U.S. and EU Cybersecurity Regulations Have Shifted

New reporting mandates took effect in Europe while the U.S. Department of Defense paused its CMMC Phase 2 rollout.

Updated on Oct. 7, 2026 in Cybersecurity

Isometric editorial illustration of a single industrial server rack, representing the structural nature of transatlantic cybersecurity compliance regulations.
New cybersecurity mandates have taken effect across the European Union, while the U.S. Department of Defense has paused its CMMC Phase 2 rollout to re-evaluate compliance standards. AI Illustration. Upload story photo >

Live Poll

Should businesses maintain strict cybersecurity compliance despite regulatory delays or pauses in federal requirements?

International cybersecurity compliance frameworks faced significant changes as the EU activated new reporting mandates and the U.S. Department of Defense suspended its CMMC Phase 2 rollout. These actions reflect ongoing efforts to manage digital security obligations across major Western economies.

Why it matters

The U.S. military halted its CMMC Phase 2 transition to evaluate compliance costs for smaller suppliers, while the EU implemented strict new rules for vulnerability reporting. These shifts highlight the growing complexity for businesses navigating transatlantic digital security standards.

The EU Cyber Resilience Act mandates early warning notifications within 24 hours of incident discovery, followed by full notification within 72 hours and a final report within 14 days. Non-compliance risks penalties of up to 15 million euros.

The players

U.S. Department of Defense

This executive branch department is responsible for coordinating and supervising all agencies and functions of the government concerned directly with national security and the United States Armed Forces.

European Commission

Acting as the executive arm of the European Union, this institution is responsible for proposing legislation, implementing decisions, and upholding the union's treaties.

ENISA

The European Union Agency for Cybersecurity works to achieve a high common level of cybersecurity across the union by developing initiatives and supporting member states.

The details

DFARS Class Deviation 2026-O0025 prevents contracting officers from requiring new Level 2 or Level 3 assessments during the ongoing DOD pause. Simultaneously, the EU Cyber Resilience Act requires firms to use the ENISA Single Reporting Platform to disclose exploited vulnerabilities as part of new manufacturing sector oversight.

Timeline

  1. July 8, 2026: EU referred Ireland, Spain, France, and the Netherlands to the Court of Justice regarding NIS2.

  2. July 13, 2026: The U.S. Department of Defense suspended the transition to CMMC Phase 2.

  3. August 15, 2026: The Netherlands brought its NIS2 transposition law into force.

  4. September 11, 2026: EU Cyber Resilience Act reporting requirements took effect.

  5. December 11, 2027: Broader EU Cyber Resilience Act requirements are scheduled to apply.

The Tech Race

The activation of the EU Cyber Resilience Act marks a significant leap in mandatory digital hygiene standards for manufacturers. This transition forces companies to move beyond voluntary practices, mirroring the broader arms race in hardening critical supply chains against sophisticated cyber threats.

Businesses operating in Europe must now integrate the ENISA reporting platform into their standard incident response workflows to avoid significant financial penalties. U.S.-based defense contractors can expect a temporary reduction in administrative burdens due to the suspension of new assessment requirements.

The takeaway

Organizations should prepare for a future defined by rapid, mandatory disclosure windows and stringent penalty structures. Maintaining robust internal audit logs will be essential for navigating the current regulatory shift in both the United States and European Union.

What happens next

Broader requirements for the EU Cyber Resilience Act are scheduled to go into effect on December 11, 2027.

Further reading

For more information on the evolving digital compliance landscape, visit the Cybersecurity section.

Source note: This article includes information reported by EMSNow.

Live Poll

Should businesses maintain strict cybersecurity compliance despite regulatory delays or pauses in federal requirements?