patch&proof.
← Research library

Corrections / Research chapter

Corrections and Updates to the First-Round Research Package

Issued 15 September 2026. The 2019–2026 historical research surfaced eleven items that supersede or materially qualify claims in the first-round deliverables (f

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Issued 15 September 2026. The 2019–2026 historical research surfaced eleven items that supersede or materially qualify claims in the first-round deliverables (files 00–17). This document is authoritative where it conflicts with them. Affected files carry a banner pointing here.

This is also, usefully, a demonstration of the corrections policy in 15-editorial-and-safety-policy.md working as intended — and evidence for the editorial argument that undated cybersecurity content goes wrong fast.


1. BOD 22-01 has been revoked and replaced

What the package said. Several files cite CISA's Binding Operational Directive 22-01 and its 14-day KEV remediation clock as current federal practice.

What is actually true. On 10 June 2026, CISA issued BOD 26-04, "Prioritizing Security Updates Based on Risk," which revokes and replaces BOD 22-01 entirely. The flat 14-day clock is gone. In its place is a four-variable risk model — public exposure, KEV listing, exploit automatability, and technical impact — producing graduated deadlines:

Condition Deadline
KEV-listed with total system control 3 days, with forensic triage
Publicly exposed, automatable, full control 3 days
Most KEV entries; certain high-risk non-KEV combinations 14 days
Non-exposed, partial control 60 days
None of the four criteria met Fix at system upgrade

The KEV catalog survives as one of four inputs rather than the sole trigger, and the methodology is explicitly informed by SSVC rather than CVSS — the first time SSVC has appeared in a binding federal mandate. Deadlines are dynamic: if an asset's exposure changes, its clock changes.

Why this matters for the site. The underlying advice does not change — patch what is being exploited, fast. But any page that says "CISA requires 14 days for KEV" is now wrong, and the more sophisticated framing (KEV is necessary but not sufficient context) is the one to teach.

2. Secure software attestation has been rescinded

What the package said. File 01 lists "CISA's Secure Software Development Attestation Form" among current compliance requirements for software sold to the US government.

What is actually true. OMB memorandum M-26-05 (23 January 2026) rescinded the standardized self-attestation requirement outright, replacing it with agency-led validation based on risk assessment. Agencies may continue using the old form, or may instead use contract terms requiring an SBOM on request. Law-firm analyses treat this as a genuine deregulatory shift rather than a technical adjustment.

This followed EO 14306 (6 June 2025), which had already struck the attestation provisions and deleted the digital identity section from EO 14144, while retaining the post-quantum deadlines — federal agencies must support TLS 1.3 with PQC no later than 2 January 2030.

The teaching point worth keeping. SBOM as a practice survived the rescission of SBOM-adjacent mandates, because by 2026 it had independent drivers: the EU Cyber Resilience Act, customer contract terms, and vulnerability tooling that assumes it exists.

3. The Cyber Safety Review Board was disbanded

What the package said. Nothing — this is an omission rather than an error, and a significant one.

What is actually true. The CSRB, created under EO 14028 in February 2022 and modeled on the NTSB, produced three substantive reports: Log4j (July 2022), Lapsus$ (August 2023), and Storm-0558 (April 2024). The Storm-0558 report called the intrusion "preventable," the product of "a cascade of avoidable errors," and Microsoft's security culture "inadequate and requiring an overhaul" — an unprecedented finding widely credited with triggering Microsoft's Secure Future Initiative.

In January 2025, DHS dissolved its advisory board memberships including the CSRB, terminating the in-progress review of the Salt Typhoon telecom intrusions. That review was never completed or published. As of September 2026 the board has not been reconstituted.

Why it belongs on the site. The most significant known intrusion into US telecommunications infrastructure has no authoritative public post-mortem. That is a fact worth reporting plainly, and the CSRB's arc — public non-punitive review changing vendor behavior faster than enforcement, then proving to have no institutional protection — is a genuinely instructive story.

4. The SEC's SolarWinds case was dismissed with prejudice

What the package said. File 11 notes that most of the SEC's SolarWinds and Tim Brown claims were dismissed in July 2024.

What is actually true. That was the partial dismissal. The SEC dismissed the case with prejudice on 20 November 2025. The case is over.

The disclosure rules themselves remain in force, but the enforcement posture described in file 11 should be read with this outcome included, and the site should not imply ongoing litigation.

5. The Cybersecurity Information Sharing Act of 2015 lapsed, and its extension expires imminently

What the package said. File 11 notes the protections "lapsed briefly in late 2025 during funding disputes."

