U.S. and EU Cybersecurity Regulations Have Shifted
New reporting mandates took effect in Europe while the U.S. Department of Defense paused its CMMC Phase 2 rollout.
Updated on Oct. 7, 2026 in Cybersecurity

Live Poll
Should businesses maintain strict cybersecurity compliance despite regulatory delays or pauses in federal requirements?
International cybersecurity compliance frameworks faced significant changes as the EU activated new reporting mandates and the U.S. Department of Defense suspended its CMMC Phase 2 rollout. These actions reflect ongoing efforts to manage digital security obligations across major Western economies.
Why it matters
The U.S. military halted its CMMC Phase 2 transition to evaluate compliance costs for smaller suppliers, while the EU implemented strict new rules for vulnerability reporting. These shifts highlight the growing complexity for businesses navigating transatlantic digital security standards.
The EU Cyber Resilience Act mandates early warning notifications within 24 hours of incident discovery, followed by full notification within 72 hours and a final report within 14 days. Non-compliance risks penalties of up to 15 million euros.
The players
U.S. Department of Defense
This executive branch department is responsible for coordinating and supervising all agencies and functions of the government concerned directly with national security and the United States Armed Forces.
European Commission
Acting as the executive arm of the European Union, this institution is responsible for proposing legislation, implementing decisions, and upholding the union's treaties.
ENISA
The European Union Agency for Cybersecurity works to achieve a high common level of cybersecurity across the union by developing initiatives and supporting member states.
The details
DFARS Class Deviation 2026-O0025 prevents contracting officers from requiring new Level 2 or Level 3 assessments during the ongoing DOD pause. Simultaneously, the EU Cyber Resilience Act requires firms to use the ENISA Single Reporting Platform to disclose exploited vulnerabilities as part of new manufacturing sector oversight.
Timeline
July 8, 2026: EU referred Ireland, Spain, France, and the Netherlands to the Court of Justice regarding NIS2.
July 13, 2026: The U.S. Department of Defense suspended the transition to CMMC Phase 2.
August 15, 2026: The Netherlands brought its NIS2 transposition law into force.
September 11, 2026: EU Cyber Resilience Act reporting requirements took effect.
December 11, 2027: Broader EU Cyber Resilience Act requirements are scheduled to apply.
The Tech Race
The activation of the EU Cyber Resilience Act marks a significant leap in mandatory digital hygiene standards for manufacturers. This transition forces companies to move beyond voluntary practices, mirroring the broader arms race in hardening critical supply chains against sophisticated cyber threats.
Businesses operating in Europe must now integrate the ENISA reporting platform into their standard incident response workflows to avoid significant financial penalties. U.S.-based defense contractors can expect a temporary reduction in administrative burdens due to the suspension of new assessment requirements.
The takeaway
Organizations should prepare for a future defined by rapid, mandatory disclosure windows and stringent penalty structures. Maintaining robust internal audit logs will be essential for navigating the current regulatory shift in both the United States and European Union.
What happens next
Broader requirements for the EU Cyber Resilience Act are scheduled to go into effect on December 11, 2027.
Further reading
For more information on the evolving digital compliance landscape, visit the Cybersecurity section.
Source note: This article includes information reported by EMSNow.
Live Poll
Should businesses maintain strict cybersecurity compliance despite regulatory delays or pauses in federal requirements?







