The Business of Cyber Security

US Regulation

The United States has no omnibus federal cyber or privacy statute. Its rules are assembled from sectoral laws, an SEC disclosure regime enforced through litigation, defense-contracting clauses, and a growing set of state privacy laws — an enforcement-by-case, patchwork structure that contrasts with the EU's comprehensive statutes (16b). The SolarWinds case illustrates how the disclosure regime operates in practice: on Nov 20, 2025 the SEC agreed to dismiss, with prejudice, the remaining claims in its cybersecurity case against SolarWinds and its CISO Timothy Brown. When filed in Oct 2023, the case had been read as the opening of an era of personal liability for security executives, and the SDNY had already thrown out most of the claims on Jul 18, 2024. The structure of the system determines which sub-segments carry a demand tailwind and when.

The shape of the system

The United States has repeatedly declined to pass a comprehensive federal privacy or cybersecurity law. What exists instead is four overlapping layers, each generating its own compliance demand:

Layer Instruments Who it binds Demand it creates
Federal sectoral HIPAA/HITECH (health), GLBA (financial), FERPA (education), FTC Act §5 (unfair/deceptive) Regulated industries GRC, data protection, breach response, sectoral compliance tooling
Cross-cutting cyber SEC disclosure rules, CIRCIA (pending), TSA/pipeline directives, EO-driven federal-agency mandates Public companies, critical infrastructure, federal suppliers Incident response, disclosure governance, board reporting, attestation
Defense/national-security CMMC, DFARS 7012/7019/7020, ITAR/EAR export controls, FedRAMP Defense industrial base, federal cloud vendors Certification, managed compliance, GovCloud, assessment services
State quilt CCPA/CPRA + ~20 state privacy laws, NYDFS 500, state breach-notification statutes Anyone touching state residents' data Consent/DSAR automation, privacy ops, multi-state compliance

The structural consequence is that the US manufactures GRC and TPRM demand precisely because it is fragmented: a national vendor must satisfy 20 state regimes plus its sectoral and cross-cutting obligations simultaneously, which is exactly the problem compliance-automation platforms (Vanta, Drata, OneTrust) and TPRM vendors (SecurityScorecard, BitSight, UpGuard, Archer) are built to solve. For the CISO on the other side of that demand, the same fragmentation is a standing tax: a large share of budget and staff goes to satisfying overlapping regimes — much of it attestation and documentation — rather than to controls that measurably cut breach risk.

No federal center — four overlapping layers manufacture compliance demand The fragmentation itself is the demand engine for GRC, TPRM & compliance automation Federal sectoral HIPAA · GLBA · FERPA · FTC §5 industry-specific Cross-cutting cyber SEC disclosure · CIRCIA (pending) · TSA directives Defense / nat-sec CMMC · DFARS · FedRAMP · ITAR / EAR State quilt CCPA/CPRA + ~20 state laws · NYDFS 500 Non-discretionary compliance spend GRC · TPRM · compliance automation · attestation · vCISO the most reliable demand in cyber Source: statutes/rules as cited. Exhibit: The Business of Cyber Security.
The US has no single privacy or cyber law; the overlap of four regimes is precisely why multi-regime compliance tooling is a structural growth market. See [GRC & TPRM](03i-grc-tprm.md) and [Regulatory Calendar](16c-regulatory-calendar-catalyst.md).

The SEC disclosure regime and the enforcement recalibration

The SEC adopted its cybersecurity disclosure rules on Jul 26, 2023. They created two obligations for public companies: a Form 8-K Item 1.05 filing within four business days of determining a cybersecurity incident is material, and annual Item 106 disclosure of cyber risk-management processes and board governance. The rules put the CISO function inside the federal securities-disclosure framework for the first time, and the SolarWinds complaint (Oct 2023) — naming CISO Tim Brown personally — was widely read as a signal that security leaders now carried securities-law exposure.

