BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-269@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20170301
DTEND;VALUE=DATE:20170302
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Part 500 effective
DESCRIPTION:Original cybersecurity regulation takes effect.\n\nNew York DFS
  Cybersecurity Requirements for Financial Services Companies (23 NYCRR Par
 t 500)\, Second Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cyb
 ersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny
 -dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-31@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20170601
DTEND;VALUE=DATE:20170602
SUMMARY:China Cybersecurity Law: Cybersecurity Law takes effect
DESCRIPTION:Original CSL obligations for network operators and CII operator
 s apply.\n\nCybersecurity Law of the People's Republic of China (as amende
 d by the NPC Standing Committee Decision of 28 October 2025) (China)\n\nSo
 urce: https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttp
 s://rulebook.fru.dev/regulations/cn-csl
URL:https://rulebook.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-164@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20200101
DTEND;VALUE=DATE:20200102
SUMMARY:CCPA / CPRA: CCPA takes effect
DESCRIPTION:Original CCPA consumer rights and business obligations take eff
 ect.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Califo
 rnia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA
  regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSour
 ce: https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nh
 ttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-33@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20210901
DTEND;VALUE=DATE:20210902
SUMMARY:China Data Security Law: Data Security Law takes effect
DESCRIPTION:Data classification\, important-data protection and data export
  restrictions apply (Art. 55).\n\nData Security Law of the People's Republ
 ic of China (China)\n\nSource: http://www.cac.gov.cn/2021-06/11/c_16249945
 66919140.htm\n\nhttps://rulebook.fru.dev/regulations/cn-dsl
URL:https://rulebook.fru.dev/regulations/cn-dsl
CATEGORIES:China,cybersecurity,data-residency,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://rulebook.fru.
 dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-70@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:DORA: DORA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 333 of 27 Dec 2022 (Art 64).\n\nRegulation (EU) 2022/2554 on digital op
 erational resilience for the financial sector (Digital Operational Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 2/2554/oj\n\nhttps://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-98@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:NIS2: NIS2 enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in OJ L 333 of 27 Dec 2022.\n\nDirective (EU) 2022/2555 on measures f
 or a high common level of cybersecurity across the Union (NIS2 Directive) 
 (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
 \n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://rulebook.
 fru.dev/regulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://rulebook.fru.dev/regulations/us-fcc-cpni-breach
URL:https://rulebook.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/r
 egulations/us-glba-safeguards
URL:https://rulebook.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://rulebo
 ok.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://rulebook.fru.dev/regulations/us-circia
URL:https://rulebook.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-99@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:NIS2: Transposition deadline
DESCRIPTION:Member States had to adopt and publish national transposing mea
 sures by 17 Oct 2024 (Art 41(1)).\n\nDirective (EU) 2022/2555 on measures 
 for a high common level of cybersecurity across the Union (NIS2 Directive)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/o
 j\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-100@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241018
DTEND;VALUE=DATE:20241019
SUMMARY:NIS2: National NIS2 measures apply\; NIS1 repealed
DESCRIPTION:Member States apply their NIS2 measures from 18 Oct 2024 and Di
 rective (EU) 2016/1148 (NIS1) is repealed (Arts 41(1)\, 44).\n\nDirective 
 (EU) 2022/2555 on measures for a high common level of cybersecurity across
  the Union (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-ni
 s2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.fru.dev/reg
 ulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-101@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241107
DTEND;VALUE=DATE:20241108
SUMMARY:NIS2: Implementing Regulation 2024/2690 enters into force
DESCRIPTION:Commission Implementing Regulation (EU) 2024/2690 (published 18
  Oct 2024) sets technical risk-management measures and significant-inciden
 t thresholds for DNS\, TLD\, cloud\, data centre\, CDN\, managed (security
 ) service providers\, online marketplaces\, search engines\, social networ
 ks and trust service providers.\n\nDirective (EU) 2022/2555 on measures fo
 r a high common level of cybersecurity across the Union (NIS2 Directive) (
 European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/269
