This website uses cookies

Read our Privacy policy and Terms of use for more information.

🎤 Episode 35 is live

September's Deadline Wall: FedRAMP, Korea, Alabama · ~8 min

A wall of September compliance deadlines just landed inside three weeks. This week's episode walks through what changes and when, drawn from the same primary-source research behind the CyberEyeQ Weekly briefing.

This Week's Top Stories

1. FedRAMP 20x Class B and Class C pipelines open Monday. Under the Consolidated Rules for 2026 (CR26), the automated authorization paths for Class B and Class C both open 31 August, following the 3 August Class A opening. FedRAMP · CRITICAL · Due 31 Aug.

2. CISA adds an actively-exploited Citrix NetScaler flaw among six new KEVs. A SAML SSO memory-corruption flaw (CVE-2026-8452) in internet-facing NetScaler ADC and Gateway leads six additions on 26 August; remediation windows flow from BOD 26-04. CISA · HIGH.

3. South Korea's PIPA overhaul brings up-to-10% turnover fines and CEO liability. The amended Personal Information Protection Act takes effect 11 September, adding an aggravated fine of up to 10% of total revenue plus personal accountability for the CEO and Chief Privacy Officer. PIPC / law.go.kr · CRITICAL · Due 11 Sep.

4. Alabama subpoenas OpenAI under the Deceptive Trade Practices Act. Subpoena Duces Tecum #26-0007, issued 20 August, commands production of safety-testing records by 10:00 AM on 14 September — the first state consumer-protection action built around autonomous model behavior. Alabama AG · CRITICAL · Due 14 Sep.

5. California completes its first AI-cohort bill (AB 2392). The bill cleared both houses unanimously (38–0, then 79–0) on 26 August, setting generative-AI procurement standards that will bind every California public university. CA Assembly Clerk · HIGH.

Compliance Action Items

  • By 31 Aug — Confirm FedRAMP 20x class eligibility and package readiness.

  • Now — Patch internet-facing Citrix NetScaler ADC/Gateway (CVE-2026-8452) and check the other five KEV entries.

  • By 1 Sep — Determine whether your China entity falls under the sub-100,000 small-processor threshold (CAC Order No. 25).

  • By 11 Sep — Brief the board on Korea's PIPA supervisory liability and re-test your breach-notification runbook.

  • By 14 Sep — If in scope of the Alabama subpoena, extend litigation holds to internal safety/security testing records.

  • Immediately — Re-review lending programs against ECOA and Regulation B without the withdrawn Special Purpose Credit Programs statement.

For the full brief with every source, read the CyberEyeQ Weekly newsletter. This podcast is generated from the same primary-source research.