ITRADE works with STEM organizations to close Technology, Talent, & Security gaps. See how →
Every security team has a list of systems they've quietly agreed to ignore.
Nobody writes it down. Nobody puts "we chose not to protect these" in a slide deck. But practically - cloud instances spun up by developers. Virtual machines cloned from templates that haven't been patched in two years. Vendors with persistent VPN tunnels straight into production. AI tools trained on production data with zero access controls.
Two years ago, most compliance frameworks let you get away with it.
That grace period is over.
In the first half of 2026, the compliance landscape shifted faster than at any point in the past decade. Not one framework. Nearly all of them.
PCI DSS 4.0 - the standard governing payment card security - went into full enforcement on March 31, 2026. Risk analysis is now mandatory, not optional. Anti-phishing controls, script integrity for payment pages, and continuous security testing all moved into scope. Organizations that were "mostly compliant" under the old version are finding gaps they didn't budget for.
CMMC 2.0 - the cybersecurity certification required for defense contracts - is now enforced for all new DoD awards. Over 73,000 defense supply chain companies need third-party certification against 110 security controls. Cloud environments, subcontractor access, and sensitive data flows that used to be self-assessed are now audit targets.
NIST CSF 2.0 added Governance as the sixth core function - officially elevating cybersecurity from an IT concern to a board-level risk management responsibility. Supply chain risk management is now a top-tier requirement, not an afterthought.
NERC CIP 2026 - the cybersecurity standard for the North American power grid - is pushing the most aggressive expansion in critical infrastructure compliance history. Three new standards hit enforcement this year alone.
The pattern across all of them is identical: assets that were previously exempt are becoming audit targets. Cloud infrastructure. Virtualized systems. Third-party access pathways. AI and machine learning workloads. Remote operations.
Your "out of scope" list is becoming your risk register.
What Happens When Compliance Catches Up: The NERC CIP Blueprint
The energy sector is going through the most dramatic version of this pattern right now - and it's worth studying even if you never touch a power grid, because it previews what every other framework is heading toward.
CIP-003-9 went into effect April 1, 2026. It extends governance and vendor access controls to low-impact assets - the systems that utilities had been largely exempt from formal requirements. Every vendor with remote access now needs individual authentication, supply chain risk documentation, and detection of malicious communications.
This is the exact same pattern: PCI DSS 4.0 just did this to payment-adjacent systems. CMMC 2.0 just did this to subcontractor access. SOC 2 auditors have been pushing this on SaaS vendors for two years.
CIP-015-1 made Internal Network Security Monitoring (INSM) mandatory for critical systems. Network traffic capture and analysis - the kind of visibility most organizations still treat as a "nice to have" - is now a regulatory requirement. Implementation deadlines run through 2030, and FERC has already ordered the scope to expand further.
The parallel outside energy: NDR and network traffic analysis deployments that security teams have been requesting budget for are on track to become compliance requirements across industries, not just operational improvements.
CIP-012-2 went into effect July 1, 2026. It extended encryption and integrity protections to any communications crossing public networks. The same requirement healthcare organizations face under HIPAA for patient data in transit, and PCI DSS 4.0 mandates for cardholder data.
In March, FERC approved 11 updated standards covering virtualization - formally recognizing VMs, containers, and software-defined infrastructure as in-scope assets. The energy sector just did what every industry will do: admit that virtual infrastructure carries the same risk as physical infrastructure and must be governed accordingly.
The Threat Pressure Driving the Expansion
Regulators don't expand compliance scope for the exercise. They do it because the threat landscape forced their hand:
- Cyberattacks targeting U.S. utilities increased roughly 70% in 2024 (Check Point Research)
- 67% of energy organizations faced ransomware in 2024, with 80% resulting in data encryption (Sophos)
- 60% of critical infrastructure attacks attributed to nation-state actors
- In December 2025, Russia's Sandworm group deployed destructive malware against 30 distributed energy facilities in Poland via internet-exposed equipment
But the broader point: that same threat pressure exists everywhere. Ransomware hit 59% of organizations globally in 2024. Supply chain attacks grew 320% between 2021 and 2025. AI-powered phishing is outperforming human-crafted campaigns in click-through rates.
Compliance frameworks are expanding because the threats already did.
What to Do
1. Audit your "out of scope" assets against the current enforceable version of your framework. Not the version you certified against - the version that's live today. PCI DSS 4.0, CMMC Level 2, and NERC CIP all expanded scope in 2026.
2. Map every third-party access pathway. Vendors with persistent remote access are the number one newly in-scope asset across frameworks. Document who has access, what protocol, whether it requires individual authentication, and whether you can disable it within 15 minutes.
3. Start network monitoring before it becomes mandatory. NERC CIP made it a requirement. In 12 to 18 months, expect similar language in SOC 2 and FedRAMP. Build the capability now while it's a competitive advantage, not a scramble.
4. Treat virtual infrastructure like physical infrastructure. VMs, containers, and cloud workloads carry the same governance requirements. Change management, patching, and access controls apply equally.
5. Brief the board on compliance expansion as a budget driver. New scope means new controls means new budget. NIST CSF 2.0 made governance a core function for a reason. Frame it as risk, not IT.
The organizations that scale compliance successfully don't treat framework expansion as a surprise. They treat it as a predictable risk management cycle and fund accordingly.
This works for any framework - PCI DSS, CMMC, SOC 2, HIPAA, NERC CIP. Run it quarterly.
If you identified gaps in 3 or more areas: your compliance readiness budget needs to catch up with framework reality.
Bianca architects the systems most leaders buy in pieces - talent, technology, and security, designed to work as one.
