Compliance Pulse — 2026-10-01

Compliance Pulse — 2026-10-01

Craig Wood
Published on: 01/10/2026

FAR 2021-017 and CIRCIA both missed September. CISA added a triage step; the Coast Guard paused plan filings and kept July 16, 2027. What still binds you.

CMMC compliance updatesNIST 800-171 compliancedefense contractor cybersecurity complianceCUI regulatory changesfederal contractor cybersecurityDFARS rulemaking updatesGRC practitioner resourcesDIB compliance news
Two Regulators Deferred, One Did Not — And the Security Obligation Never Moved At All

Two Regulators Deferred, One Did Not — And the Security Obligation Never Moved At All

Craig Wood
Published on: 10/09/2026

DoD stripped CMMC third-party assessments from contracts on Sept 3. DoJ took $2M from Honeywell over 800-171 on Sept 1. What still binds you.

CMMC compliance updatesNIST 800-171 compliancedefense contractor cybersecurity complianceCUI regulatory changesfederal contractor cybersecurityDFARS rulemaking updatesGRC practitioner resourcesDIB compliance news
CMMC Reform RFI Closes August 14 — The Pause Is a Comment Window, Not a Break

CMMC Reform RFI Closes August 14 — The Pause Is a Comment Window, Not a Break

Craig Wood
Published on: 30/07/2026

CMMC's reform RFI closes Aug 14, CIRCIA slips to September, HIPAA to 2027 — what still binds for DIB, maritime, and healthcare security leaders.

CMMC reform RFICMMC Phase 2 suspensionCIRCIA final ruleHIPAA Security Rulemaritime cybersecurity MTSANIST 800-171 complianceDFARS 252.204-7012cybersecurity compliance
Compliance Pulse — 2026-04-02

Compliance Pulse — 2026-04-02

Craig Wood
Published on: 02/04/2026

CMMC Phase 1 is live and DOJ is treating SPRS affirmations as federal representations. What defense contractors and subcontractors need to know before Phase 2 hits.

CMMC compliance updatesNIST 800-171 compliancedefense contractor cybersecurity complianceCUI regulatory changesFalse Claims Act cybersecurity enforcementSPRS score complianceDFARS 252.204-7012 compliancemaritime cybersecurity compliance