CORRECTED 15 Sept 2026. Later historical research superseded several US federal policy and EU AI Act claims in this file. See
19-corrections-and-updates.mdbefore citing anything about BOD 22-01, secure software attestation, the SEC SolarWinds case, the Cyber Safety Review Board, or EU AI Act high-risk deadlines.
Research date: September 14–15, 2026.
This material is educational and is not legal advice. Laws and rules change; several items below were in active rulemaking or parliamentary process at the research date. Anyone with compliance obligations should consult qualified counsel and the primary sources. Throughout, legal requirements (statutes, regulations, contractual mandates) are distinguished from voluntary best practices.
Part A — United States
A1. The Computer Fraud and Abuse Act and good-faith research
The CFAA (18 U.S.C. §1030, 1986) remains the core federal anti-hacking statute, with both criminal and civil liability. Van Buren v. United States (2021) narrowed "exceeds authorized access" to a gates-up-or-down test. The DOJ charging policy of May 19, 2022 directs federal prosecutors not to charge good-faith security research — accessing computers solely to test, investigate, or correct vulnerabilities, while avoiding harm and not using findings for extortion.
The caveats that matter more than the headline. The policy binds only federal prosecutors. It is not a statutory defense. It does not stop civil CFAA suits, which are how most researchers actually get threatened. And it does not preempt state computer-crime laws, which vary considerably. No CFAA statutory reform has passed as of September 2026.
For the site, the durable formulation is: written authorization is what makes testing legal; DOJ policy is prosecutorial discretion, not a defense; and safe harbor is a promise by one organization, not immunity.
A2. Breach notification and sector security rules
State breach-notification laws. All 50 states plus DC and the territories have them — California first in 2003, Alabama last in 2018. Triggers, definitions of personal information, and deadlines vary. The 2025–26 trend is tightening: 30-day deadlines now apply in California (signed October 2025, with an AG sample notice within 15 days for incidents affecting 500+ residents), Colorado, Florida, Maine, New York (a firm 30 days under a December 2024 law), and Washington, with Oklahoma updated effective January 1, 2026. Many require attorney-general notice above thresholds. There is still no general federal breach-notification law — only sectoral rules.
SEC cybersecurity disclosure rules (adopted July 2023, effective December 2023). Public companies must file a Form 8-K Item 1.05 within four business days of determining a cyber incident is material — determining materiality, not discovering the incident — and describe risk management, strategy, and governance annually in 10-K Item 106. SEC staff guidance of May 21, 2024 told companies to reserve Item 1.05 for genuinely material incidents and use Item 8.01 otherwise. First-year data showed a median of 4.5 business days from detection to disclosure, with 50% of filings later amended. Enforcement posture softened after the October 2024 settlements (Unisys, Avaya, Check Point, Mimecast) and the dismissal of most of the SEC's SolarWinds claims in July 2024; the current administration has signaled a narrower approach and has proposed reconsidering parts of the rule, but the disclosure rules remain in force.
FTC Section 5 and GLBA. The FTC continues to define "reasonable security" through consent orders rather than rulemaking. Marriott/Starwood (order finalized early 2025) imposed a 20-year comprehensive security program with data-minimization and deletion rights; GoDaddy (complaint January 2025, order finalized May 2025) mandated MFA, logging, inventory, and independent assessments. The teaching point: the FTC rarely fines first offenses but imposes 20-year audited security programs, which is often more expensive.
GLBA Safeguards Rule (16 CFR 314). Non-bank financial institutions — auto dealers, mortgage brokers, tax preparers, some fintechs — must run a written information security program with a qualified individual, risk assessment, encryption, MFA, and vendor oversight, in full effect since June 2023. The amendment adding FTC breach notification within 30 days for incidents affecting 500 or more consumers took effect May 13, 2024.
NYDFS 23 NYCRR Part 500. The Second Amendment's phased implementation completed with the final tranche effective November 1, 2025, requiring MFA for all individuals accessing any information system — not just remote access — and complete asset inventories. Earlier phases added 72-hour incident notice, 24-hour ransom-payment notice, annual CISO reporting, and enhanced duties for Class A companies. NYDFS issued detailed MFA FAQs in early 2026. This remains the most influential model for other state financial regulators.
CIRCIA. CISA's April 2024 NPRM proposed 72-hour covered-incident reports and 24-hour ransom-payment reports for entities across the 16 critical-infrastructure sectors above SBA small-business thresholds — roughly 300,000 entities. The final rule, originally due October 2025, was postponed to around May 2026 amid industry and congressional pushback on scope, and CISA reopened targeted comments. As of September 2026 the rule is in final-stage rulemaking, with reporting obligations to begin on the effective date. Related: the Cybersecurity Information Sharing Act of 2015 protections lapsed briefly in late 2025 during funding disputes and remain a live policy issue.
HIPAA. The Security Rule's proposed overhaul (NPRM published January 6, 2025) would remove the required/addressable distinction and mandate MFA, encryption, asset inventories, network mapping, segmentation, 72-hour restore objectives, and annual audits. Final action is now on HHS's long-term agenda and not expected before July 2027. The existing rule remains fully enforceable, and OCR's Risk Analysis Initiative continues to penalize weak risk analyses. HHS OCR has settled multiple ransomware-specific investigations.
A3. The state privacy wave
Roughly 20 states now have comprehensive consumer-privacy laws. Effective in 2025: Delaware, Iowa, Nebraska, New Hampshire, and New Jersey in January; Tennessee in July; Minnesota in July; Maryland on October 1, with notably strict data minimization. Effective January 1, 2026: Indiana, Kentucky, and Rhode Island, with further phases including universal opt-out recognition landing through 2026.
Nearly all require "reasonable" data security and risk assessments for sensitive processing. Only California grants a private right of action for breaches, with statutory damages of $100–$750 per consumer per incident for breaches of unencrypted personal information caused by unreasonable security — which is why California drives US breach class-action exposure. The California Privacy Protection Agency's regulations on cybersecurity audits, risk assessments, and automated decision-making became effective January 1, 2026, with mandatory independent cybersecurity audits phasing in by business size roughly 2028–2030 and first risk-assessment submissions due 2028.
Part B — European Union
GDPR. Core unchanged: Article 32 security obligations and Article 33's 72-hour notification. A Commission "digital omnibus" package proposed in November 2025 contemplates targeted GDPR and ePrivacy simplifications; it is under negotiation and not law as of September 2026.
NIS2 (Directive 2022/2555). Transposition deadline was October 17, 2024. The Commission opened infringement proceedings with formal notices to 23 member states on November 28, 2024, escalating to reasoned opinions in May 2025 for the stragglers. By mid-2026 most member states have transposed, but the patchwork means multinationals face country-by-country registration and enforcement differences.
Substance: "essential" and "important" entities across 18 sectors; Article 21 risk-management measures covering incident handling, supply chain, MFA, cryptography, and training; Article 23 reporting — early warning within 24 hours, incident notification within 72 hours, final report within one month; management-body accountability; and fines up to €10M or 2% of turnover.
DORA (Regulation 2022/2554). Applies since January 17, 2025 to roughly 20 types of financial entities and their ICT providers. Requirements: an ICT risk-management framework, incident classification and reporting, digital operational resilience testing including threat-led penetration testing for significant entities, ICT third-party risk with mandatory contract provisions, and the register of information filed to supervisors, first collected in April 2025. The European Supervisory Authorities designated the first critical ICT third-party providers — including major cloud providers — for direct EU oversight in July 2025. Directly applicable, with no transposition needed.
Cyber Resilience Act (Regulation 2024/2847). Entered into force December 10, 2024. A landmark product-security law for "products with digital elements": secure-by-design essential requirements, vulnerability handling, documentation, support periods, and CE marking. Timeline: September 11, 2026 — mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA and CSIRTs began; December 11, 2027 — full application of essential requirements. It binds manufacturers, importers, and distributors, including open-source "stewards" under a lighter regime. This is the single most consequential piece of product-security law in the world right now and deserves its own page.
EU AI Act (Regulation 2024/1689). In force August 1, 2024; prohibitions applied February 2, 2025; GPAI-model obligations from August 2, 2025; high-risk system obligations — including Article 15's accuracy, robustness, and cybersecurity requirements covering resilience to data poisoning and adversarial examples — scheduled for August 2, 2026. Caveat: the November 2025 digital-omnibus proposal would delay some high-risk deadlines pending standards availability, so verify the finally-agreed dates. Relevant even to non-AI companies through Annex III use cases covering biometrics, critical infrastructure, and employment.
