GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

Craig Wood
Published on: 08/10/2026

GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

cybersecurity complianceGAO cybersecurity regulationsregulatory harmonizationCIRCIA incident reportingSEC cybersecurity disclosureCISA BOD 26-04forensic triage before patchingCMMC compliance
Compliance Pulse — 2026-10-01

Compliance Pulse — 2026-10-01

Craig Wood
Published on: 01/10/2026

FAR 2021-017 and CIRCIA both missed September. CISA added a triage step; the Coast Guard paused plan filings and kept July 16, 2027. What still binds you.

CMMC compliance updatesNIST 800-171 compliancedefense contractor cybersecurity complianceCUI regulatory changesfederal contractor cybersecurityDFARS rulemaking updatesGRC practitioner resourcesDIB compliance news
Two Federal Cyber Rules Missed Their Own September Target — Enforcement Never Paused

Two Federal Cyber Rules Missed Their Own September Target — Enforcement Never Paused

Craig Wood
Published on: 24/09/2026

In three weeks, DoW struck third-party assessment out of defense contracts, two federal cyber rules let their own September target pass, and OCR…

Compliance PulseCMMCHIPAACUIGRCCybersecurity ComplianceDIBMaritime Cyber
The Rule Is the Artifact. The Control Is the Obligation.

The Rule Is the Artifact. The Control Is the Obligation.

Craig Wood
Published on: 17/09/2026

FAA issued new aircraft cyber special conditions in June; the rule replacing them is still proposed. CIRCIA has not published. What binds you regardless.

aviation cybersecurity complianceFAA special conditions14 CFR 25.1319CIRCIA final ruleTSA surface cybersecurityNYDFS Part 500cybersecurity compliancevCISO