“Systemically important” is borrowed from financial regulation, where it triggers obligations. Applied to FFmpeg and the kernel it triggers nothing.
Two regimes trying different approaches produce evidence a single harmonised one cannot. Nobody knows whether 24 hours beats 72.
The mechanism works. Its scope is defined by the wrong boundary — these incidents are not sector-shaped.
Criticality is emergent — it comes from how many organisations happen to depend on you, which is not visible from outside.
For a large company the regulator is not the most expensive consequence of a failure. The failure is.
The fact travels immediately; the detail follows when it is reliable. It is the structure this desk asked for at 25-1027.
The regime being amended was made in 2018. Almost nothing in this corpus existed in its current form then.
It asks whether a record is trustworthy, not whether an adversary could reach the system holding it.
Data integrity rules exist because a falsified batch record is a patient safety issue — and they describe exactly what an attacker would need to alter.
The data followed the obligation and the supervision did not follow the data.
A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage.
What that population needs is not an obligation. It is secure defaults in the products they already buy.
The first instrument in this corpus that reaches the organisation the customer has never heard of — and it regulates availability, not just data.