What is actually true, and it is more serious than that. CISA 2015 gave private entities liability protection, antitrust exemption, and FOIA exemption for sharing threat indicators. It carried a ten-year sunset and lapsed on 30 September 2025, removing the legal foundation underneath a decade of ISAC and ISAO operation, JCDC participation, and routine inter-company sharing. Reporting documented immediate chilling effects on sharing volume, because counsel advises people to stop when the shield is gone.

Congress passed short-term extensions, and the Consolidated Appropriations Act of February 2026 extended the statute through 30 September 2026. A further stopgap funding measure passed in early September 2026 extended it again, to 11 December 2026. Long-term reauthorization remains unresolved.

Action for the site. This needs a live status line and a check on or immediately after 11 December 2026. It is the clearest example in the package of why regulation pages need status fields rather than publication dates.

6. EU AI Act high-risk deadlines have been deferred

What the package said. Files 01, 09 and 11 give 2 August 2026 for high-risk obligations including Article 15's cybersecurity requirements, with a caveat that the November 2025 digital-omnibus proposal contemplated delay.

What is actually true. EU institutions reached provisional political agreement on the Digital Omnibus on 6 May 2026, deferring Annex III high-risk obligations to approximately 2 December 2027 and Annex I high-risk obligations — medical devices, machinery, vehicles — to approximately 2 August 2028.

Article 50 transparency obligations for AI-generated content still apply from 2 August 2026. The agreement also added a prohibition on AI systems generating non-consensual intimate imagery and CSAM, with a transitional period to 2 December 2026.

Standing caveat. At the time of research the Omnibus changes required formal adoption and Official Journal publication to become binding. Verify before publishing the deferred dates as settled.

7. US national cyber strategy has been replaced

What the package said. Nothing — another omission.

What is actually true. On 13 March 2026 the White House released "President Trump's Cyber Strategy for America," replacing the March 2023 National Cybersecurity Strategy. The contrast is substantive: three pages versus 34; an explicit pledge to avoid "costly checklists" and reject new compliance mandates, versus 2023's use of regulation to reshape market incentives; greater emphasis on offensive capability and "unleashing the private sector" to disrupt adversary networks; and software liability absent entirely.

A companion executive order on combating cybercrime and fraud directs agencies to target transnational criminal organizations, with a 120-day deadline for action plans.

Why this matters. The 2023 strategy's software-liability proposal was the most-cited policy idea in the field for two years. Its removal is a material change to the policy environment that any regulation tracker must reflect.

8. CIRCIA's timeline slipped again

What the package said. File 11 says the final rule was postponed to around May 2026 and is in final-stage rulemaking.

What is actually true. The target slipped again to September 2026. Town halls planned for March–April 2026 were postponed by a DHS appropriations lapse and rescheduled to 15–18 June 2026, drawing over 1,200 stakeholders. CISA has stated an intent to streamline requirements relative to the 2024 proposed rule.

As of 15 September 2026, CIRCIA reporting obligations are still not in force — four and a half years after the statute was enacted.

9. NIS2 enforcement has escalated to the CJEU

What the package said. File 11 notes infringement proceedings opened against 23 member states in November 2024, escalating to reasoned opinions in May 2025.

Update. On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union over failure to transpose NIS2.

10. Secure by Design signatory count

Minor. File 01 says the pledge "exceeded roughly 300 signatories." The better-sourced figure is over 250 companies. The substantive point — that the pledge was voluntary, unverified, and lost its architects in 2025 — stands, and the 2026 strategy's omission of software liability makes its future more uncertain than the original text implied.

11. A framing correction on ransomware statistics

What the package said. The first round presented 2024–2026 ransomware figures without the longer series.

What the history adds. Chainalysis revises prior years upward as attribution improves, so the same year appears differently across editions — 2024 has been reported as both ~$813M and ~$892M. Any chart the site builds must state which edition it uses. The full revised series is in 18-seven-year-timeline-2019-2026.md, and the seven-year payment-rate decline from roughly 70% to under 28% is a far more useful teaching statistic than any single year.


What to do with this

For the research package: treat files 00–17 as accurate except where this document contradicts them. Files 01, 09 and 11 carry banners.

For the site: every item above is an argument for the editorial standards already in 15-editorial-and-safety-policy.md. Specifically —

Regulation and framework pages need a status field ("in force," "rescinded," "proposed," "deferred"), not just a publication date. Six positions established between 2021 and 2024 were reversed between 2025 and 2026, so a page that was correct when written can be wrong within a year without anyone touching it.

The review cadence for US federal policy content should be monthly, not quarterly, through at least the end of 2026 — the CISA 2015 sunset, CIRCIA's rule, and the EU Digital Omnibus adoption are all live within weeks of each other.

And the underlying lesson is worth writing up as an article in its own right: mandates reverse, and practices sometimes outlive them. SBOM survived the rescission of SBOM mandates. That is a more interesting and more useful thing to tell readers than any individual compliance deadline.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval