The Business of Cyber Security

Regulation & Compliance

Regulation is the second exogenous demand driver, alongside the threat economy. Compliance deadlines create non-discretionary spend and spawn entire sub-segments (GRC, TPRM, compliance automation), and regulatory change is a recurring M&A catalyst. From the buyer's seat, a deadline is a purchase order the CISO cannot defer — mandated controls get funded first, sometimes ahead of the risk-reduction the CISO would otherwise prioritize.

Sub-pages cover the topic in more depth:

The major regimes (2025–2026)

Regime Jurisdiction Status / deadline Teeth
SEC Cyber Disclosure Rules US public companies In force (adopted Jul 26, 2023); 2026 enforcement recalibrated to fraudulent disclosure after the SolarWinds/CISO case was dismissed with prejudice Nov 20, 2025 — individual-CISO controls theory narrowed Enforcement actions; 8-K Item 1.05 (4 business days); board governance
SEC Reg S-P amendments (2024) US broker-dealers, investment advisers, investment companies, transfer agents Adopted May 2024; compliance now fully phased in — larger entities Dec 3, 2025; smaller entities Jun 3, 2026 Mandated incident-response program, customer notification within 30 days of a breach, and service-provider oversight; SEC exam/enforcement
NIS2 Directive EU (essential/important entities) Active enforcement — first penalties issued Q1 2026; first mandatory-audit deadlines now landing at the member-state level (e.g., Hungary's Jun 30, 2026, expected) — the Directive itself sets no single EU-wide audit date; transposition/full compliance rolling through ~Oct 2026 (expected); Commission referred Ireland, Spain, France and the Netherlands to the CJEU (Jul 8, 2026), seeking lump-sum and daily financial penalties for non-transposition (16b) Fines up to €10M or 2% global turnover
DORA (Digital Operational Resilience Act) EU financial sector In force since Jan 17, 2025; first genuine supervisory enforcement cycle now live (incident-reporting, Register of Information) Supervisory audits; financial penalties
CMMC (Cybersecurity Maturity Model Certification) US defense contractors 48 CFR final rule published Sep 10, 2025; effective Nov 10, 2025; Phase 1 (self-assessments) began Nov 10, 2025 and remains in force. Phase 2 suspended: a Jul 13, 2026 memo from DoD CIO Kirsten Davies suspended all pending and future CMMC milestones — including Phase 2's third-party assessments, which had been due to start Nov 10, 2026 — pending a 60-day top-to-bottom review by a newly created CMMC Reform Task Force Phase 1 self-assessment still required; Phase 2 third-party certification paused pending review
FCC cyber rules — EAS/WEA + submarine cables US broadcasters, cable/wireless operators, alert distributors; undersea-cable licensees Adopted at the FCC's Jun 25, 2026 open meeting; first submarine-cable rule update in decades; EAS/WEA order mandates basic cyber hygiene + a new alert-authentication ID, with a further rulemaking opened Required cyber-hygiene controls (passwords, patching, firewalls), alert authentication; "trusted provider" security standards for cable infrastructure
AI Security EO — "Promoting Advanced AI Innovation and Security" (EO 14409) US federal agencies (NSS + civilian) + a voluntary framework reaching frontier-model developers & critical-infrastructure operators Signed Jun 2, 2026 (published 91 FR 34565, Jun 5, 2026) on fast 30-/60-day clocks. 30-day (due ≈Jul 2, 2026 — both legs now landed): agencies begin hardening systems with AI-enabled cyber defenses; CISA BODs issued (see BOD 26-04 row below); the Treasury-managed AI cybersecurity clearinghouse launched Jul 14, 2026 as the "Gold Eagle" initiative (with CISA, DHS, and Defense Department contributions) to coordinate AI-discovered vulnerability reporting, validation, and patch prioritization. 60-day (Aug 1, 2026 — deadline reached): Treasury (+ DoW, NSA, CISA) jointly develop the classified benchmarking process for models' advanced cyber capabilities and set the "covered frontier model" threshold, plus a voluntary ≤30-day pre-release govt-access framework. Because the methodology and threshold are classified, the specific criteria are not expected to be published — this leg yields an internal government deliverable rather than a public rule to comply with Voluntary framework (EO is explicit: no mandatory licensing/pre-clearance); BODs bind civilian agencies; criminal-enforcement priority for AI-enabled attacks
ECB Cyber Mandate for European Banks EU financial sector (European Central Bank / Banking Supervision authority) Issued Jul 7, 2026 by ECB Banking Supervision Chair Claudia Buch to CEOs of supervised banks. Frames frontier AI models (Mythos, GPT-5.6 Cyber, Chinese open-source models without guardrails) as reshaping the cybersecurity threat landscape through accelerated vulnerability discovery and exploit generation. Mandates comprehensive action plans due to Joint Supervisory Teams (JSTs) by Oct 31, 2026. Short-term priorities: vulnerability/patch-management acceleration; AI-enabled detection/response; third-party risk management; perimeter/external-asset protection. Longer-term: legacy-tech replacement; incident-response/recovery hardening; threat-intel sharing. Separate letter on post-quantum cryptography ("must start now") to follow. Binding on supervised entities (major EU banks); action-plan noncompliance subject to supervisory enforcement (restrictions on capital, stress-test adjustments, governance mandates)
CISA BOD 26-04 — "Prioritizing Security Updates Based on Risk" US federal civilian executive-branch (FCEB) agencies (de-facto private-sector benchmark) Issued Jun 10, 2026 (operationalizes the EO's expedited-federal-cyber-defense push). Retires CVSS as the mandated prioritization basis and supersedes BOD 22-01 (KEV) and BOD 19-02. Replaces one severity number with a four-variable risk model — asset public exposure, KEV status, exploit automatability, and technical impact — driving graduated remediation timelines from as fast as 3 days (highest-risk, with mandatory forensic triage) to full deferral for the lowest-risk Binds FCEB agencies; risk-tiered patching mandate
Post-Quantum Cryptography EO — "Securing the Nation Against Advanced Cryptographic Attacks" (EO 14412) US federal agencies + "covered contractors" via a forthcoming FAR rule; critical-infrastructure operators encouraged Signed Jun 22, 2026, with OMB implementation memo M-26-15. Accelerates the federal PQC migration by roughly four to five years versus prior targets: high-value assets and high-impact systems must move to PQC for key establishment by Dec 31, 2030 and for digital signatures by Dec 31, 2031. Each agency names a PQC migration lead within 30 days; NIST completes a pilot migration of a subset of its own systems by Dec 31, 2027; the FAR Council has 180 days to propose a rule giving covered contractors until Dec 31, 2030 to meet NIST FIPS including the PQC algorithms; CISA + NIST publish minimum elements for a cryptographic bill of materials (CBOM) within 270 days Agency compliance via OMB oversight; contractor compliance via the FAR rule (certification to sell to the government)
GDPR EU (data protection) Long in force Up to €20M or 4% global turnover
HIPAA US healthcare In force; tightening Penalties + OCR enforcement
PCI DSS 4.0 Global card payments In force Contractual + fines
State privacy laws (CCPA/CPRA + ~20 states) US states Expanding patchwork AG enforcement

