Edition

InfoSec GRC Brief | August 27, 2026

Mariah Brooks

Updated Aug 27, 2026 Read Time 10 min

InfoSec GRC Brief | August 27, 2026:
CMMC Task Force Takes On CUI Markings, EU Cyber Resilience Act Reporting Begins, and CareCloud Breach Impacts 3.7 Million Patients

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the second half of August 2026.

Let’s get into it.

Regulatory & Compliance Updates

EU Cyber Resilience Act Reporting Obligations Begin September 11

Article 14 of the Cyber Resilience Act takes effect on September 11, 2026. Once the requirement is effective, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs through a single reporting platform, on a 24-hour early warning, 72-hour triage report, and 14-day final report timeline.

Before the September 11 deadline, manufacturers and importers selling into the EU can:

  • Name the reporting owner
  • Map which products fall in scope
  • Rehearse the 24-hour notification path

Harmonized standards that translate the requirements into testable criteria are expected around October 30, 2026, with full product conformity and CE marking to follow on December 11, 2027.

Because reporting arrives first, the burden lands on incident response well before any product redesign is due. Now, with the 24-hour clock starting at awareness, triage, legal review, and notification must compress into the same day.

Read more →

Inconsistent CUI Marking Inflates CMMC Scope

Inconsistent controlled unclassified information (CUI) markings forces DoD contractors to over-scope their compliance boundaries, according to industry groups advising the CMMC Reform Task Force. When markings arrive incomplete or contradictory, contractors pull more systems into scope than the contract requires and pay for controls that produce no added security.

Now, the task force is expected to recommend CUI identification standards mid-September. Since scoping decisions drive the cost of almost every CMMC assessment, a marking standard would change the math on assessment budgets across the defense industrial base.

Until the guidance lands, contractors and assessors can document their current scoping rationale to make rescoping straightforward. As a reminder:

  • CMMC Phase I self-assessment and CUI safeguarding obligations remain in place.
  • CMMC Phase II certification stays suspended.

Read more →

Contractor Confidence in CMMC Self-Assessments Falls

Only a third of contractors believe they are 80% or more ready for a CMMC certification review, according to a CyberSheath report released this month. Even as reported scores climbed, defense contractor confidence in self-assessment accuracy dropped for the second year in a row.

Paired with falling confidence, the rising scores point to an evidence problem. Often, it’s only after an assessor asks for documentation do contractors recognize that the number in their SPRS submission may not actually hold up under review.

With CMMC Phase II assessments suspended, defense contractors can use the pause to independently validate self-assessment evidence and close any gaps between the score and the proof.

Read more →

NIST Publishes SP 1353, AI Quick-Start Guide for CSF 2.0

On August 19, 2026, NIST published NIST SP 1353, a quick-start guide with structured AI prompts for building NIST CSF 2.0 analysis, planning, and monitoring artifacts. For organizations interested in responding, the comment period runs until October 15.

Notably, it’s the first NIST publication that treats AI prompting as a documented method for producing GRC work products. By providing sample scenarios and prompts usable in their draft form, NIST 1353 gives teams a reference point when auditors ask how AI-assisted analysis was generated.

Before the October deadline, GRC teams running CSF-aligned programs may want to test the draft prompts against a live scenario and submit comments.

Read more →

GRC Strategies

CISA Red Team Compromises Two Networks

On August 25, 2026, CISA published advisory AA26-237A documenting two simultaneous red team assessments run with similar tradecraft against critical infrastructure organizations. Both reached full domain compromise:

  • One security operations center triaged the first alerts and isolated three workstations within 10, 2, and 20 minutes, forcing the engagement into an assume breach model.
  • At the other, the same activity generated medium- and low-severity alerts that staff never actioned, buried under thousands of higher-severity false positives.

When comparable tradecraft produce opposite outcomes, it isolates detection and response as the variable. Theoretically, both organizations could have documented the same controls and passed the same paper review. But the one that actually caught the intrusion? It was a water utility — the same sector the FBI and EPA recently warned about over exposed controllers.

Now, threat pressure appears to build detection capability faster than control documentation does. Security leaders can run the advisory’s detection opportunities against current logging coverage, measure how many alerts an analyst reviews in a shift, and record the response-time gap as an assessment finding.

