Compliance Pulse October 2026 — Missed Rulemakings, Unchanged Obligations

Compliance Pulse — 2026-10-01

October 01, 2026

Compliance Pulse · Thursday, October 1, 2026


September 2026 ended with two federal cyber rules exactly where they started it. The Fall 2026 Unified Agenda had projected final rules for both FAR Case 2021-017 and CIRCIA inside the month, and neither published.

In the same window two other regulators did move — one adding a step to remediation, the other pausing the paperwork while leaving its deadline untouched. Read together they make one point: the filing schedule and the underlying duty are not the same object, and only one is negotiable.

The month two rules did not use

The Fall 2026 Unified Agenda, published in the Federal Register on August 14, 2026 (document 2026-16612), placed FAR Case 2021-017 (RIN 9000-AO34), Cyber Threat and Incident Reporting and Information Sharing, in Final Rule Stage with a projected date of September 2026. CIRCIA carried the same September projection.

A Federal Register check run on October 1, 2026 returns, for the FAR rulemaking, the proposed rule of October 3, 2023 (document 2023-21328) and the comment-period extension of November 1, 2023 (document 2023-24025). For CIRCIA, the newest document remains the notice of proposed rulemaking of April 4, 2024 (document 2024-06526). No rule-type document exists for either. The projection is now missed rather than elapsing, and this edition closes the carry the September 24 edition opened.

What that does not change is the part that was always binding. DFARS 252.204-7012 still requires reporting of a cyber incident within 72 hours of discovery. Item 1.05 of Form 8-K still runs on its own clock for public companies. State breach-notification statutes still run on theirs, and so do sector regulators. An organization that deferred incident-reporting runbook work pending one harmonized federal rule has now waited two years past the proposed rule and a full month past the projected final — and has been reportable the entire time.

CISA added a step rather than removing one

While two rulemakings stalled, the instrument that actually binds federal networks got more demanding. Binding Operational Directive 26-04 directs agencies to prioritize exploited vulnerabilities and to assess whether a system is already compromised before remediating it. Catalog entries issued under the directive now carry that sequence inline: apply the temporary mitigation, perform forensic triage, then install the vendor patch. The stated rationale is blunt — applying a patch generally does not evict a threat actor.

That is a federal instrument making evidence preservation a precondition of remediation, and it maps directly onto the standard defense contractors are measured against. Under 32 CFR Part 170, CMMC Level 2 is anchored to NIST SP 800-171 Rev. 2, where the incident response and audit-and-accountability families both assume the artifacts exist. An organization that patches an exploited internet-facing appliance without first capturing memory and logs has not closed an incident. It has destroyed the record its own System Security Plan commits it to retain, and it will not be able to tell an assessor, a prime, or a relator what happened.

Maritime: the inbox closed, the calendar did not

On June 4, 2026 the Coast Guard released CG-5PC Policy Letter 01-26, Cybersecurity Assessment Initial Scoping and Process; CG-MCP-WI-002, Waiver and Equivalency Guidance for Requirements of 33 CFR Part 101, Subpart F; and CG-MCP-WI-003, DoD SAFE Instructions for Cybersecurity Plan, Cybersecurity Assessment, and Waiver and Equivalency Request submissions. The same announcement asked maritime entities to refrain from submitting full Cybersecurity Plans until further notice while waiver and equivalency requests are processed.

Nothing in that announcement changes a date. 33 CFR 101.655 still requires every Cybersecurity Plan to be submitted for review and approval no later than July 16, 2027. Section 101.650 still requires the Cybersecurity Assessment by that date and annually thereafter, including addressing Known Exploited Vulnerabilities in critical systems. And MCP-WI-002 makes a completed Cybersecurity Assessment the prerequisite for any waiver or equivalency request under § 101.665. The one artifact nobody has been asked to stop producing is the one that gates every other form of relief in the subpart.

What the character cap cut

Healthcare. No HHS OCR enforcement action has published since the Ambry Genetics settlement of September 17, 2026 — $700,000, 225,370 individuals affected, a two-year corrective action plan monitoring period. The HIPAA Security Rule update, RIN 0945-AA22, remains in Long-Term Actions with a projected date of July 2027, unchanged for a fourth consecutive edition. OCR continues to enforce the rule as it currently stands, against breaches that predate the update by years.

