
Compliance Pulse — 2026-10-01
Compliance Pulse · Thursday, October 1, 2026
September 2026 ended with two federal cyber rules exactly where they started it. The Fall 2026 Unified Agenda had projected final rules for both FAR Case 2021-017 and CIRCIA inside the month, and neither published.
In the same window two other regulators did move — one adding a step to remediation, the other pausing the paperwork while leaving its deadline untouched. Read together they make one point: the filing schedule and the underlying duty are not the same object, and only one is negotiable.
The month two rules did not use
The Fall 2026 Unified Agenda, published in the Federal Register on August 14, 2026 (document 2026-16612), placed FAR Case 2021-017 (RIN 9000-AO34), Cyber Threat and Incident Reporting and Information Sharing, in Final Rule Stage with a projected date of September 2026. CIRCIA carried the same September projection.
A Federal Register check run on October 1, 2026 returns, for the FAR rulemaking, the proposed rule of October 3, 2023 (document 2023-21328) and the comment-period extension of November 1, 2023 (document 2023-24025). For CIRCIA, the newest document remains the notice of proposed rulemaking of April 4, 2024 (document 2024-06526). No rule-type document exists for either. The projection is now missed rather than elapsing, and this edition closes the carry the September 24 edition opened.
What that does not change is the part that was always binding. DFARS 252.204-7012 still requires reporting of a cyber incident within 72 hours of discovery. Item 1.05 of Form 8-K still runs on its own clock for public companies. State breach-notification statutes still run on theirs, and so do sector regulators. An organization that deferred incident-reporting runbook work pending one harmonized federal rule has now waited two years past the proposed rule and a full month past the projected final — and has been reportable the entire time.
CISA added a step rather than removing one
While two rulemakings stalled, the instrument that actually binds federal networks got more demanding. Binding Operational Directive 26-04 directs agencies to prioritize exploited vulnerabilities and to assess whether a system is already compromised before remediating it. Catalog entries issued under the directive now carry that sequence inline: apply the temporary mitigation, perform forensic triage, then install the vendor patch. The stated rationale is blunt — applying a patch generally does not evict a threat actor.
That is a federal instrument making evidence preservation a precondition of remediation, and it maps directly onto the standard defense contractors are measured against. Under 32 CFR Part 170, CMMC Level 2 is anchored to NIST SP 800-171 Rev. 2, where the incident response and audit-and-accountability families both assume the artifacts exist. An organization that patches an exploited internet-facing appliance without first capturing memory and logs has not closed an incident. It has destroyed the record its own System Security Plan commits it to retain, and it will not be able to tell an assessor, a prime, or a relator what happened.
Maritime: the inbox closed, the calendar did not
On June 4, 2026 the Coast Guard released CG-5PC Policy Letter 01-26, Cybersecurity Assessment Initial Scoping and Process; CG-MCP-WI-002, Waiver and Equivalency Guidance for Requirements of 33 CFR Part 101, Subpart F; and CG-MCP-WI-003, DoD SAFE Instructions for Cybersecurity Plan, Cybersecurity Assessment, and Waiver and Equivalency Request submissions. The same announcement asked maritime entities to refrain from submitting full Cybersecurity Plans until further notice while waiver and equivalency requests are processed.
Nothing in that announcement changes a date. 33 CFR 101.655 still requires every Cybersecurity Plan to be submitted for review and approval no later than July 16, 2027. Section 101.650 still requires the Cybersecurity Assessment by that date and annually thereafter, including addressing Known Exploited Vulnerabilities in critical systems. And MCP-WI-002 makes a completed Cybersecurity Assessment the prerequisite for any waiver or equivalency request under § 101.665. The one artifact nobody has been asked to stop producing is the one that gates every other form of relief in the subpart.
What the character cap cut
Healthcare. No HHS OCR enforcement action has published since the Ambry Genetics settlement of September 17, 2026 — $700,000, 225,370 individuals affected, a two-year corrective action plan monitoring period. The HIPAA Security Rule update, RIN 0945-AA22, remains in Long-Term Actions with a projected date of July 2027, unchanged for a fourth consecutive edition. OCR continues to enforce the rule as it currently stands, against breaches that predate the update by years.
Defense industrial base. The class deviation that directed contracting officers to strike third-party CMMC assessment requirements from contracts on September 3, 2026 remains in force with no stated end date, and self-attestation to NIST SP 800-171 Rev. 2 remains mandatory. Separately, the CMMC Reform Task Force's 60-day review closed September 11, 2026; no public release has been observed as of September 30, 2026.
Surface transportation and OT. TSA's information-collection revision covering 49 CFR Parts 1580, 1582 and 1584 (published September 1, 2026, document 2026-17894) has comments due to OMB today, October 1, 2026. The Enhancing Surface Cyber Risk Management proposed rule (November 7, 2024, document 2024-24704) remains proposed with no final rule.
Connected products. EU Cyber Resilience Act Article 14 reporting obligations took effect on September 11, 2026 — the date printed in Regulation (EU) 2024/2847, with no extension and no transition relief. The regulation's main obligations apply December 11, 2027.
The practitioner checklist
- Pull every active award and list the clauses that already impose a reporting obligation — DFARS 252.204-7012, agency supplements, prime flow-downs. Date the list. That is your reporting program today, whether or not FAR 2021-017 finalizes.
- Write the incident-reporting runbook against contract clauses, Form 8-K, state law and your sector regulator, with a labeled insertion point for CIRCIA rather than a dependency on it.
