articles

Imperative vs. Important - PQC Compliance

Sep 4, 2026

Why read this: Three September policy clocks show that cybersecurity reporting is becoming an operating capability, not a legal afterthought.

The Imperative is what changed and requires a reaction now. The Important is what remains true after the headline fades.

Carl's Corner is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

The Imperative

Europe’s connected-product reporting clock starts next week

Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. An early warning is due within 24 hours of awareness, followed by a fuller notification within 72 hours. The rule reaches products already made available in the European Union market, not only products introduced after the Cyber Resilience Act becomes broadly applicable in December 2027 (European Commission reporting guidance; European Commission legislative summary).

Business impact: A company can no longer assume that product security, legal review, and incident response may operate on separate clocks. If the first day is spent discovering which products, customers, and jurisdictions are affected, the reporting window is already being consumed.

The United States critical-infrastructure rule is scheduled for September

The federal regulatory agenda schedules the final Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA, rule for September 2026. The rule is not yet effective, and the Cybersecurity and Infrastructure Security Agency explicitly says organizations are not subject to CIRCIA reporting until the final rule takes effect (Reginfo.gov regulatory agenda; CISA CIRCIA frequently asked questions).

Business impact: The prudent move is preparation without pretending a proposed timetable is already a mandate. Critical-infrastructure organizations should use the remaining uncertainty to test classification, escalation, evidence retention, and executive decision paths.

A United States information-sharing authority reaches another sunset

The Cybersecurity Information Sharing Act of 2015 currently runs through September 30, 2026. Congress may extend it again, but the present authorization date matters because the statute supplies protections and procedures that support voluntary sharing of cyber-threat indicators (Congressional Research Service).

Business impact: Security teams should know which sharing relationships and playbooks depend on the statute, who will monitor the legislative outcome, and what operating guidance changes if Congress acts late or temporarily.

The Important

Build a reporting control plane

Compliance calendars are necessary, but they are not sufficient. A reporting obligation becomes operational only when the organization can identify the affected product or service, recognize a triggering event, start the correct clock, preserve defensible evidence, and place the decision with a named owner.

Discovery: Map products, services, jurisdictions, reporting regimes, contracts, and information-sharing relationships. Connect each obligation to the technical systems and business owners that can supply facts.

Agility: Rehearse the first 24 and 72 hours. Test whether product, security, legal, communications, and leadership teams can classify an event and produce an accurate report without waiting for perfect information.

Governance: Assign authority for starting the clock, approving the submission, coordinating regulators, and updating customers. Record the decision trail so the organization can demonstrate what it knew, when it knew it, and why it acted.

The durable lesson is simple: reporting readiness is a system. Policy sets the clock, but operating design determines whether the organization can meet it.

Three questions for the board

1. Which of our products and services fall within the European Union’s “products with digital elements” scope, and can management show the evidence behind that determination?

2. Can our teams produce an initial regulator-ready account of a material cyber event within 24 hours, including known facts, unknowns, owners, and next actions?

3. Who owns the cross-jurisdiction reporting matrix, and when was the full process last exercised rather than merely reviewed?

Carl’s Corner translates technology change into board-level decisions and practical operating questions.

#Cybersecurity #CyberResilienceAct #CIRCIA #Policy #Governance #IncidentResponse #ConnectedProducts

Carl's Corner is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Enjoyed this? Subscribe for more on Substack.