UNITED STATES
A New Federal Playbook for Cyber Risk
CMMC Final Rule
In November 2025, the US Department of Defense (DoD) issued the transformative Cybersecurity Maturity Model Certification (CMMC) final rule, a pivotal development in federal cyber compliance. This rule establishes a direct correlation between contract eligibility and an organization’s demonstrated cybersecurity maturity, categorized into three distinct levels based on the sensitivity of federal contract information and controlled unclassified information.
The implications are extensive, as the rule mandates audit and certification requirements that flow through the defense industrial base. This means that subcontractors and suppliers now face increased exposure and accountability, ensuring that even the smallest players are fortified against cyber risks. With inaccuracies in cybersecurity certifications under scrutiny, particularly through the lens of the False Claims Act, entities must now place a significant emphasis on their documentation, internal controls, and readiness for audits.
DOJ Data Security Program
In a parallel movement, the US Department of Justice (DOJ) has rolled out its Data Security Program under Executive Order 14117, targeting data transactions involving nations deemed as “countries of concern.” This program differentiates between prohibited and restricted transactions based on the nature of the data—sensitive personal data versus US government-related data—imposing rigorous security and governance obligations on covered entities.
As cybersecurity regulations increasingly intertwine with national security imperatives, organizations are compelled to re-evaluate their cross-border data streams and vendor relationships. This assessment must now consider both privacy and geopolitical risks, fortifying their operational frameworks against potential vulnerabilities.
Incident Reporting Momentum – CIRCIA and Sector-Specific Rules
As we navigated through 2025, federal momentum surrounding incident reporting picked up, intensified by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This legislative push, alongside the Cybersecurity and Infrastructure Security Agency’s (CISA) rulemaking efforts, has expanded existing sector-specific reporting obligations. Organizations may soon be required to report substantial cyber incidents within a tight 72-hour window, while ransomware payments must be disclosed within 24 hours.
These regulatory shifts demand that organizations refine their internal workflows for incident reporting and escalate the appropriate thresholds for actions. Moreover, a focus on cross-functional collaboration is essential to ensure that reporting is timely and comprehensive, addressing overlapping regulatory demands.
NIST CSF 2.0 and Incident Response Guidance
The release of NIST’s Cybersecurity Framework 2.0 and its accompanying incident response guidance clarifies federal expectations regarding governance-driven cybersecurity programs. The updated framework advocates for a holistic approach, necessitating that incident response plans incorporate the insights of legal, compliance, communications, and executive leadership teams alongside technical experts.
This thorough integration emphasizes the importance of maintaining documented playbooks, delineating decision-making authority, and coordinating with third-party service providers. Organizations are encouraged to view incident response not as a reactive measure but as a strategic function integral to their broader cybersecurity posture.
Emerging DOJ Criminal Enforcement Posture
The year 2025 also signaled a shift in the DOJ’s enforcement posture. The federal government displayed an increased readiness to pursue criminal investigations into ransomware, insider-related cybercrimes, and conspiracies. Notable indictments involving sophisticated ransomware syndicates underscore issues such as credential misuse, privileged access, and failures in internal controls.
Such high-profile cases serve as a stark reminder to organizations about the pressing need for robust identity and access management practices, vigilant monitoring of insider risks, and incident response strategies that anticipate potential regulatory, civil, and criminal liabilities post-event.
The Rise of State-Driven Cyber Governance
CPPA Rules on ADMT and Cybersecurity Audits
On the state level, the California Privacy Protection Agency (CPPA) finalized impactful regulations regarding automated decision-making technology (ADMT), cybersecurity audits, and risk assessments in July 2025. These regulations elevate compliance requirements considerably, mandating heightened transparency, meaningful human involvement in automated decisions, and ongoing assessments when risk levels are elevated.
The need for formal cybersecurity audits and reporting on high-risk activities means that organizations must strengthen their governance protocols and documentation processes, extending well beyond basic compliance checks.
State AG Activity in Privacy and Cybersecurity Enforcement
State attorneys general are taking an assertive role in privacy enforcement, actively pursuing cases relating to digital tracking technologies, health data protections, and online consent mechanisms. Their focus has begun shifting towards deceptive practices in data disclosures, underscoring the importance of aligning cybersecurity with public-facing representations. Compliance now extends beyond reaction to data breaches—it encompasses proactive management of public perceptions and consumer expectations.
New State Privacy Laws Take Effect
With new comprehensive privacy statutes emerging in various states like Tennessee, Minnesota, and Maryland, we witness a further acceleration towards a multistate compliance model. Nearly half of U.S. states have adopted their own privacy laws since California’s groundbreaking statute in 2018. However, these laws are not uniform, presenting a patchwork of requirements concerning security safeguards, risk assessments, and individual rights. This diversity complicates compliance for organizations that operate across multiple states, necessitating the development of scalable, adaptable governance frameworks.
Texas AG Enforcement and Texas ‘Mini-TCPA’
Recent enforcement actions in Texas illustrate the growing scrutiny on data practices connected to communications and marketing, epitomized by the state’s “Mini-TCPA.” These developments signal an increasing risk for companies in telecom, advertising, and digital engagement sectors, where data collection and automated outreach intersect with evolving privacy and cybersecurity obligations.
Operational Implications
The cumulative effect of state legislative developments throughout 2025 has significantly heightened the documentation, assessment, and governance burdens on organizations, particularly those navigating multiple jurisdictions. Organizations are faced with the challenge of coordinating overlapping audit, risk assessment, and disclosure obligations across diverse regulatory environments.
As we step into 2026, organizations should prepare for an evolving regulatory landscape that prioritizes integrated privacy and cybersecurity frameworks capable of scaling across jurisdictions. Rather than focusing solely on isolated compliance efforts, regulators are expected to scrutinize the coherence and operational integrity of overarching cybersecurity and privacy programs.
Access the Full Cybersecurity & Privacy Report
For a comprehensive dive into jurisdictional analyses, sector-specific compliance implications, litigation developments, and practical guidance on navigating the ever-evolving landscape of cyber and privacy enforcement in 2026, download the full report.