 0/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-106@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241208
DTEND;VALUE=DATE:20241209
SUMMARY:Product Liability Directive: New PLD enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in the OJ on 18 Nov 2024 (Art 23).\n\nDirective (EU) 2024/2853 on lia
 bility for defective products (new Product Liability Directive) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-pld
URL:https://rulebook.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-48@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Cyber Resilience Act: CRA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 20 Nov 2024 (Art 71(1)).\n\nRegulation (EU) 2024/2847 on horizonta
 l cybersecurity requirements for products with digital elements (Cyber Res
 ilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 /2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://rulebook.fru.dev/regulations
 /us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-194@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241216
DTEND;VALUE=DATE:20241217
SUMMARY:CMMC 2.0: CMMC Program rule (32 CFR Part 170) effective
DESCRIPTION:The program rule establishing CMMC levels and assessment proces
 ses took effect\; contract enforcement awaited the DFARS rule.\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://rulebook.fru.dev/regulations/us-sec-cyber
URL:https://rulebook.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://rulebook.fru.dev/regulations/cn-network-data-regs
URL:https://rulebook.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://rulebook.fru.dev/regulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://rulebook.fru.dev/regulations/us-hip
 aa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://rulebook.fru.dev/
 regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://rulebook.fru.dev/regulations/eu
 -dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://rulebook.fru.dev/
 regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://rulebook.fru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://rule
 book.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://rulebook.fru.dev/regulations/us-doj-bulk-data
URL:https://rulebook.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://rulebook.fru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://rulebook.fru.dev/regulati
 ons/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/reg
 ulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://rulebook.fru.dev/regula
 tions/eu-dora
URL:https://rulebook.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-3@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware rep
 orting moves to compliance phase
DESCRIPTION:The education-first phase (30 May-31 Dec 2025) ends\; Home Affa
 irs moves to a compliance and education approach for missed reports.\n\nCy
 ber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporti
 ng) Rules 2025 (Australia)\n\nSource: https://www.homeaffairs.gov.au/cyber
 -security-subsite/files/factsheet-ransomware-payment-reporting.pdf\n\nhttp
 s://rulebook.fru.dev/regulations/au-cyber-security-act
URL:https://rulebook.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-168@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:CCPA / CPRA: New CCPA regulations take effect
DESCRIPTION:ADMT\, risk assessment\, cybersecurity audit and updated CCPA r
 egulations become effective\; risk assessments required for new high-risk 
 processing.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the
  California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) a
 nd CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\
 n\nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://ru
 lebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-32@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:China Cybersecurity Law: 2025 amendments take effect
DESCRIPTION:Higher fines\, first-violation fines\, AI governance provisions
  and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.\n\n
 Cybersecurity Law of the People's Republic of China (as amended by the NPC
  Standing Committee Decision of 28 October 2025) (China)\n\nSource: https:
 //www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttps://rulebook
 .fru.dev/regulations/cn-csl
URL:https://rulebook.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-111@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Hong Kong Critical Infrastructure Cyber Ordinance: PCICSO comes int
 o operation
DESCRIPTION:Commissioner's Office is established and designation of CIOs be
 gins\; obligations apply to designated operators.\n\nProtection of Critica
 l Infrastructures (Computer Systems) Ordinance (Cap. 653) (Hong Kong)\n\nS
 ource: https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm\n\
 nhttps://rulebook.fru.dev/regulations/hk-pcico
URL:https://rulebook.fru.dev/regulations/hk-pcico
CATEGORIES:Hong Kong,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://rulebook.fru.dev/regulations/us-hipaa
URL:https://rulebook.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-277@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260415
DTEND;VALUE=DATE:20260416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Annual certification or acknowledgment covering calendar year 2
 025 due.\n\nNew York DFS Cybersecurity Requirements for Financial Services
