top of page

When the Rules Won't Hold Still: The Rising Complexity of Compliance Regulation

11 minutes ago
5 min read

Ask a compliance leader what changed this year, and you’ll usually get a list of new requirements. That’s the wrong list to plan from. The more useful one is what moved. So far in 2026, four widely tracked compliance dates have moved, paused, or been repealed before taking effect. Not every one applies to your organization. The pattern behind them does, no matter which frameworks you’re tracking.


  • The updated HIPAA Security Rule remains a proposed rule. HHS’s projected final action date slid from May 2026 to July 2027, and the rulemaking moved to long-term actions, the category HHS uses for rules it doesn’t expect to act on within a year.

  • CMMC Phase 2, scheduled for November 10, 2026, was suspended on July 13, pending a 60-day reform review. Contracting officers were told to stop inserting Phase 2 requirements and amend active solicitations.

  • CIRCIA, the federal incident-reporting rule for critical infrastructure owners and operators across sectors like energy, healthcare, financial services, and water, passed its statutory October 2025 deadline without a final rule. Its projected publication slipped again this year, from May to September 2026. No reporting obligation exists today.

  • The Colorado AI Act was repealed and replaced before its effective date arrived. Its successor pushes obligations to January 1, 2027 and drops the duty of care, impact assessments, and risk management program.


Add the SEC, where the 2023 cyber disclosure rules remain in force while a petition to rescind the 8-K incident disclosure item sits unanswered and the SolarWinds action was dismissed with prejudice last November.


Counting frameworks was never the hard part. The regulatory calendar itself has become unreliable as a planning tool, and an organization that manages compliance as a sequence of dates is working from a plan that keeps changing underneath it.


What hardened while the headlines moved

When proposed rules stall, it’s easy to read the pause as pressure coming off. In reality, the opposite happened. Requirements already on the books got harder to satisfy, and the penalties for missing them got steeper and arrived faster than before.


The grace-period era in state privacy law is closing. Right-to-cure provisions expired in Minnesota in January and New Jersey on July 15. These states joined California, Colorado, Connecticut, Delaware, Montana, New Hampshire, and Oregon, where similar provisions had already been eliminated. Roughly 20 comprehensive state privacy laws are now enforceable, with more expected in 2027 and 2028.


Penalties climbed with them. California’s General Motors settlement in May reached $12.75 million, over four times the California Consumer Privacy Act record set three months earlier. The earlier settlement turned on the gap between what a company promised in its privacy notice and opt-out controls and what its systems actually did. GM’s went further. It was the state’s first data minimization case, faulting the retention and sale of driving and location data long past the purpose that justified collecting it.


Elsewhere, deadlines passed without fanfare. Every future-dated requirement in PCI DSS 4.x has been mandatory since March 2025: script inventory on payment pages, semiannual scope confirmation for service providers, and MFA for all non-console access into the cardholder data environment are ordinary audit findings, not roadmap items. New York’s amended DFS Part 500 finished phasing in last November. It now extends MFA to any individual accessing any information system owned by a covered entity, under an annual certification that the highest-ranking executive and the CISO both must sign.


A clear pattern shows up here. The rules that moved were the ones under active political contest and heavy public comment. The technical control mandates and enforcement mechanics, the less visible stuff, quietly took effect on schedule. Colorado went further than a pause: its replacement law drops obligations the original imposed. But that fight was over a novel duty, not over controls organizations already operate. Reversals happen at the top of the stack. The floor keeps rising.


Why the requirement is the wrong unit of measure

Most compliance programs are organized around requirements: a HIPAA workstream, a PCI program, a CMMC initiative, each with its own owner, evidence, and calendar. That structure works until a date moves. Then the effort stalls, and finished work waits on a rule that may not arrive.


It stalls because the unit is wrong. Asset inventory, network segmentation, MFA, encryption, logging, vendor oversight, and incident response appear in nearly every security regulation. An organization that maps to each framework separately ends up building the same controls again and again, paying for them several times over. Or, worse, it treats each framework’s checklist as the finish line and still can’t answer the one question the audit committee actually asks: where are we exposed?


CMMC illustrates the difference. The July suspension only paused the certification tranche: third-party Level 2 and government-led Level 3 assessments. DFARS 252.204-7012 and its 72-hour reporting clock, NIST SP 800-171 Rev. 2, and SPRS scoring are unchanged, as are the requirements for self-assessments and annual affirmations. A contractor that treated CMMC as its own checklist, organized around the certification date instead of the underlying controls, now has a stalled program and the same obligations it had before. Compare that to a contractor that had already folded those same controls into a broader crosswalk. NIST SP 800-171 was never siloed to CMMC in the first place, so nothing was lost when the date moved, and that contractor is now in a stronger position against the False Claims Act, the more immediate exposure while certification is deferred.


What to do about it

Five moves make a compliance program durable against a calendar that will not hold still.

  1. Build a control-based crosswalk. Map your obligations to one shared control catalog (e.g., NIST SP 800-53 or ISO 27001 Annex A) that spans every framework you’re subject to, so a new state law becomes a delta against controls you already operate, not a brand-new build.

  2. Separate what is binding from what is projected. A Unified Agenda date is an agency's estimate of when a rule might publish, not a date anything becomes required. Track the two separately, and don’t treat projections as deadlines.

  3. Assume no cure period. Where the grace period has expired, the first notice you receive may be the enforcement action. Test the mechanics regulators typically probe, such as opt-out signals that work, notices that match system behavior, and requests that reach downstream vendors.

  4. Inventory the obligations that arrive through vendors. New requirements rarely enter through a procurement decision. They arrive when a platform you already run adds a feature, or a renewal updates terms by reference. Treat renewal review as a compliance control.

  5. Make evidence continuous. Evidence assembled in the weeks before a filing is the most common reason a sound program fails an examination. Automate evidence capture at the control level (configuration exports, access logs, training records, vendor attestations) on a recurring schedule, and assign an owner to each control who reviews it whether or not an audit is on the calendar. Do that consistently and most of the gaps in this article close themselves.


You don’t have to predict what regulators do next. You need a program whose value doesn’t depend on guessing right.

Comments


bottom of page