Compliance Pulse October 2026 — Duties Arriving Without Rulemaking

GAO found federal cyber reporting rules duplicate and conflict with sector rules. Two watchdog reports and one directive added duties with no rulemaking.

October 08, 2026

Six industry representatives sat down with GAO in July and said out loud what most compliance leaders say privately: the federal cyber reporting stack has grown to the point where satisfying it competes with responding to the incident. GAO published that on September 28. In the three weeks since, two watchdog reports and one directive have each added a duty, and not one required a rulemaking to do it. Meanwhile FAR Case 2021-017 and CIRCIA both missed their September projections, the HIPAA Security Rule overhaul sits in Long-Term Actions until July 2027, and the Department of War struck third-party CMMC assessment from new procurements. Everyone tracks the Federal Register. The Federal Register is not where the duty moved.

Cross-cutting federal — GAO-26-109197 puts the conflict on the record

Published September 28, 2026. GAO convened six industry representatives from energy, financial services, and healthcare and public health — the sectors its prior work identified as carrying the heaviest regulatory load — at a panel held July 16, 2026.

Participants in all three sectors said DHS's proposed cyber incident reporting rule and the SEC's cybersecurity disclosure rules were duplicative of, and in conflict with, their own sector's regulations. GAO's summary of the consequence is the sentence to carry into a board meeting: it "could be difficult to fully satisfy all reporting requirements while remediating cyber threats."

Half the participants said harmonization progress over the past year was limited. Their proposed fixes were specific: define reporting timeframes and thresholds consistently across regimes, and designate a lead agency to coordinate and receive incident reports.

This is not a complaint about paperwork. It is a finding that reporting now draws on the same people and hours as containment. GAO made no recommendations and raised no matters for congressional consideration, so nothing changes on this finding alone.

Bottom line for CISOs and general counsel: the conflict is documented. An obligation map built before the next incident is the only version of this problem you solve calmly.

DIB and federal — preserve before you patch stopped being the exception

Every addition to CISA's Known Exploited Vulnerabilities catalog in the first week of October carried the Forensics Triage Requirements language in its required-action field, each on a three-day clock. A quarter ago it appeared on a minority of entries and was treated as notable. It is now standard.

The instrument behind it is BOD 26-04, which directs agencies to assess whether a system is already compromised before remediating it, on the stated rationale that applying a patch generally does not evict a threat actor. No rulemaking produced that sequence.

For contractors the consequence is contractual. Under 32 CFR Part 170, with CMMC Level 2 anchored to NIST SP 800-171 Revision 2, the incident response and audit and accountability families assume the artifacts exist. Rebooting an internet-facing appliance for an emergency patch without first capturing memory and logs destroys the record the System Security Plan commits you to retain — closing the vulnerability and the only window to learn whether it was already used.

Bottom line for defense contractors: patching inside the deadline is no longer the same thing as closing the incident.

Aviation — GAO-26-108439, nine open recommendations, all concurred

Published September 21, 2026. GAO found the text-based applications FAA, pilots and industry rely on — ACARS and CPDLC — vulnerable to interception and spoofing because of weak authentication, limited encryption and protocol design. Its example: a malicious actor sending fraudulent clearance cancellations.

On spectrum, FAA has identified spoofing and jamming threats to the National Airspace System and international routes but has not completed the risk and mitigation assessments or updated the security documentation addressing them, and has no defined real-time monitoring capability — so it investigates only after an incident is reported.

Nine recommendations. All nine open. The Department of Transportation concurred with all nine on FAA's behalf.

FAA's own cybersecurity rulemaking has been proposed since August 2024. The requirement is arriving anyway — through oversight findings and through the certification basis of specific aircraft.

Bottom line for aviation operators and A&D suppliers: the certification basis moves before the CFR does.

The DIB enforcement picture the class deviation did not touch

DFARS Class Deviation 2026-O0025 Revision 3, issued September 3, 2026, struck third-party CMMC assessment from new procurements. It left DFARS 252.204-7012, annual affirmations, subcontractor flowdown and False Claims Act exposure where they were.

Two settlements show where the liability sits. LOGZONE resolved for $507,144 on June 18, 2026, after self-reporting an SPRS score of 110 against a DCMA-assessed negative 170 on an assessment dated February 2, 2024. Honeywell Aerospace resolved for $2,042,518 on September 1, 2026, covering conduct from April 2020 through December 2023, in U.S. ex rel. Tenney v. Honeywell International, No. 3:22-cv-129 (W.D.N.C.).

Neither required a certification to have been scheduled. Both turned on an affirmation that did not match the environment.

One open question, stated as open: whether the CMMC Reform Task Force report was delivered to the Department CIO on September 11 is unresolved, and no public release has been observed. Settle it before citing it.

What did not move

Maritime: 33 CFR 101 Subpart F is unchanged. Cybersecurity Plans must be submitted for review and approval, and the initial Cybersecurity Assessment completed, no later than July 16, 2027 — 281 days from today. The Coast Guard asked entities to refrain from submitting full plans on June 4, 2026; no notice lifting that pause has been located. The inbox closed; the deadline did not.

Surface transportation: the TSA Enhancing Surface Cyber Risk Management proposal remains proposed; the OMB comment window on its information collection closed October 1, 2026.

The question underneath

If the instruments that changed something this quarter were a directive, two watchdog reports, a catalog field and two settlements — and every rulemaking people track deferred — then a program scheduled against the Federal Register is scheduled against the wrong document.

Every control worth having survives its rule slipping. Evidence capture before remediation. An affirmation that matches the environment. Authentication on a channel carrying clearances. A reporting path naming who files what, to whom, in how many hours. Each is already required by something.

Compliance confirms the work. It has never been where the work originates.

Practitioner checklist

1. Build the obligation map GAO's panelists asked for: every reporting duty, its trigger, clock, recipient and owner. One page, before the incident.

2. Add an evidence-capture step to emergency patching on every internet-facing appliance. Name the owner, pre-approve the out-of-band change path, document it against your SSP.

3. Reconcile your SPRS score to your actual environment this month. Both settlements turned on that gap; the class deviation did not touch it.

4. Aviation and A&D: treat GAO-26-108439's nine recommendations as a preview of your certification basis, and inventory where ACARS and CPDLC data enters your systems.

5. Maritime: work backward from July 16, 2027. The pause is not relief.

6. Healthcare: compare your largest BAAs and payer agreements against the deferred Security Rule proposals. Most already require more.

7. Connected products sold into the EU: confirm who files the 24-hour early warning, from what evidence, to which CSIRT.

Regulatory milestone calendar

SectorInstrumentMilestoneDateStatus
8 Cross-federalGAO-26-109197Regulatory duplication/conflict panel report2026-09-28Published — no recommendations
4 AviationGAO-26-1084399 recommendations to FAA; DOT concurred2026-09-21All 9 open
8 Cross-federalCISA BOD 26-04Assess compromise before remediatingIn forceActive — latest BOD
8 Cross-federalFAR Case 2021-017 / CIRCIAFall 2026 agenda projection2026-09Missed — nothing published
1 DIB/DoWClass Deviation 2026-O0025 Rev. 33rd-party assessment struck from new procurements2026-09-03In force — open-ended
1 DIB/DoWDFARS 252.204-7012 / 800-171 Rev. 2Self-attestation, 72-hour reporting, flowdownNowUnchanged
1 DIB/DoWGAO-26-107955DoD external-factor documentation due2026-12-3184 days — inside 120
2 HealthcareHIPAA Security Rule, RIN 0945-AA22Long-Term Actions — projected final2027-07Deferred — 5th edition
3 Maritime33 CFR 101.650 / 101.655Cyber Assessment and Plan submission2027-07-16281 days — unmoved
3 MaritimeUSCG PL 01-26 / MCP-WI-002 / -003Full CSP submissions paused until further notice2026-06-04In force — no lifting notice
5 OT/ICSEnhancing Surface Cyber Risk ManagementNPRM — no final rule2024-11-07Still proposed
5 OT/ICSTSA OMB control 1652-0074Comments to OMB2026-10-01Closed
6 IIoTReg. (EU) 2024/2847 Art. 14CRA reporting obligations apply2026-09-11In force
6 IIoTReg. (EU) 2024/2847CRA main obligations2027-12-11On track
7 Financial23 NYCRR 500.17(b)(1)Annual certification of material complianceApril 15, annuallyRecurring
9 GlobalEU AI Act Art. 5 transitionTransition ends2026-12-0255 days — inside 120

Sources

  • GAO-26-109197, Cybersecurity Regulations: Industry Panelists Identify Duplication and Conflicts and Ways to Address Them (2026-09-28) — link
  • GAO-26-108439, Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications (2026-09-21) — link
  • CISA BOD 26-04, Prioritizing Security Updates Based on Risk — link
  • 32 CFR Part 170 — CMMC Program — link
  • 33 CFR Part 101 Subpart F — Cybersecurity — link
  • USCG Maritime Commons, policy and guidance supporting 33 CFR Part 101 Subpart F (2026-06-04) — link
  • TSA, Enhancing Surface Cyber Risk Management, NPRM (2024-11-07, doc 2024-24704) — link
  • FAA, Equipment, Systems, and Network Information Security Protection, NPRM (2024-08-21, doc 2024-17916) — link
  • Regulation (EU) 2024/2847, Cyber Resilience Act — link

Craig Wood | CISM | CCA Lead Assessor | ISO/IEC 27001 Senior Lead Auditor | CEO, PSY Logistics Technology Partners | CMMC | Maritime Cybersecurity | vCISO | DIB

Back to Blog