The Pentagon’s CMMC 2.0 regime has moved from policy design to contract enforcement, forcing defense contractors and subcontractors to prove cybersecurity controls before they can win or keep many Defense Department awards. The latest confirmed development came on June 17, 2026, when Federal News Network reported that a Senate defense bill would create a grant…
Read MoreCISA Advances CIRCIA Reporting Rule Toward 2026 Deadline
The U.S. Cybersecurity and Infrastructure Security Agency’s CIRCIA cyber incident reporting rule remains unfinished after more than 4 years of statutory, regulatory and industry debate, leaving critical infrastructure operators preparing for mandatory reports of covered cyber incidents within 72 hours and ransom payments within 24 hours once the final rule takes effect. CISA’s Spring 2025…
Read MoreEU Cyber Resilience Act 2026 Reporting Deadline
The EU Cyber Resilience Act will make software and connected-product manufacturers report actively exploited vulnerabilities and severe product security incidents from September 11, 2026, giving software makers a binding notification regime before the broader product security rules apply on December 11, 2027. The law, Regulation (EU) 2024/2847, applies to hardware and software products with digital…
Read MoreCMMC 2.0 Becomes A Contract Test For Defense Contractors
CMMC 2.0 is now a contract requirement for many U.S. defense contractors after the Department of Defense finalized the DFARS rule that lets contracting officers put Cybersecurity Maturity Model Certification requirements directly into solicitations, contracts, task orders and delivery orders starting November 10, 2025. The rule changes CMMC from a long-running compliance planning issue into…
Read More