GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

Craig Wood
Published on: 08/10/2026

GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

cybersecurity complianceGAO cybersecurity regulationsregulatory harmonizationCIRCIA incident reportingSEC cybersecurity disclosureCISA BOD 26-04forensic triage before patchingCMMC compliance
The Rule Is the Artifact. The Control Is the Obligation.

The Rule Is the Artifact. The Control Is the Obligation.

Craig Wood
Published on: 17/09/2026

FAA issued new aircraft cyber special conditions in June; the rule replacing them is still proposed. CIRCIA has not published. What binds you regardless.

aviation cybersecurity complianceFAA special conditions14 CFR 25.1319CIRCIA final ruleTSA surface cybersecurityNYDFS Part 500cybersecurity compliancevCISO
AI Kill-Chain Benchmarks Land as the EU Defers Its High-Risk Deadline — Your Current Obligations Already Cover the Gap

AI Kill-Chain Benchmarks Land as the EU Defers Its High-Risk Deadline — Your Current Obligations Already Cover the Gap

Craig Wood
Published on: 03/09/2026

A benchmark put autonomous intrusion on the record the same month the EU deferred its high-risk AI deadline to 2027. What still binds contractors now.

AI governance complianceEU AI Act high-risk deadlineNIST AI RMFNIST SP 800-53 AI overlaysautonomous AI cyber attackDFARS 252.204-7012board cybersecurity oversightcybersecurity compliance
CMMC Reform RFI Closes August 14 — The Pause Is a Comment Window, Not a Break

CMMC Reform RFI Closes August 14 — The Pause Is a Comment Window, Not a Break

Craig Wood
Published on: 30/07/2026

CMMC's reform RFI closes Aug 14, CIRCIA slips to September, HIPAA to 2027 — what still binds for DIB, maritime, and healthcare security leaders.

CMMC reform RFICMMC Phase 2 suspensionCIRCIA final ruleHIPAA Security Rulemaritime cybersecurity MTSANIST 800-171 complianceDFARS 252.204-7012cybersecurity compliance