The 24-Hour Clock Started This Morning (09/11/2026)

September 11, 2026
The 24-Hour Clock Started This Morning (09/11/2026)
Key Intel / TL;DR
  • Manufacturers must now report actively exploited flaws and severe incidents to ENISA within 24 hours under the EU Cyber Resilience Act.
  • The CFTC will grant declinations and penalty reductions to firms that self-report, cooperate, and remediate.
  • The FDA published a discussion paper seeking feedback on how it might regulate generative AI medical devices.
  • HHS released version 3.7 of its Security Risk Assessment Tool.
  • Central Maine Medical Center and Susan B. Allen Memorial Hospital both settled data breach class actions.

A 24-hour reporting obligation is a different kind of rule from the ones most compliance calendars are built around. It cannot be satisfied by a quarterly process or a committee, because the clock starts at the moment somebody in engineering notices something, and it ends before most organizations have finished deciding who to tell internally.

Top 5 Critical Compliance Alerts

1. The Cyber Resilience Act’s Reporting Obligation Is Live

Manufacturers placing products with digital elements on the EU market must now disclose actively exploited vulnerabilities and severe security incidents through ENISA’s new reporting platform within 24 hours. We covered the Commission’s scope guidance earlier this week, and this is the operative half of it, since the guidance describes who is covered and this describes what happens the first time something goes wrong. A company that has not decided in advance who makes the disclosure call will spend most of the window finding that person. The Register has the mechanics.

Operator Note: Name the person who can authorize a 24-hour disclosure, name their backup, and put both names somewhere your on-call engineer can find at two in the morning.

2. The CFTC Will Reward Self-Reporting With Declinations

The Commodity Futures Trading Commission’s Division of Enforcement announced a policy granting declinations and penalty reductions to market participants who invest in meaningful compliance programs, voluntarily self-report misconduct, and remediate it. Policies of this shape only change behavior when firms believe the reduction is real, which means the first few outcomes under it will carry more weight than the policy text. The calculation a general counsel makes about disclosure is built on precedent and not on announcements. JD Supra has the analysis.

3. The FDA Opens the Question of Regulating Generative AI Devices

The Food and Drug Administration published a discussion paper seeking feedback on considerations for regulating generative AI medical devices, which is the earliest formal stage of a framework that does not yet exist. Medical device regulation is built around a device that behaves the same way on Tuesday as it did on Monday, and a model that is updated or fine-tuned breaks the premise that validation is a one-time event. Anybody building in this space should read the discussion paper as the list of questions their submission will eventually have to answer. HIPAA Journal has the paper.

4. HHS Ships an Updated Security Risk Assessment Tool

The Department of Health and Human Services released version 3.7 of its Security Risk Assessment Tool, the free instrument small and midsize healthcare organizations use to work through the HIPAA Security Rule requirement. A risk analysis is the single most commonly cited failure in OCR enforcement, and a practice that has never completed one is carrying an unresolved finding whether or not anybody has looked yet. The tool exists because the requirement is not optional and the expertise usually is. HIPAA Journal has the release.

Operator Note: A risk analysis that has not been revisited since your last major system change is stale by the standard the regulator applies, so check the date on yours before somebody else does.

5. Two More Hospital Systems Settle Breach Litigation

Central Maine Medical Center and Susan B. Allen Memorial Hospital each agreed to settle class action lawsuits arising from data breaches. Settlements at this cadence have stopped being individual news and started being a baseline, which is the useful way to read them, since the question for a hospital board is no longer whether litigation follows a breach but what the reserve should be. Every one of these outcomes is a data point for the actuarial question your own insurer is already asking. HIPAA Journal has both settlements.

Additional Compliance Alerts

Regulatory Updates

  • The SEC proposes modernizing transfer agent rules: A September 1 proposal would substantively update the framework governing registered transfer agents for the first time since the early 1980s. JD Supra
  • A welding fume listing change reaches process rather than product: The reclassification obliges employers to revisit ventilation, monitoring, and training practices, which is the expensive half of an occupational exposure change. Corporate Compliance Insights

Healthcare Technology

  • An Orthanc DICOM Server flaw enables denial of service: A high-severity vulnerability lets an authenticated remote attacker disrupt the imaging server, in a product category where an outage is a clinical problem. HIPAA Journal

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)