  Companies (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: ht
 tps://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://rulebook.f
 ru.dev/regulations/us-ny-dfs-500
URL:https://rulebook.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-297@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260603
DTEND;VALUE=DATE:20260604
SUMMARY:SEC Regulation S-P: Smaller entities must comply
DESCRIPTION:Smaller covered institutions (24 months after Federal Register 
 publication) must comply with the amended Regulation S-P.\n\nRegulation S-
 P: Privacy of Consumer Financial Information and Safeguarding Customer Inf
 ormation (2024 amendments) (United States (Federal))\n\nSource: https://ww
 w.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-priva
 cy-of-consumer-financial-information-and-safeguarding-customer-information
 \n\nhttps://rulebook.fru.dev/regulations/us-sec-reg-sp
URL:https://rulebook.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-49@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260611
DTEND;VALUE=DATE:20260612
SUMMARY:Cyber Resilience Act: Conformity assessment body provisions apply
DESCRIPTION:Chapter IV (Arts 35-51\, notification of conformity assessment 
 bodies) applies (Art 71(2)).\n\nRegulation (EU) 2024/2847 on horizontal cy
 bersecurity requirements for products with digital elements (Cyber Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 4/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-17@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-8 / CCSPA: Royal Assent
DESCRIPTION:Bill C-8 receives Royal Assent (S.C. 2026\, c. 9)\; Telecommuni
 cations Act amendments take effect.\n\nCritical Cyber Systems Protection A
 ct (enacted by Bill C-8\, An Act respecting cyber security) (Canada)\n\nSo
 urce: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttps://rulebook.f
 ru.dev/regulations/ca-ccspa
URL:https://rulebook.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-146@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260616
DTEND;VALUE=DATE:20260617
SUMMARY:UK Cyber Security and Resilience Bill: Passes House of Commons
DESCRIPTION:Report stage and third reading completed in the Commons after c
 arry-over into the new session.\n\nCyber Security and Resilience (Network 
 and Information Systems) Bill (United Kingdom)\n\nSource: https://bills.pa
 rliament.uk/bills/4035\n\nhttps://rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-50@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligati
 ons apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabil
 ities and severe incidents (24-hour early warning\, 72-hour notification) 
 via the single reporting platform. Also covers products placed on the mark
 et before 11 Dec 2027 (Art 69(3)).\n\nRegulation (EU) 2024/2847 on horizon
 tal cybersecurity requirements for products with digital elements (Cyber R
 esilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-147@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage scheduled
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\, 
 3 and 7 Sept 2026).\n\nTentative: depends on a proposal not yet adopted.\n
 \nCyber Security and Resilience (Network and Information Systems) Bill (Un
 ited Kingdom)\n\nSource: https://bills.parliament.uk/bills/4035\n\nhttps:/
 /rulebook.fru.dev/regulations/uk-csr-bill
URL:https://rulebook.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-196@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1\; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 
 170.3(e)(2)).\n\nCybersecurity Maturity Model Certification (CMMC) Program
  (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 21
 7\, 252) (United States (Federal))\n\nSource: https://www.federalregister.
 gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certifica
 tion-cmmc-program\n\nhttps://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-107@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
SUMMARY:Product Liability Directive: Transposition deadline\; old PLD repea
 led
DESCRIPTION:Member States must transpose by 9 Dec 2026 (Art 22). Directive 
 85/374/EEC is repealed from that date but still applies to products placed
  on the market before it (Art 21).\n\nDirective (EU) 2024/2853 on liabilit
 y for defective products (new Product Liability Directive) (European Union
 )\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps://rul
 ebook.fru.dev/regulations/eu-pld
URL:https://rulebook.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://rulebook.
 fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://rulebook.fru.dev/regulations/eu-nis2
URL:https://rulebook.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regula
 tions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://rulebook.fru.dev/regulations/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulatio
 ns/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-54@regulations.fru.dev
DTSTAMP:20260924T132629Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four years
  (Art 70(1)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity req
 uirements for products with digital elements (Cyber Resilience Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n\nht
 tps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
