
Two Federal Cyber Rules Missed Their Own September Target — Enforcement Never Paused
Compliance Pulse · Thursday, September 24, 2026
In three weeks, DoW struck third-party assessment out of defense contracts, two federal cyber rules let their own September target pass, and OCR settled a $700,000 penalty over a 2020 breach. The schedules slipped. The liability did not.
🛡️ DIB: the assessment left the contract. The exposure stayed.
On September 3, DoW made the CMMC Phase 2 suspension binding by class deviation, ordering contracting officers to strip third-party assessment out of contracts. Self-attestation to NIST SP 800-171 stays mandatory. DFARS 252.204-7012 never moved. DOJ settled Honeywell Aerospace for over $2M on September 1 — 800-171 controls, no C3PAO required.
Bottom line for defense subcontractors: the certificate paused. The False Claims Act did not.
🏛️ Federal: two incident-reporting rules, one target month, nothing filed.
The Fall 2026 Unified Agenda (August 14) puts FAR Case 2021-017, RIN 9000-AO34, in Final Rule Stage — projected September 2026. CIRCIA carries the same month. Six days left, and the Federal Register holds neither.
Bottom line for contractor CISOs: build the reporting runbook on contract terms, 8-K, and state law — an insert point for CIRCIA, not a dependency on it.
🏥 Healthcare: a 2020 breach, a 2026 penalty, a rule waiting on 2027.
On September 17, OCR settled with Ambry Genetics for $700,000 over a phishing breach affecting 225,370 people — in January 2020. Findings: no accurate risk analysis, no access-termination procedure, no unique user IDs. The HIPAA Security Rule update (RIN 0945-AA22) sits in Long-Term Actions, projected July 2027.
Bottom line for health-system and life-sciences CFOs: the rule you are waiting on is not the rule you will be judged by.
What did not move: EU Cyber Resilience Act Article 14 reporting obligations took effect September 11 — the date the regulation printed. No extension.
What This Means
Four regulators, four schedules, one constant: every enforcement action here ran against a control already in force. Rulemaking sets the audit date. It does not set the risk, the contract exposure, or the plaintiff's theory. Programs funded on rule timelines go dark when a rule slips. Programs funded on control ownership keep running — and keep protecting revenue, contract eligibility, and market access.
Fund the control, not the calendar.
Open your current security budget. Which line items survive if the rule justifying them never finalizes — and who in your organization made that call?