# CHQ-ED-2026-001

- **Artifact ID:** CHQ-ED-2026-001
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-001
- **Machine-record SHA-256:** `36ee9a3433c6a737474f42caa84b5eb7419ccd6e77a7a069405cd349224231db`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-001",
  "associated_position": "CHQ-P-2026-010 v1.0",
  "relationship": "original",
  "issuance_date": "2026-03-05",
  "evidence_freeze_time": "2026-03-05T16:00:00Z",
  "total_exhibits": 4,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [
    {
      "id": "CHQ-EX-2026-041",
      "source_type": "REGULATORY RULE + EXAMINATION GUIDANCE",
      "source_authority": "New York State Department of Financial Services (NYDFS)",
      "title": "NYDFS Cybersecurity Regulation 23 NYCRR Part 500 (2023 Amendments) and October 2025 Third-Party Service Provider Industry Guidance",
      "source_publication_date": "2023-11-01 (regulation); 2025-10-21 (guidance letter)",
      "source_urls": [
        {
          "label": "REGULATION",
          "url": "https://www.dfs.ny.gov/industry_guidance/cybersecurity"
        },
        {
          "label": "GUIDANCE",
          "url": "https://www.dfs.ny.gov/industry_guidance/cybersecurity"
        }
      ],
      "capture_date": "2026-03-05",
      "capture_method": "Primary source review; regulatory text and guidance letter public record",
      "relevant_sections": [
        "§500.12 Multi-Factor Authentication (full compliance November 1, 2025)",
        "§500.17 Certification of Compliance (April 15, 2026 deadline)",
        "§500.11 Third-Party Service Provider Security Policy",
        "§500.4(a) CISO designation and annual certification signature requirement",
        "FAQ 18–23 (MFA operationalization, SSO, and cloud system coverage)",
        "October 2025 Industry Letter: TPSP due diligence, monitoring, and non-delegability of compliance"
      ],
      "notes": "Final phase of 2023 amendments activated November 1, 2025. This is the first certification cycle in which all amended requirements are simultaneously in force."
    },
    {
      "id": "CHQ-EX-2026-042",
      "source_type": "NATIONAL STATUTE",
      "source_authority": "Federal Republic of Germany / Federal Office for Information Security (BSI)",
      "title": "BSI Act (BSIG) as amended by NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), December 2025",
      "source_publication_date": "2025-12-06 (entry into force)",
      "source_urls": [
        {
          "label": "BSI",
          "url": "https://www.bsi.bund.de"
        }
      ],
      "capture_date": "2026-03-05",
      "capture_method": "Primary source review; official federal gazette and BSI public documentation",
      "relevant_sections": [
        "Section 28: Entity classification (particularly important / important entities)",
        "Section 38: Personal liability of management bodies for failure to approve and oversee cybersecurity risk-management measures",
        "Section 61–62: Supervisory and enforcement powers (inspection rights, binding orders)",
        "Section 65: Sanctions regime (up to €10M or 2% global annual turnover for particularly important entities)",
        "Registration obligation: mandatory within three months of entry into force (April 2026 deadline)"
      ],
      "notes": "Section 38 liability activates on governance failure without requiring a breach event. Germany is the first major EU economy to complete NIS2 transposition via amended BSI Act."
    },
    {
      "id": "CHQ-EX-2026-043",
      "source_type": "STANDARDS BODY BALLOT",
      "source_authority": "CA/Browser Forum",
      "title": "Ballot SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods",
      "source_publication_date": "2025-04-11 (vote closed)",
      "source_urls": [
        {
          "label": "BALLOT",
          "url": "https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/"
        }
      ],
      "capture_date": "2026-03-05",
      "capture_method": "Primary source review; CA/B Forum public ballot record",
      "ballot_status": "PASSED",
      "relevant_sections": [
        "Phased schedule: 398 days → 200 days (March 15, 2026) → 100 days (March 15, 2027) → 47 days (March 15, 2029)",
        "Domain Control Validation reuse: 398 days → 200 days (March 15, 2026) → 10 days (March 15, 2029)",
        "Subject Identity Information reuse: 825 days → 398 days (March 15, 2026)",
        "Scope: publicly trusted TLS certificates only; private PKI and internal certificates not governed by this ballot",
        "Vote: 29 in favor, 0 opposed, 5 abstentions"
      ],
      "notes": "At 47-day maximum lifetime, automated renewal is operationally necessary. Manual renewal at that frequency is not viable at enterprise scale."