AI Security EO (EO 14409) — deadline detail. The 30-day cluster (≈Jul 2, 2026) is the near-term catalyst: a federal AI cybersecurity clearinghouse for vulnerability scanning, validation, and patch coordination, plus CISA BODs mandating AI-enabled defenses. This is a demand pull for the AI-for-Security cohort (AI-native vulnerability discovery, validation, and remediation — the discover→validate→remediate loop AWS Continuum and the autonomous-pentest startups sell) and for exposure-management incumbents (Tenable and peers) positioning as clearinghouse private-sector partners. The 60-day "covered frontier model" benchmarking track (Aug 1, 2026) is the regulatory sibling of the BIS Fable/Mythos export-control directive (lifted Jun 30 – Jul 1, 2026 in a settlement that includes prerelease federal review of frontier models — see AI Security / 20f / Sovereign); it institutionalizes "AI cyber capability" as a national-security-graded model property, a Security-for-AI diligence axis. The 60-day deliverable, due Aug 1, 2026, differs in kind from the Jul 2 clearinghouse leg (Gold Eagle): the benchmarking methodology and the "covered frontier model" threshold are developed through a classified multi-agency process, so the specific criteria are not expected to be published, and the EO is explicit that the framework carries no mandatory licensing or pre-clearance — for developers and critical-infrastructure operators it functions as a voluntary early-access channel rather than a public rule (Wiley; Norton Rose Fulbright). Both 30-day legs have now landed: the CISA BOD leg on Jun 10, 2026 (BOD 26-04; see row above and note below), and the Treasury clearinghouse on Jul 14, 2026 — twelve days past the Jul 2 deadline — as the "Gold Eagle" initiative. Gold Eagle is managed by the Treasury Department with contributions from CISA, DHS, and the Defense Department alongside open-source software providers, critical-infrastructure operators, and industry; its intake platform, the Vulnerability Information and Coordination Environment (VINCE), operated in partnership with Carnegie Mellon University's Software Engineering Institute, accepts third-party reports of AI-discovered vulnerabilities for triage and patch prioritization. The White House said at launch that the system was already receiving vulnerability intelligence and prioritizing patches, and that closed-source frontier models — including Anthropic's Mythos — would be used for discovery. The design question raised before launch is now the program's live test: a HackerOne policy analysis argued the clearinghouse risks becoming "a committee that discovers more problems than it solves" unless it is built around patch triage and deployment rather than scanning coordination — making time-to-fix, rather than findings collected, the measure of whether Gold Eagle closes the finding-versus-fixing gap in AI-assisted vulnerability discovery. The EO's voluntary prerelease-review framework, by contrast, is already operating in practice: OpenAI held its GPT-5.6 family to a limited "trusted partner" preview from late June at the administration's request, and launched publicly on Jul 9, 2026 after additional federal testing — the framework's first observed end-to-end pass on a non-Anthropic model (TechCrunch, Jul 9 2026; detail in 20e). The Aug 1, 2026 deadline for the 60-day benchmarking leg has now passed without a published "covered frontier model" threshold or framework text, consistent with the classified multi-agency process and the EO's voluntary, no-mandatory-licensing design; the mechanism continues to run as an early-access channel demonstrated by the GPT-5.6 pass rather than as a public rule (Norton Rose Fulbright). Sources: White House EO (Jun 2, 2026), White House — Gold Eagle launch (Jul 14, 2026), CyberScoop (Jul 14, 2026), Cybersecurity Dive, Tenable Govt Affairs summary, CyberScoop — "Found fast, fixed slow" (Jul 8, 2026).