Part C — United Kingdom
Computer Misuse Act 1990. Still the operative anti-hacking law, and still lacking any statutory public-interest or good-faith defence for security researchers. The Home Office review has run since 2021; in 2025–26 the government signaled willingness to reform, while the CyberUp campaign pushed for a defence and critics noted that draft proposals would protect only a narrow slice of researchers. No enacted reform as of September 2026 — UK researchers still rely on written authorization and prosecutorial discretion, which is a materially weaker position than their US counterparts.
UK GDPR and the Data Protection Act 2018. Security duties mirror EU Article 32. The Data (Use and Access) Act 2025 (Royal Assent June 2025) made targeted changes without altering core security obligations. The ICO enforces, with notable security fines including Advanced Computer Software's £3.07M in 2025 for the 2022 NHS-supplier ransomware breach.
NCSC. The UK's technical authority, part of GCHQ, and non-regulatory: it publishes guidance including the Cyber Assessment Framework used by NIS regulators, runs Cyber Essentials and Cyber Essentials Plus certification (a baseline for many government contracts, with the "Willow" question-set update in April 2025), and supports incident management. Its Annual Review 2025 reported 429 incidents handled, of which 204 were nationally significant — up from 89.
Cyber Security and Resilience Bill. Introduced in the Commons November 12, 2025 as the UK's NIS2 analogue: it would expand the NIS Regulations 2018 to managed service providers and data centres, strengthen regulator powers and incident reporting on a two-stage 24-hour and 72-hour model, and enable designation of critical suppliers. Still progressing through Parliament as of September 2026.
Part D — Other jurisdictions
Australia. The Cyber Security Act 2024 created Australia's first standalone cyber law: mandatory ransomware-payment reporting within 72 hours from May 30, 2025 for businesses with more than A$3M turnover and for critical-infrastructure entities, smart-device security standards, a limited-use rule for information shared with the National Cyber Security Coordinator, and a Cyber Incident Review Board. Companion amendments expanded the SOCI Act 2018 to cover data systems, government assistance powers, and risk-management program obligations.
Singapore. The Cybersecurity (Amendment) Act 2024 extended regulation beyond physical critical information infrastructure to virtual and cloud-hosted CII, and added regimes for Systems of Temporary Cybersecurity Concern, Entities of Special Cybersecurity Interest, and major foundational digital infrastructure. The PDPA continues to require reasonable security and breach notification.
Canada. Bill C-26 (Critical Cyber Systems Protection Act) died on prorogation in January 2025 and was reintroduced as Bill C-8 in June 2025, covering cybersecurity programs and 72-hour incident reporting for federally regulated critical sectors. Not yet law as of September 2026; PIPEDA breach reporting remains the operative federal hook.
Part E — Practice areas that cut across jurisdictions
E1. Coordinated vulnerability disclosure and safe harbors
Norms: ISO/IEC 29147 (disclosure) and 30111 (handling); the CERT/CC CVD guide; RFC 9116 security.txt for publishing contact points. CISA Binding Operational Directive 20-01 requires every US federal civilian agency to publish a vulnerability disclosure policy with legal safe-harbor language, and CISA, NSA, and international partners published joint guidance on establishing CVD programs in July 2026. In the EU, NIS2 Article 12 established the European vulnerability database, launched by ENISA in 2025, and the CRA makes vulnerability-handling a legal product requirement.
Safe harbor is a contractual promise by one organization not to sue or refer researchers acting within policy, standardized through disclose.io and platform terms. Frame it accurately for readers: it cannot authorize testing third-party systems, and it does not bind prosecutors.
E2. Bug-bounty legal terms researchers should check
Scope definition, authorization language, the safe-harbor clause, prohibited techniques (denial of service, social engineering, data-exfiltration limits), data handling and deletion duties, disclosure rules — coordinated timelines versus indefinite NDA-style gag terms, a recurring ethics controversy — payment conditions, and tax status.
Two cautions worth publishing. Private programs' NDAs can restrict publishing findings indefinitely, so researchers should read terms before testing. And organizations should not use bounties and NDAs to suppress breach disclosure — the 2016 Uber case led to a federal conviction of its chief security officer.
E3. Penetration-test authorization essentials
Written authorization signed by someone with actual authority over the systems. For cloud and hosted assets, confirm provider policy — AWS, Azure, and GCP allow most customer-resource testing without prior approval but prohibit denial of service — and obtain third-party consent where systems are managed by MSPs or SaaS providers.
