News

The regulatory changes and threat trends shaping our clients' obligations, with what each one means in practice.

Updated 1 October 2026. Timelines change often; confirm with the issuing authority before relying on a date.

Key dates ahead

Deadlines our clients are planning around, in date order.

  • 10 Nov 2026CMMC Phase 2: Level 2 third-party certification in applicable DoD solicitations
  • 2 Dec 2026EU AI Act: marking of AI-generated content for systems already on the market
  • 11 Dec 2026Cybersecurity Information Sharing Act of 2015 expires unless extended
  • July 2027HIPAA Security Rule final action (target, not binding)
  • 2 Dec 2027EU AI Act: high-risk obligations for stand-alone (Annex III) systems
  • 11 Dec 2027EU Cyber Resilience Act: full application
  • To be setCIRCIA reporting begins on the final rule's effective date

Regulatory watch

New obligations and the status of pending rules in the U.S. and EU.

New obligation

EU Cyber Resilience Act: vulnerability and incident reporting is now mandatory

Since 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe security incidents through ENISA's new Single Reporting Platform. An early warning is due within 24 hours, a full notification within 72 hours, and a final report within 14 days for vulnerabilities or one month for incidents. This applies to products already on the market, not only new ones. The rest of the Act applies from 11 December 2027.

What it means for you: Manufacturers and software vendors selling into the EU need a working process to detect, triage, and report exploitation within 24 hours. If you rely on such vendors, ask how they are meeting this duty.

Sources: ENISA, Hogan Lovells Cadwalader

Deadline approaching

CMMC Phase 2: third-party Level 2 certification becomes a condition of award

From 10 November 2026, applicable Department of Defense solicitations will require contractors that handle Controlled Unclassified Information to hold a CMMC Level 2 certification from an accredited third-party assessor, not a self-assessment. Assessor capacity is limited, so lead times are significant.

What it means for you: Defense contractors and their subcontractors should confirm which contracts are in scope, close gaps against NIST SP 800-171, and book an assessment now rather than after a solicitation arrives.

Sources: Chainguard, DoD CIO: CMMC

Status update

CIRCIA: the September target passes without a final rule

CISA had targeted September 2026 for the final rule under the Cyber Incident Reporting for Critical Infrastructure Act. As of 1 October 2026, CISA still states that organizations do not have to report until a final rule is published and takes effect. Once it does, covered entities in 16 critical-infrastructure sectors must report covered incidents within 72 hours and ransom payments within 24 hours.

What it means for you: The timing keeps moving, but the 72-hour and 24-hour clocks are fixed in the statute. Use the extra time to confirm whether you are covered and to build the reporting decision into your incident response plan.

Sources: CISA, Bright Defense

Status update

Cyber threat information-sharing law extended only to 11 December 2026

The Cybersecurity Information Sharing Act of 2015, which gives companies legal protections when they share cyber threat indicators with the government and each other, was extended to 11 December 2026 by the stopgap funding law signed on 2 September. A long-term reauthorization has not passed.

What it means for you: If the law lapses, the liability and antitrust protections for sharing threat information could lapse with it. Legal and security teams should agree now on how they will share threat information if that happens.

Sources: Defense One, Federal News Network

Regulatory watch

EU AI Act: high-risk deadlines deferred, transparency duties now apply

The EU's Digital Omnibus on AI entered into force on 27 July 2026. It defers obligations for stand-alone high-risk AI systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. The Article 50 transparency obligations were not deferred, and machine-readable marking of AI-generated content applies to systems already on the market from 2 December 2026.

What it means for you: The extra time is best used to inventory AI systems, classify their risk, and build a management system such as ISO/IEC 42001 that will support compliance when the deadlines arrive.

Sources: DLA Piper, Usercentrics

Regulatory watch

HIPAA Security Rule overhaul: final action now targeted for July 2027

HHS proposed the largest update to the HIPAA Security Rule in two decades in January 2025, including mandatory encryption of ePHI, multi-factor authentication, and stricter oversight of business associates. The federal regulatory agenda has moved the final rule to a July 2027 target, and it could still change or be withdrawn.

What it means for you: The current Security Rule is still being enforced, and risk analysis remains the most frequently cited deficiency. A current, documented risk analysis is the best preparation for either outcome.

Sources: Clark Hill, The HIPAA Journal

Threat trends

What the latest evidence says about how breaches happen.

Threat trend

Exploited vulnerabilities and third parties now drive breaches

Verizon's 2026 Data Breach Investigations Report found that exploitation of vulnerabilities was the leading way in, at 31% of breaches, while credential abuse fell to 13%. Third parties were involved in 48% of breaches, and ransomware appeared in 48%. Patching slowed: the median time to fully remediate rose to 43 days, and only 26% of vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated.

What it means for you: Prioritize patching by known exploitation rather than severity score alone, and review critical vendors continuously rather than once a year. Both are now where most breaches start.

Sources: SecurityWeek, Help Net Security

This month

Cybersecurity Awareness Month 2026: “Don't Make It Easy for Them”

The National Cybersecurity Alliance opened the 23rd Cybersecurity Awareness Month on 1 October with a focus on four everyday habits: strong, unique passwords; multi-factor authentication; keeping devices updated; and caution with suspicious messages.

What it means for you: October is a good moment for a short staff refresher and a check that multi-factor authentication is enforced on email, remote access, and administrator accounts.

Sources: National Cybersecurity Alliance

Earlier news

Previous editions, kept for reference. Some details have since changed; see the current items above for the latest status.

September 2026 edition3 items: HIPAA, CIRCIA, EU AI Act

The CIRCIA item below reflects CISA's September target, which has since passed without a final rule.

Regulatory watch

HIPAA Security Rule overhaul: final action now targeted for July 2027

HHS proposed the largest update to the HIPAA Security Rule in two decades in January 2025, including mandatory encryption of ePHI, multi-factor authentication, and stricter oversight of business associates. The federal regulatory agenda has since moved the final rule to a July 2027 target, and it could still change or be withdrawn.

What it means for you: The current Security Rule is still being enforced, and risk analysis remains the most frequently cited deficiency. A current, documented risk analysis is the best preparation for either outcome.

Sources: Clark Hill, The HIPAA Journal

Regulatory watch

CIRCIA final rule targeted for September 2026

CISA missed the October 2025 statutory deadline for the CIRCIA final rule, held stakeholder town halls in June 2026, and now targets September 2026 for publication. Once in effect, covered entities across 16 critical-infrastructure sectors must report covered cyber incidents within 72 hours and ransom payments within 24 hours.

What it means for you: Those reporting clocks are set in the statute. Organizations that may be covered should confirm scope now and build the reporting decision into their incident response plans. Check cisa.gov/circia for publication status.

Sources: Hunton Andrews Kurth, Federal News Network

Regulatory watch

EU AI Act: high-risk deadlines deferred, transparency duties now apply

The EU's Digital Omnibus on AI entered into force on 27 July 2026. It defers obligations for stand-alone high-risk AI systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. The Article 50 transparency obligations were not deferred.

What it means for you: The extra time is best used to inventory AI systems, classify their risk, and build a management system such as ISO/IEC 42001 that will support compliance when the deadlines arrive.

Sources: DLA Piper, Usercentrics

Firm announcements

Announcement

SenasoftConsult launches a new website and visual identity

The new site brings together the firm's services, its approach, its research focus, and its leadership team, alongside a refreshed logo and brand system built for clarity across print and screen.