Read more →

NCSC Issues Interim Controls for Agentic AI

On August 20, 2026, the UK’s National Cyber Security Centre released interim guidance for organizations running autonomous AI agents. Recommended controls include:

  • Sandboxed execution environments
  • Distinct short-lived credentials per agent
  • Mandatory human oversight at defined decision points

Interim guidance from a national authority tends to become the reference standard auditors reach for before formal guidance arrives. But agents already deployed with standing credentials and broad permissions now sit outside that baseline. Still, teams deploying agentic AI can:

  • Inventory every agent with system access
  • Unscope its credentials down to short-lived and agent-specific
  • Confirm the autonomy granted still matches documented risk tolerance

Read more →

Black Hat 2026 Puts AI in the Supply Chain

Trojanized AI “skills” were downloaded 1.7 million times, according to researchers at Black Hat USA 2026. The result is a supply-chain vector that did not exist a year ago. Other sessions revealed:

  • AI compressing the timeline from vulnerability disclosure to working exploit.
  • Human-led research still outperforming fully autonomous approaches.

Now, AI tooling sits on both sides of the equation. It shortens the window defenders have to patch, and the packages feeding AI workflows carry the same dependency risk as any other third-party code.

As organizations prepare for 2027, risk teams may want to consider adding AI extensions, skills, and model packages to the third-party inventory, and factor faster exploit timelines into risk assessments and patch service levels.

Read more →

Cyber Incidents & Risk Implications

CISA Sets 3-Day Zimbra Patch Deadline

On August 21, 2026, CISA added CVE-2026-73570 (CVSS 8.9) to its Known Exploited Vulnerabilities catalog. A command-injection flaw in the SNMP notification component of Zimbra Collaboration Suite reachable through crafted SMTP requests. Under Binding Operational Directive 26-04, the publication also set a three-day federal remediation deadline of August 24, 2026.

Between August 20 and August 22, the Shadowserver Foundation and CERTA Polska tracked compromised internet-facing instances climbing from roughly 155 to at least 274, with more than 8,200 servers still unpatched. However, no threat actor has been publicly attributed to the campaign as of today’s date.

Because Zimbra hosts mail, calendars, and archived correspondence, a compromise reaches the records that legal holds and regulatory disclosures depend on. Fortunately, Version 10.1.20 closes the flaw. Patch first, then assume compromise on any instance exposed before the fix and hunt for injected commands and unauthorized mailbox access.

Read more →

ATF Confirms Major Incident

On August 26, 2026, the Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident affecting a standalone system that held criminal investigation records. After the Justice Department designated it a major incident, the Qilin ransomware group listed the agency on its leak site.

Three federal law enforcement agencies have now disclosed compromises within six months, following the FBI’s Digital Collection System Network and the DHS Homeland Security Information Network. The common theme? Standalone systems are rarely as isolated as the label suggests. Even as admin accounts, vendor remote access, and software update connections get added over the years, the label never changes.

To prevent these types of attacks, risk teams can:

  • Identify every system classified as standalone or isolated
  • Test that classification against real administrative and network access
  • Revisit internal incident classification thresholds against federal major-incident criteria

Read more →

FBI and EPA Warn of PLC Attacks on Water Utilities

On July 30, 2026, the FBI and EPA issued a joint public service announcement reporting that water and wastewater utilities in at least seven states had logged incidents since July 27. By August 6, follow-on reporting extended the campaign to at least 12 states, with more than 30 Minnesota systems targeted across a single weekend in late July. However, neither agency has attributed the activity to a specific actor yet.

Attackers reached internet-facing Rockwell Automation MicroLogix 1100 and 1400 controllers, then changed IP addresses and passwords to strip operators of monitoring and control. So far, reported effects of the attacks include pressure loss and flooding.

Updated July 22, CISA advisory AA26-097A documents Iranian-affiliated exploitation of the same controller families and now extends to Schneider Electric Modicon M340 and Siemens S7-1200 devices. Although researchers have drawn a tentative link between the two campaigns, federal officials have not confirmed one yet.

In the meantime, utilities, manufacturers, and other operators of industrial control systems can:

  • Inventory internet-facing controllers
  • Confirm each one sits behind a gateway or firewall
  • Query logs for traffic on ports 44818, 2222, 102, and 502

AA26-097A also recommends returning Rockwell controllers to the run position on the physical mode switch.