    },
    {
      "id": "CHQ-EX-2026-044",
      "source_type": "LEGISLATIVE TEXT (COMMITTEE STAGE)",
      "source_authority": "UK Parliament / Home Office",
      "title": "Cyber Security and Resilience (Network and Information Systems) Bill 2024–26; Home Office ransomware consultation response (December 2025)",
      "source_publication_date": "2025-11-12 (bill introduction); 2026-02-24 (committee compilation current as of this docket)",
      "source_urls": [
        {
          "label": "BILL",
          "url": "https://bills.parliament.uk/bills/4035"
        },
        {
          "label": "CONSULTATION",
          "url": "https://www.gov.uk/government/consultations/ransomware-proposals-to-increase-incident-reporting-and-reduce-payments-to-criminals"
        }
      ],
      "capture_date": "2026-03-05",
      "capture_method": "Primary source review; parliamentary publications and Home Office public record",
      "relevant_sections": [
        "Bill scope: 900–1,100 managed service providers (new category); commercial data centres ≥1MW designated essential services",
        "Mandatory ransomware incident reporting: retained in bill; economy-wide vs. threshold applicability not confirmed",
        "Ransomware payment ban: removed from bill; placed into separate Home Office consultation (open as of March 5, 2026)",
        "Secondary legislation: most substantive obligations require secondary legislation to take effect",
        "Timeline: enactment targeted spring 2026; seven committee stages completed February 24, 2026"
      ],
      "notes": "",
      "evidence_status_note": "This exhibit is legislative draft text, not enacted law. Characterised in CHQ-P-2026-010 v1.0 as prospective enforcement alignment, not active enforcement."
    }
  ],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Position Statement ¶2",
      "claim_text": "NYDFS Part 500 enters its first full examination cycle under the 2023 amended regulation. Examiners are testing whether requirements have been operationalized: MFA across all systems including SSO and third-party access, asset inventory currency, and TPSP due diligence documentation.",
      "evidence_exhibits": [
        "CHQ-EX-2026-041"
      ],
      "relevant_sections": "§500.12 (MFA), §500.17 (certification), FAQ 18–23 (MFA operationalization scope), October 2025 TPSP guidance",
      "verification_type": "REGULATORY TEXT + EXAMINATION GUIDANCE + REGULATORY FAQ"
    },
    {
      "claim_id": "C-02",
      "position_section": "Position Statement ¶2",
      "claim_text": "The certification, due April 15, 2026, must be signed by both the CISO and the highest-ranking executive.",
      "evidence_exhibits": [
        "CHQ-EX-2026-041"
      ],
      "relevant_sections": "§500.17(b); §500.4(a) CISO designation requirement",
      "verification_type": "REGULATORY TEXT"
    },
    {
      "claim_id": "C-03",
      "position_section": "Position Statement ¶3",
      "claim_text": "Germany’s BSI Act Section 38 introduces personal liability for members of management bodies for failure to approve and oversee cybersecurity risk-management measures. The liability provision does not require a breach. It activates on governance failure.",
      "evidence_exhibits": [
        "CHQ-EX-2026-042"
      ],
      "relevant_sections": "Section 38 (management body liability); Section 65 (sanctions)",
      "verification_type": "NATIONAL STATUTE"
    },
    {
      "claim_id": "C-04",
      "position_section": "Position Statement ¶3",
      "claim_text": "Registration with the Federal Office for Information Security is mandatory by April 2026.",
      "evidence_exhibits": [
        "CHQ-EX-2026-042"
      ],
      "relevant_sections": "Registration obligation (three months from December 6, 2025 entry into force)",
      "verification_type": "NATIONAL STATUTE"
    },
    {
      "claim_id": "C-05",
      "position_section": "Position Statement ¶4",
      "claim_text": "CA/Browser Forum voted April 11, 2025 to compress maximum TLS certificate lifetimes from 398 days to 47 days through a phased schedule. Phase one takes effect March 15, 2026: maximum lifetime drops to 200 days. The ballot passed 29 to zero.",
      "evidence_exhibits": [
        "CHQ-EX-2026-043"
      ],
      "relevant_sections": "Ballot SC-081v3 phased schedule; vote record",
      "verification_type": "STANDARDS BODY BALLOT TEXT"
    },
    {
      "claim_id": "C-06",
      "position_section": "Position Statement ¶4",
      "claim_text": "DigiCert stopped issuing certificates exceeding 199 days effective February 24, 2026.",
      "evidence_exhibits": [
        "CHQ-EX-2026-043"
      ],
      "relevant_sections": "",
      "verification_type": "MARKET ACTION — VENDOR OPERATIONAL NOTICE"
    },
    {
      "claim_id": "C-07",
      "position_section": "Position Statement ¶5",
      "claim_text": "The UK Cyber Security and Resilience Bill completed seven committee stages as of February 24, 2026. Mandatory ransomware incident reporting is retained. Whether the obligation applies economy-wide or above a size threshold remains undetermined.",
      "evidence_exhibits": [
        "CHQ-EX-2026-044"
      ],
      "relevant_sections": "Committee compilation February 24, 2026; bill scope provisions",
      "verification_type": "LEGISLATIVE TEXT (COMMITTEE STAGE)",
      "classification_note": "Prospective enforcement alignment, not active enforcement."
