<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance on</title><link>https://waypointca.com/blog/tags/compliance/</link><description>Recent content in Compliance on</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://waypointca.com/blog/tags/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>CMMC Phase 2 Is Suspended. Your Legal Exposure Went Up.</title><link>https://waypointca.com/blog/posts/cmmc-phase-2-suspended-self-reporting-risk/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/cmmc-phase-2-suspended-self-reporting-risk/</guid><description>The certification deadline is gone. The obligations are not, and the one government mechanism that used to catch a bad SPRS score before a lawyer did is paused. Here is what defense contractors should actually be working on.</description></item><item><title>FedRAMP 20x Turns Compliance Into Code</title><link>https://waypointca.com/blog/posts/fedramp-20x-compliance-becomes-code/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/fedramp-20x-compliance-becomes-code/</guid><description>20x is not a version bump. It replaces narrative control descriptions with automated Key Security Indicators, replaces the annual audit with continuous validation, and replaces documents with machine-readable data. Here is what that actually demands of a cloud service provider.</description></item><item><title>Florida Gave You the Mandate, Vetoed the Safe Harbor, and Just Funded the Fix</title><link>https://waypointca.com/blog/posts/florida-cybersecurity-mandates-no-safe-harbor/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/florida-cybersecurity-mandates-no-safe-harbor/</guid><description>Florida is one of the few states that mandates a cybersecurity framework by statute. The alignment deadlines have already passed, the liability safe harbor was vetoed, and as of July 1 there is finally state money on the table. Here is what actually applies to Florida agencies, counties, and cities.</description></item><item><title>Your FedRAMP Package Has to Be Machine-Readable by September 30</title><link>https://waypointca.com/blog/posts/fedramp-machine-readable-september-30-deadline/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/fedramp-machine-readable-september-30-deadline/</guid><description>RFC-0024&amp;rsquo;s machine-readable package requirements were confirmed in NTC-0009 and finalized in the Consolidated Rules for 2026, with initial compliance due September 30, 2026. They apply to existing Rev 5 certifications, not just new applicants, and most providers have not started.</description></item><item><title>Five HIPAA SRA Mistakes That Get Practices Fined</title><link>https://waypointca.com/blog/posts/hipaa-sra-mistakes/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/hipaa-sra-mistakes/</guid><description>Most security risk assessments fail on the same handful of gaps. We walk through the findings HHS OCR flags most often and how to close them before an audit.</description></item><item><title>CMMC Level 2 for Small Businesses: What Actually Changed</title><link>https://waypointca.com/blog/posts/cmmc-level-2-small-business/</link><pubDate>Sat, 14 Mar 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/cmmc-level-2-small-business/</guid><description>The final rule is live. Here is what small defense contractors need to know about scoping, POA&amp;amp;M timelines, and what assessors are actually looking for.</description></item></channel></rss>