Read more →

CareCloud Breach Grows to 3.7 Million Patients

On August 17, 2026, Electronic health record vendor CareCloud reported to HHS that a March intrusion actually affected 3,756,469 individuals, up from the roughly 345,000 disclosed to state regulators on August 3. The company also filed an SEC Form 8-K on March 24, five months before the federal breach filing landed.

According to the report, attackers held access for about eight hours and reached one of six AWS-hosted EHR environments on March 16. The result is the fifth-largest health data theft of 2026. However, no group has claimed the intrusion.

But the timeline is the part worth noting here. An eight-hour incident took five months to reach the HHS portal, and the count moved by an order of magnitude just two weeks after the first public number. As a result, provider organizations relying on CareCloud learned the scope of their own patient exposure from a federal database instead of hearing it from their vendor.

TPRM owners can map which vendors hold regulated data, confirm that breach-notification timelines sit in the contract rather than in vendor discretion, and move those relationships onto continuous monitoring.

Read more →

SaltyCloud Research

NIST 800-53 Multi-Framework Crosswalk

A filterable workbook mapping every NIST 800-53 control to CSF 2.0, SOC 2, ISO 27001, 800-171, and HIPAA, with implementation status, assessment objectives, and evidence tracked in one place.

Access the Crosswalk →

NIST 800-171: Complete Guide [2026]

Everything there is to know about NIST SP 800-171, its 110 requirements, who must comply, and how it relates to other frameworks. It remains the control set behind Phase I self-assessments during the CMMC suspension.

Read the Guide →

Conducting an IT Security Risk Assessment: Complete Guide

How to run an assessment that shows whether security controls operate effectively and which vulnerabilities and requirements matter most.

Read the Guide →

Future News

Upcoming GRC news and deadlines to watch for over the next few months.

August 2026 | HIPAA Privacy Rule final rule

The HHS regulatory agenda still targets August 2026 for the final Privacy Rule. First proposed in 2020, the rule changes cover individual access rights, care coordination disclosures, and administrative burden reduction. Separately, the HIPAA Security Rule overhaul moved to the long-term agenda with July 2027 as the revised target.

September 2026 | CIRCIA final rule

The Unified Agenda of Federal Regulatory Actions lists September 2026 for the final CIRCIA incident reporting rule. The new deadline comes after CISA missed the statutory October 2025 deadline and a revised May 2026 target. Under the proposed rule, which reached around 30,000 entities across all 16 sectors, covered critical infrastructure entities would report incidents within 72 hours and ransom payments within 24 hours.

September 2026 | CMMC Reform Task Force recommendations

Following the industry Request for Information that closed on August 14, 2026, the CMMC task force is expected to deliver findings to the DoD CIO around September 13. The CUI marking standard sits inside that scope, but a public determination may not arrive until October. Until then, CMMC Phase II remains suspended.

October 2026 | EU CRA harmonized standards

The technical standards that translate CRA requirements into testable criteria are expected in late October, seven weeks after the reporting obligations begin.

January 2027 | New state privacy laws

State privacy laws in Louisiana and Oklahoma are set to take effect on January 1, 2027, with Alabama following on May 1, 2027. Delaware and Connecticut amendments also land on January 1, narrowing existing exemptions.

January 2027 | Colorado’s automated decision-making law

On May 14, 2026, Governor Polis signed SB 26-189, repealing the 2024 Colorado AI Act. Replacing it is a narrower, disclosure-focused framework covering automated decision-making technology used in consequential decisions. Rule-making on implementation details remains open, and enforcement centralizes with the state attorney general.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

InfoSec GRC Brief | August 13, 2026: CMMC Comment Period Closes, CA Launches DROP Platform, and CISA Sets Cisco Firewall Patch Deadline Welcome back...

Edition
09.03.2026

InfoSec GRC Brief | July 30, 2026: HHS Delays HIPAA Overhaul, FTC Issues $2.25M Fine, and EU Defers AI Act Deadline Welcome back to the InfoSec GRC...

Edition
09.03.2026

InfoSec GRC Brief | July 15, 2026: DoD Suspends CMMC Phase 2, Treasury Sanctions VPN Provider, and Zero-Day Exploit Hits 100+ Companies Welcome back...

Edition
09.03.2026
The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo