
Two Regulators Deferred, One Did Not — And the Security Obligation Never Moved At All
Compliance Pulse | Thursday, September 10, 2026
Three federal and international regulators moved compliance deadlines in three different directions inside a ten-day window. Two deferred. One landed on schedule. Not one of them changed the security obligation underneath. This week's Compliance Pulse is about the difference between those two things, and about what happens to a control budget that was never told the difference.
DoD: the assessment gate came out of contracts
On September 3, 2026, the Department of Defense's principal director for defense pricing, contracting and acquisition policy issued a class deviation directing contracting officers to remove CMMC third-party assessment requirements from contracts (Nextgov/FCW). The action converts July's policy suspension of CMMC Phase 2 into binding acquisition direction. The clause at issue is DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
What the deviation does not do is the part practitioners need in writing. DFARS 252.204-7012 remains in every affected contract. All 110 controls of NIST SP 800-171 Rev. 2 remain the applicable standard for CMMC Level 2, anchored there by 32 CFR Part 170 and distinct from the FAR and DFARS Rev. 3 tracks. Self-assessment scores and SPRS submissions remain conditions of contract eligibility. And False Claims Act exposure for a false or stale representation continues in full through the suspension (Latham & Watkins).
The 60-day CMMC Reform Task Force review that began July 13 carries a September 11 deadline. Whether its recommendations are published is a separate decision, and it has not been made.
DoJ: the enforcement side never paused
Two days before the deviation, on September 1, 2026, Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements in a Department of Defense contract. The standard at issue was NIST SP 800-171. The conduct period ran from April 2020 through December 2023 — entirely before CMMC became an enforceable gate on any contract. The case arrived as a qui tam action brought by a former employee, Rachel Tenney, who received $375,823 of the settlement.
That sequencing is the whole argument. Liability attached to the control, in a period when the certification apparatus did not exist. The assessment is how a program demonstrates the control. It is not the control, and removing it does not remove the exposure. The Assistant Attorney General's framing was unambiguous: contractors that obtain defense information in administering their contracts must follow required cybersecurity standards.
GAO named the capacity risk in March
None of this arrived without warning. In GAO-26-107955, published March 12, 2026, the Government Accountability Office found that DoD had addressed six of seven strategic elements in its CMMC planning but had not assessed or documented how it intended to mitigate the risk that private-sector assessor capacity would be insufficient for a base of roughly 200,000 companies. DoD concurred, submitted a corrective action plan on April 29, 2026, and committed to complete the documentation by December 31, 2026. Six months later the assessment requirement came out of contracts. Read together, the March finding and the September deviation describe the same constraint from two ends.
HHS: the HIPAA Security Rule rewrite moved to Long-Term Actions
The HIPAA Security Rule overhaul, RIN 0945-AA22, now sits on the Unified Agenda's Long-Term Actions list with a projected date of July 2027 (Clark Hill). The January 2025 proposed rule would have made multi-factor authentication, encryption, asset inventory and network mapping explicit requirements rather than addressable ones. Those proposals are now roughly two years out.
A move to Long-Term Actions is not a non-event. It is a transfer of authority. While the rewrite waits, the bar is set by HHS Office for Civil Rights enforcement of the Security Rule as currently written — a risk-analysis-centred text that OCR has enforced against exactly the deficiencies the rewrite was meant to close. Covered entities and business associates do not get a deadline to budget against. They get the same breach exposure, the same enforcement posture, and no forcing function.
The EU: the one date that held
On September 11, 2026, the reporting obligations of the EU Cyber Resilience Act, Regulation (EU) 2024/2847, begin to apply. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents affecting product security: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days once a corrective measure is available, or within one month for severe incidents. Reports go through the CRA Single Reporting Platform to the CSIRT of the manufacturer's main establishment, with simultaneous notification to ENISA (European Commission).
This binds US manufacturers placing product on the EU market. It arrived on the date it was always going to arrive. For anyone who spent 2026 tracking American deadlines, it is the milestone that did not slip, attached to the consequence that matters most to a CFO: market access.
