01TOP NEWS
enforcement/regulator
CISA adds Cisco SD-WAN auth bypass to KEV Catalog
Emergency Directive 26-03 is already live; this KEV addition raises the remediation floor for FCEB agencies.nist-800-171/standards
NIST SP 800-70 Rev 5 mandates CSF 2.0 traceability in federal checklists
Checklist developers who skip the new cross-framework mapping lose NCP participation; assessors now need evidence tied to CSF 2.0 outcomes, not just control IDs.nist-800-172/standards
NIST opens comment period on SP 800-52 Rev. 2 TLS guidelines
The real question isn't TLS 1.3 alignment, it's whether NIST will demote TLS 1.2 from required to optional, which sets the pace of cryptography deprecation across CMMC-tied frameworks.02THE RIVER
06 07 nist-800-171/standardsNIST releases BloSS@M draft, a blockchain supply chain framework for federal software
IR 8500A marks the first NIST framework to embed blockchain-based provenance tracking directly into federal software acquisition, shifting compliance from retrospective audit to continuous, immutable record.08 09