- Add a preserve-before-remediate step to emergency patching for internet-facing appliances: capture memory and logs first, then mitigate, then upgrade. Name the person who owns the capture.
- Confirm your System Security Plan scopes the management plane — firewall management servers, access proxies, VPN concentrators, SD-WAN orchestrators and edge routers are Security Protection Assets under 32 CFR Part 170 even when they store no CUI.
- Maritime operators: scope the Cybersecurity Assessment this quarter. It gates the waiver, the equivalency and the plan, and the submission pause does not extend July 16, 2027.
- Healthcare entities: run a risk analysis that names systems rather than an enterprise risk register, and test the access-termination path for departed workforce across every system holding ePHI, including business associates.
- Surface transportation operators: the OMB comment window on the TSA collection closes today, October 1, 2026.
- For each control you funded this year, record whether the business case was a filing date or the risk. Re-test the ones that say filing date.
The question to answer in your own environment
Three regulators adjusted paperwork in the same month, and none of them adjusted the duty behind it. A missed rulemaking does not suspend a contract clause. A paused filing window does not move a compliance date. A faster patch does not satisfy a directive that asks you to preserve the evidence first.
Name one control in your budget that exists because a filing date required it. If that date moves again, who decides whether it stays funded?
Regulatory milestones — sectors covered this edition
| Sector | Instrument | Milestone | Date | Status |
|---|---|---|---|---|
| 1 DIB/DoW | DFARS 252.204-7012 / NIST SP 800-171 Rev. 2 | Self-attestation mandatory; 72-hour incident reporting | In force | Active — unchanged |
| 1 DIB/DoW | DoW class deviation (CMMC Phase 2) | Third-party assessment struck from contracts | 2026-09-03 | In force — open-ended |
| 1 DIB/DoW | CMMC Reform Task Force | 60-day review closed | 2026-09-11 | Passed — no public release observed |
| 2 Healthcare | HHS OCR — Ambry Genetics | $700,000; 225,370 individuals; 2-yr CAP | 2026-09-17 | Resolved — current rule enforced |
| 2 Healthcare | HIPAA Security Rule, RIN 0945-AA22 | Long-Term Actions — projected final | 2027-07 | Deferred — unchanged |
| 3 Maritime | USCG PL 01-26 / MCP-WI-002 / MCP-WI-003 | Guidance released; full CSP submissions paused | 2026-06-04 | In force — pause not lifted |
| 3 Maritime | 33 CFR 101.650 / 101.655 | Cybersecurity Assessment and Plan due | 2027-07-16 | On track — date unchanged |
| 5 OT/ICS | TSA OMB control 1652-0074 | Comments to OMB due | 2026-10-01 | DUE TODAY |
| 6 IIoT | Reg. (EU) 2024/2847 Art. 14 | CRA reporting obligations apply | 2026-09-11 | Took effect on schedule |
| 6 IIoT | Reg. (EU) 2024/2847 | CRA main obligations apply | 2027-12-11 | On track |
| 8 Cross-federal | FAR Case 2021-017 (RIN 9000-AO34) | Final Rule Stage — projected September 2026 | 2026-09 | MISSED — nothing published |
| 8 Cross-federal | CIRCIA final rule | Agenda projection September 2026 | 2026-09 | MISSED — nothing published |
| 8 Cross-federal | CISA BOD 26-04 | Assess compromise before remediating | Ongoing | Active — latest BOD |
Sources — primary instruments
- Regulatory Agenda — FAR Council / OFPP, Fall 2026 edition (2026-08-14, doc 2026-16612) — https://www.federalregister.gov/documents/2026/08/14/2026-16612/regulatory-agenda
- FAR — Cyber Threat and Incident Reporting and Information Sharing, proposed rule (2023-10-03, doc 2023-21328) — https://www.federalregister.gov/documents/2023/10/03/2023-21328/federal-acquisition-regulation-cyber-threat-and-incident-reporting-and-information-sharing
- FAR — same rulemaking, extension of comment period (2023-11-01, doc 2023-24025) — https://www.federalregister.gov/documents/2023/11/01/2023-24025/federal-acquisition-regulation-cyber-threat-and-incident-reporting-and-information-sharing-extension
- CISA — CIRCIA Reporting Requirements, NPRM (2024-04-04, doc 2024-06526) — https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements
- CISA — BOD 26-04, Prioritizing Security Updates Based on Risk — https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- USCG Maritime Commons — additional policy and guidance in support of 33 CFR Part 101, Subpart F (2026-06-04) — https://www.news.uscg.mil/maritime-commons/Article/4512023/us-coast-guard-releases-additional-policy-and-guidance-in-support-of-33-code-of/
- eCFR — 33 CFR Part 101, Subpart F (Cybersecurity) — https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-101/subpart-F
- HHS OCR — Ambry Genetics settlement (2026-09-17) — https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-investigation-ambry-genetics-phishing-attack-affecting-225000-individuals.html
- TSA — Revision of Agency Information Collection Activity Under OMB Review: Cybersecurity Measures for Surface Modes (2026-09-01, doc 2026-17894) — https://www.federalregister.gov/documents/2026/09/01/2026-17894/revision-of-agency-information-collection-activity-under-omb-review-cybersecurity-measures-for
- Regulation (EU) 2024/2847 — Cyber Resilience Act (EUR-Lex) — https://eur-lex.europa.eu/eli/reg/2024/2847/oj
- 32 CFR Part 170 — CMMC Program — https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170
Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Senior Lead Auditor | PSY Logistics Technology Partners, Inc. — Houston, TX / Littleton, CO