Defense industrial base. The class deviation that directed contracting officers to strike third-party CMMC assessment requirements from contracts on September 3, 2026 remains in force with no stated end date, and self-attestation to NIST SP 800-171 Rev. 2 remains mandatory. Separately, the CMMC Reform Task Force's 60-day review closed September 11, 2026; no public release has been observed as of September 30, 2026.

Surface transportation and OT. TSA's information-collection revision covering 49 CFR Parts 1580, 1582 and 1584 (published September 1, 2026, document 2026-17894) has comments due to OMB today, October 1, 2026. The Enhancing Surface Cyber Risk Management proposed rule (November 7, 2024, document 2024-24704) remains proposed with no final rule.

Connected products. EU Cyber Resilience Act Article 14 reporting obligations took effect on September 11, 2026 — the date printed in Regulation (EU) 2024/2847, with no extension and no transition relief. The regulation's main obligations apply December 11, 2027.

The practitioner checklist

  1. Pull every active award and list the clauses that already impose a reporting obligation — DFARS 252.204-7012, agency supplements, prime flow-downs. Date the list. That is your reporting program today, whether or not FAR 2021-017 finalizes.
  2. Write the incident-reporting runbook against contract clauses, Form 8-K, state law and your sector regulator, with a labeled insertion point for CIRCIA rather than a dependency on it.
  3. Add a preserve-before-remediate step to emergency patching for internet-facing appliances: capture memory and logs first, then mitigate, then upgrade. Name the person who owns the capture.
  4. Confirm your System Security Plan scopes the management plane — firewall management servers, access proxies, VPN concentrators, SD-WAN orchestrators and edge routers are Security Protection Assets under 32 CFR Part 170 even when they store no CUI.
  5. Maritime operators: scope the Cybersecurity Assessment this quarter. It gates the waiver, the equivalency and the plan, and the submission pause does not extend July 16, 2027.
  6. Healthcare entities: run a risk analysis that names systems rather than an enterprise risk register, and test the access-termination path for departed workforce across every system holding ePHI, including business associates.
  7. Surface transportation operators: the OMB comment window on the TSA collection closes today, October 1, 2026.
  8. For each control you funded this year, record whether the business case was a filing date or the risk. Re-test the ones that say filing date.

The question to answer in your own environment

Three regulators adjusted paperwork in the same month, and none of them adjusted the duty behind it. A missed rulemaking does not suspend a contract clause. A paused filing window does not move a compliance date. A faster patch does not satisfy a directive that asks you to preserve the evidence first.

Name one control in your budget that exists because a filing date required it. If that date moves again, who decides whether it stays funded?

Regulatory milestones — sectors covered this edition

SectorInstrumentMilestoneDateStatus
1 DIB/DoWDFARS 252.204-7012 / NIST SP 800-171 Rev. 2Self-attestation mandatory; 72-hour incident reportingIn forceActive — unchanged
1 DIB/DoWDoW class deviation (CMMC Phase 2)Third-party assessment struck from contracts2026-09-03In force — open-ended
1 DIB/DoWCMMC Reform Task Force60-day review closed2026-09-11Passed — no public release observed
2 HealthcareHHS OCR — Ambry Genetics$700,000; 225,370 individuals; 2-yr CAP2026-09-17Resolved — current rule enforced
2 HealthcareHIPAA Security Rule, RIN 0945-AA22Long-Term Actions — projected final2027-07Deferred — unchanged
3 MaritimeUSCG PL 01-26 / MCP-WI-002 / MCP-WI-003Guidance released; full CSP submissions paused2026-06-04In force — pause not lifted
3 Maritime33 CFR 101.650 / 101.655Cybersecurity Assessment and Plan due2027-07-16On track — date unchanged
5 OT/ICSTSA OMB control 1652-0074Comments to OMB due2026-10-01DUE TODAY
6 IIoTReg. (EU) 2024/2847 Art. 14CRA reporting obligations apply2026-09-11Took effect on schedule
6 IIoTReg. (EU) 2024/2847CRA main obligations apply2027-12-11On track
8 Cross-federalFAR Case 2021-017 (RIN 9000-AO34)Final Rule Stage — projected September 20262026-09MISSED — nothing published
8 Cross-federalCIRCIA final ruleAgenda projection September 20262026-09MISSED — nothing published
8 Cross-federalCISA BOD 26-04Assess compromise before remediatingOngoingActive — latest BOD

Sources — primary instruments


Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Senior Lead Auditor | PSY Logistics Technology Partners, Inc. — Houston, TX / Littleton, CO

Back to Blog