That reading has been substantially walked back. The SDNY dismissed most of the SEC's SolarWinds claims on Jul 18, 2024, finding that "perspective and context are critical" and that the company's filings were not materially misleading; the SEC dismissed the rest with prejudice on Nov 20, 2025. In parallel, the SEC reorganized its enforcement apparatus, launching the Cyber and Emerging Technologies Unit (CETU) on Feb 20, 2025 (≈30 specialists, led by Laura D'Allaird, repurposed from the former Crypto Assets and Cyber Unit) with a stated focus on fraud against retail investors rather than technical-controls theories. US public-company cyber liability has narrowed to knowingly false disclosure rather than honest judgment calls — a contrast with the EU's strengthening of management-body liability under NIS2 (16b). (The SEC did extract settlements from four issuers — Unisys, Avaya, Check Point, Mimecast — on Oct 22, 2024 for understating SolarWinds-related exposure, so disclosure accuracy still has teeth.)

CIRCIA — the federal incident-reporting rule

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) was enacted in Mar 2022 and would require covered critical-infrastructure entities to report substantial cyber incidents within 72 hours and ransomware payments within 24 hours. CISA issued the proposed rule in Apr 2024, but the final rule has still not been published as of Jun 2026: the statutory Oct 2025 finalization deadline was pushed to May 2026, and a partial government shutdown forced CISA to postpone its CIRCIA town halls (originally Mar 9–Apr 2, 2026). Per a May 26, 2026 Federal Register notice, CISA reconvened the public town-hall meetings June 15–18, 2026 (general sessions + critical-infrastructure-sector groupings) — a signal the rulemaking is moving again, though still with no published effective date, and CISA has indicated it is examining options to streamline the NPRM (criticized for sweeping ~300,000 entities). The core 72-hour/24-hour obligations are not expected to change. Whenever CIRCIA finalizes, it would pull forward incident-response, detection, and reporting-automation demand across the 16 critical-infrastructure sectors.

CMMC — certification as a contracting gate

For the defense industrial base, compliance functions as a license to bid rather than a fine. The Cybersecurity Maturity Model Certification (CMMC) program rule (32 CFR Part 170) became effective Dec 16, 2024, and the DFARS contract clause (48 CFR final rule) took effect Nov 10, 2025, beginning a three-year phase-in that was to insert Level 1/Level 2 requirements into DoD solicitations and ramp to full application by 2028. On July 13, 2026, the Defense Department reversed course: two memoranda suspended the phased implementation — including the planned Nov 10, 2026 transition to Phase II, which would have required contractors and subcontractors handling controlled unclassified information (CUI) to pass Level 2 third-party (C3PAO) assessments — and placed all pending and future CMMC milestones "in abeyance until further notice." The Department opened a 60-day CMMC Reform Task Force review, framed around lowering barriers for small and non-traditional contractors and evaluating alternatives to the third-party assessment model, and issued a Request for Information whose comment window closed Aug 14, 2026 (noon ET), with Task Force recommendations expected around mid-September 2026 (Greenberg Traurig, Jul 15 2026). Baseline obligations are unchanged: contractors must still meet NIST SP 800-171 Rev. 2 controls via self-assessment, and FAR 52.204-21 and DFARS 252.204-7012 remain in force; program managers may still require Level 1 or Level 2 self-assessments, while solicitations carrying Level 2 (C3PAO) or Level 3 requirements are to be amended to remove them, and no CMMC waivers are granted during the review.

The suspension does not repeal the underlying demand — CUI-protection obligations persist — but it removes the near-term, deadline-driven catalyst that had been pulling third-party-assessment (C3PAO) and managed-compliance revenue forward toward the November 2026 cliff, replacing a fixed compliance clock with policy uncertainty for the tens of thousands of contractors and subcontractors in the defense supply chain. For the deal record the compliance-automation logic still holds: Fortreum (Gryphon-backed) acquired Kovr.AI (announced Apr 13, 2026), a compliance platform spanning FedRAMP, CMMC 2.0, DoD SRG and NIST CSF 2.0 that had itself achieved FedRAMP Moderate authorization — a tuck-in that buys a portable certification stack rather than rebuilding it — though the pace of CMMC-specific demand now depends on how the reform review resolves (16c). A second print landed a month into the suspension: Datavault AI agreed to acquire CyberCatch Holdings (announced Aug 14, 2026, US$94.5M all cash), a continuous-compliance and control-validation platform whose assessments map to NIST CSF 2.0, NIST SP 800-171, CMMC, ISO 27001, HIPAA and PCI DSS and whose customer base runs through the US defense supply chain. That a CMMC-mapped compliance asset changed hands while the Phase II clock was stopped indicates buyers are underwriting the durable multi-framework control-validation capability rather than the certification deadline alone (11).

