# A-026

- **Artifact ID:** A-026
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-026
- **Machine-record SHA-256:** `086f03bf6e26eef10505e94a286154ffa49ff2e1e29ac0b16329cb8230278217`

## Complete structured record

```json
{
  "id": "A-026",
  "statement": "Regulatory disclosure timelines assume detection capabilities that exist within the governed environment",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-07-24 — Enterprise financial platform KEV listing lag (July 2026): An enterprise financial platform was added to the CISA KEV catalog with an observed exploitation-to-listing lag of approximately 2.5 weeks. The four-business-day mandatory disclosure window begins at determination of a material incident; if organizational detection occurs 2.5 weeks into an active exploitation campaign, the detection precondition for the disclosure clock is not met. The gap between adversary action and organizational awareness is outside the scope of the regulatory timeline, which begins at determination, not at exploit."
  ],
  "evidence_count": 1,
  "last_updated": "2026-07-24",
  "related_positions": []
}
```
