CODY KELLER

Six months in. It’s a reasonable moment to step back from the tactical and look at the rest of the year as a whole — what’s coming, what’s already behind schedule, and where security and GRC programs need to be positioned heading into Q3 and Q4.

This isn’t a predictions post. It’s a planning post. Here’s what the second half of 2026 looks like and what it means for your program.

What’s Already Overdue

Before looking ahead, the honest accounting of what was supposed to happen in the first half of 2026 and didn’t.

CIRCIA’s final rule missed its original October 2025 deadline, was pushed to May 2026, and as of this writing has not been formally published. If your incident response program has been waiting on the final rule to operationalize CIRCIA compliance, that’s a posture worth reconsidering. The proposed rule is detailed enough to build against, and the core requirements — 72-hour incident reporting, 24-hour ransomware payment reporting, covered entity determination — are unlikely to change materially in the final version. Organizations that start building now will be in refinement mode when the rule drops. Organizations waiting for finality will be starting from scratch under a compliance deadline.

CISA’s leadership vacancy has persisted. Sean Plankey’s nomination remains in the Senate. The operational implications — reduced threat intelligence sharing, weakened critical infrastructure partnerships, uncertain CIRCIA implementation guidance — are real regardless of when confirmation happens. Plan your program around CISA’s current operational capacity, not its pre-2025 posture.

August 2: The EU AI Act Deadline

The single most significant compliance deadline remaining in 2026 is August 2, when the EU AI Act’s major provisions — including requirements for high-risk AI systems — become fully applicable.

We’ll cover this in detail next week. The short version for the halfway point review: if your organization touches EU markets and uses AI in any capacity, and you haven’t completed your AI system inventory and risk classification, you are now operating in a narrow window. August 2 is eleven days after this post publishes. That’s not enough time to build a compliance program from scratch. It is enough time to make a defensible start and document it.

Q3: The Enforcement Ramp

Q3 is historically when regulatory enforcement activity from earlier in the year starts producing visible results. Investigations opened in Q1 and Q2 begin resolving. Consent decrees get announced. AG offices that signaled enforcement priorities in the spring start acting on them.

For state privacy law specifically, the Connecticut AG’s office has indicated it will not extend informal grace for technical violations. California’s enforcement apparatus — both the AG and the California Privacy Protection Agency — has been active. Indiana, Kentucky, and Rhode Island AGs are now six months into having live enforcement authority.

The organizations most likely to be in a Q3 enforcement action are the ones that received deficiency notices earlier in the year and failed to adequately address them — exactly the pattern that produced Connecticut’s first CTDPA settlement. If your organization has received any regulatory correspondence about privacy compliance this year, treat Q3 as the accountability window for whatever response you provided.

Q3: The Midterm Election Threat Environment

The 2026 midterm elections are in November. By September, the political environment will be at peak intensity, and with it, the threat environment that follows election cycles — disinformation campaigns, credential harvesting targeting political operatives and campaigns, infrastructure probing targeting election systems, and AI-generated content designed to manipulate public discourse.

Most private sector organizations aren’t directly in the election security perimeter. But the geopolitical activity that accompanies major elections affects the broader threat landscape. Iran, Russia, and China all have documented histories of using US election cycles as a period of elevated offensive cyber activity. The geopolitical threat post from April 14 is worth revisiting as a context reference heading into Q3.

For organizations in financial services, healthcare, critical infrastructure, and defense supply chain, Q4 election proximity historically correlates with elevated nation-state activity. Factor that into your threat model and your monitoring posture.

Q4: The Holiday Accumulation Problem

Q4 is when three things happen simultaneously that create compounding risk: the threat environment elevates as nation-state actors and criminal groups run holiday campaigns, your organization’s headcount and attention are reduced by holiday schedules, and the year-end push to close out audit findings, policy reviews, and compliance tasks creates competing priorities for your team.

Start planning your Q4 security posture now rather than in October when it’s already complicated. Specifically: what’s your coverage model for key holidays? What open audit findings need to close before year-end? What policy reviews are scheduled for Q4 that could be pulled forward into Q3 to reduce the load? What are your CIRCIA and state privacy law obligations heading into Q4 reporting cycles?

The Second Half Planning List

  • Build against the CIRCIA proposed rule if you haven’t started. Don’t wait for finality that may not come until Q4.
  • Treat August 2 as a real deadline for EU AI Act compliance work. Document your current state and your remediation roadmap even if you can’t be fully compliant by that date.
  • Review any regulatory correspondence from H1 and confirm your responses were adequate. Q3 is the accountability window.
  • Adjust your threat model for election proximity heading into Q3 and Q4. Elevated geopolitical activity is a planning input, not a theoretical consideration.
  • Pull forward Q4 compliance tasks where possible. Anything that can close in Q3 reduces your year-end load and your exposure window.
  • Schedule your year-end access review now. Put it on the calendar for mid-November. By the time you need it, you’ll be glad you planned it in advance.

The first half of 2026 moved fast. The second half will move faster. Programs that are positioned heading into Q3 will have options. Programs that are reactive will be managing from behind for the rest of the year.


Discussion Questions

  1. Has your organization started building your CIRCIA compliance program against the proposed rule, or are you waiting for the final rule? What’s driving that decision?
  2. Where does your Q4 compliance calendar currently stand? Are there tasks scheduled for Q4 that could be pulled forward into Q3 to reduce the year-end load?
  3. How does your organization’s threat model account for election-cycle elevated activity? Is that a formal input into your monitoring posture or an informal assumption?

Further Reading


Leave a Reply

Your email address will not be published. Required fields are marked *