
The Rule Is the Artifact. The Control Is the Obligation.
Three federal cybersecurity rules that were expected to be finished by now are not. Aircraft manufacturers, critical infrastructure operators, and rail and transit agencies are held to the underlying security obligations anyway. This edition traces how that works in each sector — and what the one regulator that kept its date tells everyone else.
Aviation: the FAA certifies cyber one project at a time
On June 1, 2026 the FAA published final special conditions — Docket FAA-2026-4489 — requiring electronic system security protection on a Honeywell modification to the Boeing 757-200. The conditions require protection of airplane electronic systems from unauthorized external access, identification and assessment of electronic security threats, and operator procedures that maintain continued airworthiness after certification. The FAA’s stated justification is that the applicable airworthiness regulations “do not contain adequate or appropriate safety standards” for the design feature.
The rule written to close that gap is Equipment, Systems, and Network Information Security Protection — Docket FAA-2024-1398, RIN 2120-AL94 — which adds 14 CFR 25.1319, 33.28(n), and 35.23(f). It was proposed August 21, 2024 at 89 FR 67564. Comments closed October 21, 2024. No final rule has published. The proposal itself records that the FAA has imposed these requirements by special condition on every new transport category certification project and relevant design change since the Boeing 787 program. A prior set in the same line went to Universal Avionics on March 5, 2025.
Oversight has noticed. GAO-26-107693, issued July 16, 2026, found the FAA has fully implemented three of the seven objectives in its Cybersecurity Strategy and that TSA has not defined roles and responsibilities in its Cybersecurity Roadmap. GAO made five recommendations; DOT and DHS concurred.
Bottom line for aerospace OEMs and avionics suppliers: the cyber requirement is already binding, it arrives per docket rather than per CFR section, and it gates the type certificate. The type certificate gates delivery. Delivery is revenue.
Cross-sector: CIRCIA is on its third target date
CISA published the CIRCIA proposed rule on April 4, 2024. Practitioner analysis from Hunton records that CISA missed the statutory October 2025 deadline for the final rule and then an internal May 2026 target. CISA held additional town halls in June 2026, and the 2026 Unified Agenda projects the final rule for September 2026. As of September 17, 2026, no final rule has published. Thirteen days remain in the projection window.
None of that changes what a covered entity owes today. Incident reporting obligations already attach through federal contract clauses, SEC Form 8-K Item 1.05, state breach-notification statutes, and sector regulators. The 72-hour and 24-hour CIRCIA clocks are statutory; the rule decides who is covered and how the report is filed, not whether an organization needs to detect, decide, and notify inside a fixed window.
Bottom line for critical infrastructure CISOs and general counsel: write the incident-reporting runbook against the obligations in force now, and leave a CIRCIA insert point. A runbook that waits on CIRCIA is a runbook that does not exist during the next incident.
Surface transportation: TSA renewed the directives instead
TSA proposed Enhancing Surface Cyber Risk Management on November 7, 2024, covering 49 CFR Parts 1500, 1503, 1520, 1570, 1580, 1582, and 1584. No final rule has published. On September 1, 2026 TSA instead sent OMB a revision to the information collection behind its existing program — OMB control number 1652-0074, Cybersecurity Measures for Surface Modes. The collection covers freight rail, mass transit and passenger rail, and over-the-road bus owner/operators, plus the security directives issued in 2021 and 2022. TSA counts 67 respondents and 22,167 annual burden hours. The revision adds a condition that a Cybersecurity Coordinator who is not a U.S. citizen hold trusted-traveler membership. Comments to OMB are due October 1, 2026.
Bottom line for rail, transit, and motorcoach operators: the security directives are the requirement, and the agency is resourcing them for another cycle. Verify the Cybersecurity Coordinator designation against the revised collection, and file comments by October 1 if the burden estimate does not match the operation.
What did not move: NYDFS Part 500
23 NYCRR Part 500 is the counter-example. Section 500.22(d) set staged transitional periods running from the Second Amendment’s November 1, 2023 effective date. The final, two-year tranche — multi-factor authentication under §500.12 and asset inventory under §500.13(a) — ran out on schedule. No extension issued. The annual certification of material compliance under §500.17(b)(1) is due April 15.
Bottom line for covered financial entities: policy-ready is not examination-ready. The certification is a signed attestation, and the evidence behind §500.12 and §500.13(a) has to exist before the signature does.
Milestones at a glance
Sector | Instrument | Milestone | Status |
|---|---|---|---|
Aviation | Docket FAA-2026-4489 | Final special conditions, June 1, 2026 | In force |
Aviation | 14 CFR 25.1319 (RIN 2120-AL94) | NPRM August 21, 2024 | Proposed — no final rule |
Aviation | GAO-26-107693 | Five recommendations, July 16, 2026 | Open |
Cross-cutting federal | CIRCIA final rule | Unified Agenda: September 2026 | Not published as of September 17 |
Surface / OT | TSA surface cyber NPRM | Proposed November 7, 2024 | Proposed — no final rule |
Surface / OT | OMB 1652-0074 | Comments due October 1, 2026 | Open |
Financial | 23 NYCRR 500.12 / 500.13(a) | Two-year transitional period | Ended on schedule |
Financial | 23 NYCRR 500.17(b)(1) | Annual certification, April 15 | Recurring |
What this means
Four regulators, four schedules, one constant: the security obligation never waited for rule text. A certification authority enforces it through the type certificate. A contracting officer enforces it through the clause. An examiner enforces it through the attestation. Organizations that fund security on the rulemaking calendar carry the risk now and buy the compliance late. Organizations that fund the control hold the certificate, the contract, and the license when the rule lands — with the evidence already in hand. Security brings compliance. Compliance does not bring security.
Build to the control. Let the rule catch up to you.
Practitioner checklist
Inventory every open TC and STC project and record whether electronic system security special conditions have issued against it.
Map every incident-reporting obligation in force today — contract, SEC, state, sector — into one runbook with named decision owners and clocks.
Mark the CIRCIA insert point in that runbook; do not make the runbook contingent on it.
Surface operators: confirm the Cybersecurity Coordinator designation and calendar the October 1, 2026 OMB comment deadline.
NYDFS covered entities: test §500.12 and §500.13(a) evidence as an examiner would, and calendar April 15.
Tag every security budget line to the control it funds, not the rule it anticipates.
The question to take to the next budget review: which line items wait on a rule that has not published — and what funds them if it never does?
Craig Wood | CISM | CCA Lead Assessor | ISO/IEC 27001 Senior Lead Auditor | CEO, PSY Logistics Technology Partners | CMMC | Maritime Cybersecurity | vCISO | DIB