01 / コンプライアンスダイジェスト
コンプライアンス ニュースダイジェスト
規制変更、フレームワークの更新、執行措置、コンプライアンス期限を重要度別にまとめた月次サマリーを自動生成しています。
Top Floor
Compliance Digest: June 2026
2 regulatory events this month — 1 critical, 1 important, 0 informational
Critical (1)
(Projected) CMMC Phase 2: All DoD Contracts Require Certification
CMMC Phase 2 is projected to expand certification requirements to all DoD contracts involving CUI, requiring third-party C3PAO assessments for Level 2 certification. This phase represents the full operationalization of CMMC, where every defense contractor handling CUI must hold a valid certification from an accredited C3PAO, not merely a self-assessment.
Important (1)
(Projected) CISA Secure by Design Principles Expected in Federal Acquisition Requirements
CISA is expected to formalize Secure by Design principles as requirements in federal acquisition regulations by mid-2026. Building on the voluntary pledge program that enrolled over 250 software manufacturers, the projected rule would require software vendors selling to federal agencies to attest compliance with Secure by Design principles, including elimination of default passwords, MFA by default, evidence of vulnerability management maturity, and published vulnerability disclosure policies.
Generated by Top Floor Regulatory Radar. View full event details
このダイジェストをメールで受け取る
毎月のコンプライアンスニュースダイジェストをビジネスメールでお届けします。ノイズなしに規制変更の最新情報を把握できます。