CIRCIA cyber incident reporting (final rule)
US (federal) · binds covered entities in the 16 critical-infrastructure sectors (scope set by the final rule)
you operate in a critical-infrastructure sector in the US
- 2026-09
final rule targeted for September 2026 (CISA / unified agenda); NOT published as of 8 Sep 2026 pending
- tbd
compliance date set by the final rule (statutory clocks 72h incident / 24h ransom payment) to verify
CISA CIRCIA FAQs, https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs; Hunton (secondary), https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026
Watch for: Federal Register publication of the final rule ·
verified 2026-09-08 secondary source
CMMC 2.0 phased rollout
US (DoD / Department of War contracts) · binds defense contractors and subcontractors handling FCI/CUI
you hold or bid on DoD contracts, or sit in that supply chain
- 10 Nov 2025
Phase 1 in force — self-assessments (L1, L2) and SPRS scores; DFARS 252.204-7012 / NIST SP 800-171 r2 continue
- 13 Jul 2026
Phase 2 (third-party C3PAO L2 certification, was 10 Nov 2026) SUSPENDED pending a 60-day CMMC Reform Task Force review
- 2026-09
task-force report due to DoW CIO (~mid-September); no decision date stated pending
- 10 Nov 2026
original Phase 2 date — now uncertain to verify
Department of War release 13 Jul 2026, https://www.war.gov/News/Releases/Release/Article/4542329/; 32 CFR Part 170
Watch for: task-force outcome; DFARS class deviation ·
verified 2026-09-08 primary source
FTC Safeguards Rule (GLBA) — security programme and 30-day breach notice
US (federal, non-bank financial institutions) · binds financial institutions under FTC jurisdiction — mortgage brokers, auto dealers with financing, tax preparers, collection agencies, non-bank lenders and others
you extend credit or handle customer financial data and are not a bank
- 9 Jun 2023
amended rule's programme requirements in force (qualified individual, risk assessment, MFA, encryption, monitoring)
- 13 May 2024
notification to the FTC within 30 days of discovering a breach affecting 500+ consumers
16 CFR Part 314; FTC blog 13 May 2024, https://www.ftc.gov/business-guidance/blog/2024/05/safeguards-rule-notification-requirement-now-effect
Watch for: FTC enforcement orders naming a Safeguards count ·
verified 2026-09-08 primary source
HIPAA Security Rule modernisation (NPRM Jan 2025)
US (federal) · binds covered entities and business associates
you handle US health data as a covered entity or business associate
- 2027-07
final rule projected July 2027 (Reginfo / unified agenda)
- tbd
compliance date (set in final rule) to verify
Reginfo.gov unified agenda; Holland & Knight 6 Jul 2026, https://www.hklaw.com/en/insights/publications/2026/07/hipaa-security-rule-amendments-now-projected-for-july-2027
Watch for: OMB/OIRA review listing ·
verified 2026-09-08 secondary source
SEC cybersecurity disclosure (Item 1.05 8-K; Reg S-K Item 106)
US (federal) · binds SEC registrants
you are listed in the US
- standing
Item 1.05 within four business days of a materiality determination; Item 106 in each 10-K
- 3 Sep 2026
no amendment or rescission proposed; cyber listed only as a possible "disclosure rationalisation" topic in the fall agenda preview
17 CFR 229.106; Form 8-K Item 1.05; NatLawReview fall rulemaking preview 3 Sep 2026
Watch for: SEC proposing release touching Item 1.05 ·
verified 2026-09-08 secondary source