The state quilt — 20 regimes and rising enforcement

In the federal vacuum, the states have built the privacy regime. As of 2026, 20 states have comprehensive consumer-privacy laws in effect (California's CCPA/CPRA plus, most recently, Indiana, Kentucky and Rhode Island joining in 2026), each with its own definitions, thresholds and AG enforcement. The compliance burden is multiplicative, not additive — a national business must reconcile 20 rulebooks at once. Two 2025–2026 shifts matter for demand:

The result is the same as at the federal level, only sharper: fragmentation is the demand engine. Each new state law and each headline penalty pushes more enterprises toward consent/DSAR automation and multi-state compliance platforms.

Contracting the private sector into offensive operations

A fifth instrument appeared in August 2026, and it creates demand by procurement rather than by compliance. A National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, signed Aug 12, 2026, directs the National Coordination Center to establish a federal program under which vetted US cybersecurity companies may conduct government-approved cyber surveillance and cyber effects operations against cyber-enabled transnational criminal organizations. It builds on Executive Order 14390 (Mar 6, 2026), Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens, and cites more than $20.8B in 2025 losses to cyber-enabled crime against Americans.

The mechanism is contractual: participating companies sign agreements with the Department of Justice or the Department of Homeland Security, executive directors from those departments approve every operations package in writing, participants post a bond or escrow of at least $1M forfeitable for non-compliance, and a classified annex governs deconfliction across law enforcement, State, the Treasury, War, Justice and the intelligence community. Because authority runs only through government direction and supervision, legal analyses of the memorandum have read it as stopping short of authorizing private-sector "hack back," with the approval process supplying the authorization for access that the Computer Fraud and Abuse Act otherwise withholds. Targets exclude criminal groups that are an institutional part of, or wholly operated under the direction of, a foreign government. In structure the review-and-approval design echoes NSPM-13 (Aug 2018), United States Cyber Operations Policy, which delegated authority for offensive operations conducted by the military.

Operating procedures, vetting requirements and approval processes are due within 60 days of signing — approximately Oct 11, 2026. Until those land, the eligibility criteria, indemnification and liability terms, and the definition of the non-compliance that triggers bond forfeiture are undefined, and the reauthorization status of the Cybersecurity Information Sharing Act of 2015, currently extended on a temporary basis, remains an open variable for prospective participants. The segment consequences are covered on Offensive Security & PTaaS; the milestone is tracked on 16c. (White House memorandum, Aug 12, 2026 · Wiley alert, Aug 14, 2026 · Cybersecurity Dive, Aug 13, 2026)

→ M&A implications

US fragmentation produces three durable deal patterns. (1) Category creation: GRC, TPRM, compliance automation, data-residency and attestation all exist because the US never centralized — and each remains structurally fragmented enough to roll up. (2) Certification-as-moat M&A: FedRAMP, CMMC and StateRAMP authorizations are slow, expensive barriers to entry, so a certified target is acquisition-attractive to a platform that wants instant federal access — the strategic logic behind compliance-platform tuck-ins like Fortreum–Kovr.AI. (3) Enforcement-timed demand: a finalized CIRCIA rule, a new state law's effective date, or a marquee penalty each pull demand forward into a nameable sub-segment, lifting target revenue and multiples on a knowable clock (16c).

Sources: SEC — dismisses SolarWinds/CISO case (Perkins Coie, Nov 2025) · Harvard Corp Gov — SolarWinds dismissed, what the U-turn signals · SEC — CETU launch (press release 2025-42) · Hunton — SEC fines four companies (Oct 2024) · CyberScoop — CISA pushes CIRCIA final rule to May 2026 · Federal Register — CIRCIA town halls (Feb 2026) · White & Case — CMMC final DFARS rule · EDUCAUSE — DFARS/CMMC effective Nov 10, 2025 · MultiState — 20 state privacy laws in effect 2026 · Smith Anderson — data privacy 2026: state enforcement · Solganick — cybersecurity services M&A update (Fortreum–Kovr.AI) · BusinessWire — Fortreum acquires Kovr.AI (Apr 13, 2026)


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.