Rules of engagement: scope by IP, domain, and application; test windows; permitted techniques; production-safety constraints; emergency stop and deconfliction contacts; data-handling rules on what testers may access or copy; and evidence retention.
Contract terms: liability caps and mutual indemnification, insurance requirements (testers should carry E&O and cyber cover), confidentiality, report ownership, and — after the 2019 Iowa Coalfire courthouse arrests — explicit coverage of physical testing and law-enforcement notification arrangements.
The reference methodology is NIST SP 800-115. The distinction to draw: authorization is what makes testing legal; everything else is contractual risk management.
E4. Digital evidence
Chain-of-custody documentation; forensic imaging with cryptographic hashing using write blockers and verified copies; volatile-data ordering; contemporaneous notes. In US courts, Federal Rules of Evidence 901 and 902 govern authentication, and FRE 902(13)–(14), added in 2017, allow self-authentication of machine-generated records and hash-verified copies via certification.
The litigation lesson taught by In re Capital One (2020) and Wengui v. Clark Hill (2021): forensic reports prepared in the ordinary course of business, or serving dual purposes, may not be shielded by privilege. Structure incident-response engagements through counsel deliberately, and do it before the incident.
E5. Cyber insurance requirements
Underwriting has become a technical audit. Near-universal prerequisites: MFA, especially for remote access and privileged accounts; EDR coverage; tested offline or immutable backups; email authentication; patch and end-of-life management; and an exercised IR plan. Carriers increasingly scan policyholders' attack surfaces and adjust terms mid-policy.
Contested coverage frontiers: war and state-sponsored-attack exclusions (the Lloyd's 2023 mandate; Merck's roughly $1.4B NotPetya settlement in 2024) and ransomware co-insurance. And misrepresenting controls on an application can void coverage — Travelers v. ICS (2022) rescinded a policy over a false MFA attestation.
E6. Vendor-contract security clauses
The typical enterprise stack: a security exhibit referencing a framework (ISO 27001, SOC 2, or CIS); breach notification to the customer within 24 to 72 hours; audit and penetration-test-report access rights; data location, return, and deletion; subprocessor flow-down; cyber-insurance minimums; and liability carve-outs elevating data-breach caps.
Several of these are legally required rather than negotiable: GDPR Article 28 processor terms, DORA's mandatory ICT-contract provisions under Article 30, NIS2 supply-chain duties, HIPAA business associate agreements, GLBA service-provider oversight, and DFARS 252.204-7012 flow-downs in US defense contracting.
E7. Cross-border investigations
The Budapest Convention on Cybercrime (2001) has roughly 70-plus parties and harmonizes offenses and mutual legal assistance; its Second Additional Protocol (2022) on electronic evidence, enabling direct cooperation with providers, is gathering ratifications.
The US CLOUD Act (2018) enables executive agreements for direct cross-border data demands — the US–UK agreement has been in force since 2022, with US–Australia following. The EU e-Evidence Regulation (2023) applies from 2026, standardizing intra-EU production orders.
The UN Convention against Cybercrime was adopted by the General Assembly on December 24, 2024 and opened for signature in Hanoi on October 25–26, 2025, with roughly 65–72 states signing. It enters into force 90 days after the 40th ratification and is not yet in force as of September 2026. It has been widely criticized by industry and human-rights groups for broad scope and weak safeguards for security researchers — a key talking point to present alongside the Budapest framework rather than instead of it.
Part F — Editorial rules for legal content
- State the disclaimer on every page. Educational, not legal advice; consult counsel; verify against primary sources.
- Separate must from should, and label each item: statute, regulation, contractual mandate, or voluntary framework.
- Date-stamp every status line and build a review cadence. The following are moving targets as of September 2026 and should carry explicit "status as of" language: HIPAA's final rule (2027 or later), CIRCIA's final rule, the UK Cyber Security and Resilience Bill, CMMC phase-in, EU AI Act high-risk timing under the digital omnibus, UN convention ratifications, Canada's Bill C-8, and FCC post-Salt-Typhoon rules.
- Repeat the researcher-safety mantra wherever offensive security is discussed: authorization in writing, scope in writing, safe harbor is not immunity, and DOJ policy is discretion rather than a defense.
- Do not generalize across jurisdictions. The UK's lack of a research defence, the US's state-law patchwork, and the EU's directly applicable regulations behave differently enough that a single "the law says" sentence is almost always wrong.