Two more items that did not make the post
CISA's BOD 26-04 is now issuing split remediation windows. On August 26, 2026, three-day deadlines were assigned to current-year flaws in Gitea, Citrix NetScaler and Microsoft SQL Server while four legacy vulnerabilities disclosed between 2015 and 2021 received fourteen days — same catalog, same day. Deadlines are scored per entry against exposure, known exploitation, automation potential and technical impact. A fixed 21-day internal patch SLA no longer maps to the federal expectation.
In the maritime sector, 33 CFR Part 101 Subpart F is in force and unchanged this window. The Cyber Assessment, Cyber Plan and Cybersecurity Officer designation milestone remains July 16, 2027 — about ten months out, which makes assessment scoping a this-quarter activity rather than a next-year one.
Milestone calendar — sectors covered this edition
| Sector | Instrument | Milestone | Date |
|---|---|---|---|
| DIB / DoW | DFARS 252.204-7021 | 3rd-party assessment removed from contracts (class deviation) | 2026-09-03 |
| DIB / DoW | CMMC Reform Task Force | 60-day review report due | 2026-09-11 |
| DIB / DoW | DFARS 252.204-7012 / SP 800-171 Rev. 2 | In force — unchanged | Now |
| DIB / DoW | GAO-26-107955 corrective action | DoD external-factor documentation due | 2026-12-31 |
| Healthcare | HIPAA Security Rule, RIN 0945-AA22 | Long-Term Actions — projected final | 2027-07 |
| IIoT / Global | Reg. (EU) 2024/2847 Art. 14 | CRA reporting obligations apply | 2026-09-11 |
| IIoT / Global | Reg. (EU) 2024/2847 | Main obligations apply | 2027-12-11 |
| Maritime | 33 CFR 101 Subpart F | Cyber Assessment / Cyber Plan / CySO | 2027-07-16 |
| Cross-federal | CISA BOD 26-04 | Per-entry KEV deadlines (3-day and 14-day issued 2026-08-26) | Ongoing |
Practitioner checklist
- Confirm in writing which of your contracts had DFARS 252.204-7021 removed and which retain 252.204-7012. They are different clauses with different consequences.
- Re-date your most recent SPRS submission. If the score reflects a plan of action rather than implementation, that gap is the FCA exposure, not the assessment status.
- Identify every control whose funding justification cited a CMMC assessment date or the HIPAA Security Rule rewrite. Re-justify each one against the asset it protects, or defund it deliberately and record who decided.
- If you manufacture anything with digital elements sold into the EU, name the person who owns the 24-hour early-warning clock and confirm they can reach the CRA Single Reporting Platform today.
- Rebuild patch SLAs around per-entry KEV deadlines rather than a fixed cycle.
- Maritime operators: scope the Cyber Assessment this quarter.
Which of your controls exist because a rule requires them, and which because the risk does? The two lists diverged this month. Yours should be able to show where.
Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Senior Lead Auditor | PSY Logistics Technology Partners
Sources
- U.S. Department of Justice, Office of Public Affairs — Honeywell Aerospace Inc. FCA settlement (September 1, 2026)
- Regulation (EU) 2024/2847 — Cyber Resilience Act (EUR-Lex)
- European Commission — Cyber Resilience Act reporting obligations
- GAO-26-107955 — Defense Contractor Cybersecurity (March 12, 2026)
- eCFR — DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- eCFR — DFARS 252.204-7021, Contractor Compliance With the CMMC Level Requirements
- Supplier Performance Risk System (SPRS) — U.S. Department of Defense
- eCFR — 32 CFR Part 170 (CMMC Program)
- eCFR — 33 CFR Part 101 Subpart F (Maritime Cybersecurity)
- eCFR — 45 CFR Part 164 Subpart C (HIPAA Security Rule)
- Federal Register — HIPAA Security Rule NPRM (January 6, 2025)
- Federal Register — Cybersecurity in the Marine Transportation System final rule (January 17, 2025)
- CISA — BOD 26-04, Prioritizing Security Updates Based on Risk
- Nextgov/FCW — CMMC's Phase 2 suspension locked in with binding regulation (September 2026)
- Latham & Watkins — What Defense Contractors Should Know About DOD's Suspension of CMMC Phase 2
- Clark Hill — HIPAA Security Rule Update Delayed Until 2027