Cybersecurity Maturity Model Certification
Cybersecurity Maturity Model Certification requirements are arriving in Financial & Capital Markets through a combination of direct Department of Defense contract obligations and downstream pressure from the U.S. Securities and Exchange Commission's cybersecurity disclosure rules and the Federal Financial Institutions Examination Council's updated examination procedures. Firms with any defense-adjacent lending, payments infrastructure, or contractor relationships are now reconciling CMMC Level 2 documentation requirements against existing NIST SP 800-171 gap assessments. The compliance question is no longer whether CMMC applies to financial firms; it is which business lines and third-party relationships pull them into scope.
Watch
- CMMC Level 2 final rule (32 CFR Part 170): effective date and contractor flow-down obligations
- SEC cybersecurity incident disclosure rule: 4-day Form 8-K filing clock for material breaches
- FFIEC examination updates incorporating NIST CSF 2.0 benchmarks for core institutions
- Third-party and vendor scoping: which fintech and cloud contracts trigger CMMC controlled unclassified information rules
Recent material activity in Financial & Capital Markets
Federal Reserve terminates cease-and-desist order against United Texas Bank and written agreement with Quontic entities
The Federal Reserve Board terminated two enforcement actions effective September 2, 2026. The terminations close a cease-and-desist order issued to United Texas Bank in August 2024 and a written agreement with Quontic Ba…
Read a full sample brief →Cboe Exchange files immediately effective rule change to implement an Order Entry Protocol Migration Program
On September 4, 2026, the SEC granted immediate effectiveness to a Cboe Exchange rule filing that amends its fee schedule to establish an Order Entry Protocol Migration Program. The filing signals a structured transition…
Read a full sample brief →Nasdaq files immediately effective rule change amending disciplinary code Rule 9558
On September 4, 2026, the SEC published Nasdaq's notice of filing for an immediately effective amendment to Rule 9558 of Nasdaq's Disciplinary Code. The amendment takes effect without a standard comment period under the …
Read a full sample brief →ESMA-SEBI MoU reopens the path for Indian CCP recognition under EMIR after a two-year suspension
ESMA signed a Memorandum of Understanding with the Securities and Exchange Board of India on September 4, 2026, covering supervisory cooperation and information exchange for Indian central counterparties. This agreement …
Read a full sample brief →SFC issues supervisory circular to licensed corporations, virtual asset service providers, and associated entities on brokers forum conduct
On September 4, 2026, the Securities and Futures Commission issued a circular to licensed corporations, SFC-licensed virtual asset service providers, and their associated entities, setting out conduct and supervisory exp…
Read a full sample brief →ASIC review finds cash settlements used in 63% of home insurance claims, flags systemic consumer harm risks
ASIC's August 31, 2026 review finds systemic failures in cash settlement practices across approximately 65% of the Australian home insurance market. The review identifies deficiencies in settlement adequacy, support for …
Read a full sample brief →Federal Court orders CashnGo to pay $3.5 million for unfair contract terms across 201,000 small-amount credit contracts
On 2 September 2026, the Federal Court imposed a $3.5 million penalty against Venture 5 Group Pty Ltd, trading as CashnGo, in proceedings brought by ASIC. The judgment declares multiple contract terms void, mandates opt-…
Read a full sample brief →ASIC secures insider trading conviction against former Beacon Minerals project manager following five-year prosecution
The Supreme Court of Western Australia sentenced Alexander John McCulloch on 25 August 2026 to 12 months' imprisonment for one count of insider trading under the Corporations Act 2001. McCulloch, a former project manager…
Read a full sample brief →South Korea's FSC expands network separation rule exemption to nonbank firms and electronic financial service providers for frontier AI cybersecurity testing
The Financial Services Commission announced on September 3, 2026 the second phase of its network separation rule easing, expanding eligibility beyond banks to nonbank financial companies and electronic financial service …
Read a full sample brief →SEBI announces review of derivative contract settlement price methodology following Centralized Accounting System rollout
SEBI's Press Release 53/2026, issued September 3, 2026, announces a review of settlement price methodology for derivative contracts. The review is tied to the Centralized Accounting System rollout, signaling a potential …
Read a full sample brief →