Personal liability (2026)

By 2026 the personal-liability story has bifurcated by region. In the EU it is strengthening — NIS2 imposes explicit management-body liability, DORA reaches through regulated firms to their critical ICT vendors, and these (with CMMC and HIPAA) transform vendor/third-party risk into a board-level fiduciary duty. In the US it has narrowed: the SEC's landmark SolarWinds case against the company and its CISO was dismissed with prejudice on Nov 20, 2025 (after the SDNY threw out most claims Jul 18, 2024), and the SEC's Cyber and Emerging Technologies Unit (CETU) — launched Feb 20, 2025 — now focuses on fraudulent disclosure rather than internal-controls theories. Net: directors/officers face rising personal exposure in Europe and honest-judgment protection (but continued liability for knowingly false disclosure) in the US. DORA has entered active supervision of incident-reporting and Register-of-Information deficiencies; NIS2 enforcement is arriving country-by-country as transposition completes (see 16b).

Demand implication: This is rocket fuel for TPRM, GRC, and continuous-compliance vendors (Vanta, Drata, OneTrust, SecurityScorecard, BitSight, UpGuard, Archer) and for vCISO/advisory services. Boards buying down personal liability = non-discretionary spend.

How regulation drives M&A

  1. Creates categories — GRC, TPRM, compliance automation, attestation, data residency all exist because of regulation.
  2. Forces buying — deadlines (NIS2 member-state milestones landing through 2026 — e.g., Italy's full security-measure compliance deadline by October 2026 (expected); the CMMC rollout — though its Phase 2 was suspended for review in Jul 2026, illustrating that these calendars can also slip) pull demand forward, lifting target revenue and multiples.
  3. Builds moats — certifications (FedRAMP, CMMC, SOC 2, ISO 27001) are barriers to entry that make certified vendors acquisition-attractive.
  4. Triggers consolidation — fragmented GRC/compliance tools roll up as enterprises seek single-pane platforms.
  5. Regionalizes markets — data-sovereignty rules favor local vendors, driving cross-border M&A and JV structures (see 14).

Sector-specific overlays

Global regulatory map (beyond the US & EU)

Cyber/data regulation has globalized. Most major economies now run GDPR-inspired privacy regimes plus cyber-specific resilience and incident-reporting laws. The result is a compliance patchwork that itself drives demand for GRC/TPRM platforms and regional vendors.

United States (federal + state)

No single federal privacy law; a sectoral patchwork (HIPAA, GLBA, FERPA) plus an expanding state quilt — CCPA/CPRA (California) and ~20 state privacy laws, each AG-enforced. Cyber-specific: SEC disclosure rules, CIRCIA (critical-infrastructure incident reporting), CMMC (defense). Trend: individual-executive-accountability theory narrowed in the US after the SolarWinds/CISO case was dismissed with prejudice (Nov 20, 2025), with SEC enforcement recalibrating toward fraudulent disclosure — the opposite trajectory from the EU, where personal/management liability is strengthening (NIS2, DORA).

Europe

The global standard-setter. GDPR (privacy, up to €20M/4%), NIS2 (resilience; transposition deadline was Oct 17, 2024, member states phasing obligations in through 2026 — e.g., Italy's full security-measure compliance deadline by Oct 2026 (expected; the Italian decree 138/2024 itself entered into force Oct 2024), and member-state first-audit deadlines now landing (e.g., Hungary Jun 30, 2026, expected); up to €10M/2%), DORA (financial sector, in force Jan 2025), the EU AI Act (risk-tiered AI rules phasing in 2025–2027; GPAI-provider enforcement and penalty powers became applicable Aug 2, 2026, while the high-risk regime is deferred to Dec 2, 2027), Cyber Resilience Act (security-by-design for connected products), and the Data Act. The UK (post-Brexit) runs UK GDPR, the Data (Use and Access) Act, NIS regulations, and NCSC guidance.

Asia-Pacific (a 2025–2026 wave of new rules)

Rest of world

GDPR-style laws now operate in Brazil (LGPD), South Africa (POPIA), Canada (PIPEDA / Law 25 in Québec), Gulf states (UAE, Saudi PDPL), and many others — familiar concepts (lawful basis, access/deletion rights, breach notification) with local scope and penalties.

Implication: The cross-border patchwork is the structural reason GRC, TPRM, data-residency, and compliance-automation vendors keep growing — and why data sovereignty (see 14) favors regional vendors and cross-border M&A.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.