🎤 Episode 35 is live
September's Deadline Wall: FedRAMP, Korea, Alabama · ~8 min
Listen: Web player · Direct MP3
A wall of September compliance deadlines just landed inside three weeks. This week's episode walks through what changes and when, drawn from the same primary-source research behind the CyberEyeQ Weekly briefing.
This Week's Top Stories
1. FedRAMP 20x Class B and Class C pipelines open Monday. Under the Consolidated Rules for 2026 (CR26), the automated authorization paths for Class B and Class C both open 31 August, following the 3 August Class A opening. FedRAMP · CRITICAL · Due 31 Aug.
2. CISA adds an actively-exploited Citrix NetScaler flaw among six new KEVs. A SAML SSO memory-corruption flaw (CVE-2026-8452) in internet-facing NetScaler ADC and Gateway leads six additions on 26 August; remediation windows flow from BOD 26-04. CISA · HIGH.
3. South Korea's PIPA overhaul brings up-to-10% turnover fines and CEO liability. The amended Personal Information Protection Act takes effect 11 September, adding an aggravated fine of up to 10% of total revenue plus personal accountability for the CEO and Chief Privacy Officer. PIPC / law.go.kr · CRITICAL · Due 11 Sep.
4. Alabama subpoenas OpenAI under the Deceptive Trade Practices Act. Subpoena Duces Tecum #26-0007, issued 20 August, commands production of safety-testing records by 10:00 AM on 14 September — the first state consumer-protection action built around autonomous model behavior. Alabama AG · CRITICAL · Due 14 Sep.
5. California completes its first AI-cohort bill (AB 2392). The bill cleared both houses unanimously (38–0, then 79–0) on 26 August, setting generative-AI procurement standards that will bind every California public university. CA Assembly Clerk · HIGH.
Compliance Action Items
By 31 Aug — Confirm FedRAMP 20x class eligibility and package readiness.
Now — Patch internet-facing Citrix NetScaler ADC/Gateway (CVE-2026-8452) and check the other five KEV entries.
By 1 Sep — Determine whether your China entity falls under the sub-100,000 small-processor threshold (CAC Order No. 25).
By 11 Sep — Brief the board on Korea's PIPA supervisory liability and re-test your breach-notification runbook.
By 14 Sep — If in scope of the Alabama subpoena, extend litigation holds to internal safety/security testing records.
Immediately — Re-review lending programs against ECOA and Regulation B without the withdrawn Special Purpose Credit Programs statement.
For the full brief with every source, read the CyberEyeQ Weekly newsletter. This podcast is generated from the same primary-source research.