    },
    {
      "claim_id": "C-08",
      "position_section": "Structural Observation",
      "claim_text": "Germany’s April 2026 BSI registration deadline coincides with the NYDFS certification window. Both require governance documentation. Neither accepts the other’s format.",
      "evidence_exhibits": [
        "CHQ-EX-2026-041",
        "CHQ-EX-2026-042"
      ],
      "relevant_sections": "",
      "verification_type": "REGULATORY TEXT (CROSS-REGIME COMPARISON)"
    },
    {
      "claim_id": "C-09",
      "position_section": "Structural Observation",
      "claim_text": "An organization operating across DORA, NYDFS Part 500, UK NIS, and the forthcoming UK CS&R obligations faces four active incident notification regimes. A ransomware event triggers all four simultaneously. Three of the four have defined timelines. The fourth is still being written.",
      "evidence_exhibits": [
        "CHQ-EX-2026-041",
        "CHQ-EX-2026-042",
        "CHQ-EX-2026-044"
      ],
      "relevant_sections": "",
      "verification_type": "CROSS-REGIME STRUCTURAL ANALYSIS"
    }
  ],
  "signals": [
    {
      "signal_id": "SIG-033",
      "signal_type": "REGULATORY ENFORCEMENT SHIFT",
      "classification": "NYDFS Part 500 first full examination cycle; operational examination of MFA, TPSP governance, asset inventory",
      "evidence_exhibits": [
        "CHQ-EX-2026-041"
      ]
    },
    {
      "signal_id": "SIG-034",
      "signal_type": "STATUTORY LIABILITY SHIFT",
      "classification": "Germany BSI Act Section 38; personal management liability activating on governance failure without breach requirement",
      "evidence_exhibits": [
        "CHQ-EX-2026-042"
      ]
    },
    {
      "signal_id": "SIG-035",
      "signal_type": "STANDARDS BODY ARCHITECTURAL PRESSURE",
      "classification": "CA/B Forum SC-081v3; certificate lifetime compression removing manual renewal as viable posture at scale for publicly trusted TLS certificates",
      "evidence_exhibits": [
        "CHQ-EX-2026-043"
      ]
    },
    {
      "signal_id": "SIG-036",
      "signal_type": "PROSPECTIVE LEGISLATIVE ALIGNMENT",
      "classification": "UK CS&R Bill; reporting regime expansion with scope unconfirmed; ransomware payment prohibition moved to separate consultation",
      "evidence_exhibits": [
        "CHQ-EX-2026-044"
      ]
    }
  ],
  "integrity_statement": [
    "All exhibits referenced in this docket were reviewed against primary sources prior to issuance of CHQ-P-2026-010 v1.0 on 2026-03-05.",
    "Retrieval of original sources after this date may produce different text due to subsequent regulatory amendments, website updates, or legislative progression. The captured records used in this docket represent the state of each source at the evidence freeze time: 2026-03-05T16:00:00Z.",
    "CHQ-EX-2026-044 reflects legislative draft text as of committee stage completion February 24, 2026. This exhibit will require a new version if the bill is amended, enacted, or withdrawn. Any such development triggers a docket amendment and a corresponding Position version review.",
    "Docket update policy: APPEND_ONLY. Existing exhibit records and claim mappings are not modified after issuance. New exhibits or updated legislative status are added as versioned amendments with their own timestamps."
  ],
  "docket_hash": "fdcf98ca54d0e701e154c8c1ee4ac7dde2a2399866a09ecf99ce18a9c7d83844",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-001 Docket Hash",
      "scope": "the evidence record (exhibit registry + claim mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-010 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
