<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cybersecurity on CrossGov.com</title>
    <link>https://crossgov.com/tags/cybersecurity/</link>
    <description>Recent content in Cybersecurity on CrossGov.com</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 10 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://crossgov.com/tags/cybersecurity/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>FedRAMP 20x Reaches 538 Certified Cloud Services on a $10 Million Budget, While Europe Still Has No Common Cloud Certification</title>
      <link>https://crossgov.com/fedramp-20x-reaches-538-certified-cloud-services-on-a-10-million-budget-while-europe-still-has-no-common-cloud-certification/</link>
      <pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://crossgov.com/fedramp-20x-reaches-538-certified-cloud-services-on-a-10-million-budget-while-europe-still-has-no-common-cloud-certification/</guid>
      <description>&lt;p&gt;FedRAMP is the US government&amp;rsquo;s security approval for cloud services. If a federal agency wants to run its work on someone&amp;rsquo;s cloud, the service generally needs FedRAMP clearance first. In fiscal 2026, which ended on 30 September, the programme issued 92 new certifications, bringing the total to 538 cloud offerings. Agencies issued 760 new authorisations to use them.&lt;/p&gt;&#xA;&lt;p&gt;It did that with 17 federal employees, 15 contractors and a budget of $10 million, of which it spent just under $9 million.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CISA&#39;s Cyber Incident Reporting Rule Sits at OIRA as the Agency Shrinks to 2,200 Staff Without a Confirmed Director</title>
      <link>https://crossgov.com/cisas-cyber-incident-reporting-rule-sits-at-oira-as-the-agency-shrinks-to-2200-staff-without-a-confirmed-director/</link>
      <pubDate>Thu, 08 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://crossgov.com/cisas-cyber-incident-reporting-rule-sits-at-oira-as-the-agency-shrinks-to-2200-staff-without-a-confirmed-director/</guid>
      <description>&lt;p&gt;The final rule under the Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA, went to the White House Office of Information and Regulatory Affairs for review on 1 October 2026. It hasn&amp;rsquo;t been published. When it is, it will require critical infrastructure companies to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours, and ransom payments within 24 hours.&lt;/p&gt;&#xA;&lt;p&gt;Congress passed CIRCIA in March 2022. The law gave CISA until 2025 to write the final rule. It&amp;rsquo;s more than a year late.&lt;/p&gt;</description>
    </item>
    <item>
      <title>US Cyber Information-Sharing Law Runs on Stopgaps While the EU Cyber Resilience Act Reporting Clock Starts</title>
      <link>https://crossgov.com/us-cyber-information-sharing-law-runs-on-stopgaps-while-the-eu-cyber-resilience-act-reporting-clock-starts/</link>
      <pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://crossgov.com/us-cyber-information-sharing-law-runs-on-stopgaps-while-the-eu-cyber-resilience-act-reporting-clock-starts/</guid>
      <description>&lt;p&gt;On 11 September 2026 a new obligation started for every company selling software or connected hardware in the EU. If a vulnerability in one of their products is being actively exploited, they now have 24 hours to send an early warning, 72 hours to file a notification, and 14 days after a fix is available to send a final report. It applies to products already on the market too. ENISA, the EU cybersecurity agency, opened its single reporting platform the same day.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CISA&#39;s Midterm Election Security Plan Leaves States and Counties Paying for What Washington Used to Provide</title>
      <link>https://crossgov.com/cisas-midterm-election-security-plan-leaves-states-and-counties-paying-for-what-washington-used-to-provide/</link>
      <pubDate>Fri, 25 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://crossgov.com/cisas-midterm-election-security-plan-leaves-states-and-counties-paying-for-what-washington-used-to-provide/</guid>
      <description>&lt;p&gt;On 24 September, six weeks before the midterms, the Cybersecurity and Infrastructure Security Agency released its 2026 Election Infrastructure Security Plan. It promises monthly classified threat briefings with the FBI and intelligence agencies at more than 70 secure sites, a free threat-sharing platform linked to state fusion centres, and election advice from CISA&amp;rsquo;s ten regional directors.&lt;/p&gt;&#xA;&lt;p&gt;What it doesn&amp;rsquo;t include is the dedicated election staff and funding the agency cut in 2025. The plan gives no staffing numbers or budget, and doesn&amp;rsquo;t mention the information-sharing centre most counties used.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
