BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Rulebook//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (Rulebook)
X-WR-CALDESC:Compliance deadlines tracked at rulebook.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-192@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California AI Transparency Act (SB 942): Capture device manufacture
 r duties
DESCRIPTION:Capture device manufacturer provenance requirements become oper
 ative.\n\nCalifornia AI Transparency Act (SB 942\, Stats. 2024\, ch. 291)\
 , as amended by AB 853 (Stats. 2025\, ch. 674) (California)\n\nSource: htt
 ps://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=20252026
 0AB853\n\nhttps://rulebook.fru.dev/regulations/us-ca-sb942
URL:https://rulebook.fru.dev/regulations/us-ca-sb942
CATEGORIES:California,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-180@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:California Delete Act / DROP: Independent third-party audits begin
DESCRIPTION:Beginning Jan 1\, 2028 and every 3 years thereafter\, data brok
 ers must undergo an independent audit of Delete Act compliance.\n\nCalifor
 nia Delete Act (SB 362\, 2023)\, Cal. Civ. Code 1798.99.80 et seq.\, and D
 ROP regulations (California)\n\nSource: https://www.cppa.ca.gov/data_broke
 rs/\n\nhttps://rulebook.fru.dev/regulations/us-ca-delete-act
URL:https://rulebook.fru.dev/regulations/us-ca-delete-act
CATEGORIES:California,privacy,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-315@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280101
DTEND;VALUE=DATE:20280102
SUMMARY:Vermont VDPOSA: Vermont Data Privacy and Online Surveillance Act ta
 kes effect
DESCRIPTION:All obligations under Act 145 apply (sec. 4).\n\nVermont Data P
 rivacy and Online Surveillance Act (S.71\, Act 145 of 2026) (Vermont)\n\nS
 ource: https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT145/ACT
 145%20As%20Enacted.pdf\n\nhttps://rulebook.fru.dev/regulations/us-vt-vdpos
 a
URL:https://rulebook.fru.dev/regulations/us-vt-vdposa
CATEGORIES:Vermont,privacy,health,ai
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regula
 tions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://rulebook.fru.dev/regulat
 ions/us-ca-ccpa
URL:https://rulebook.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://rulebook.fru.dev/regulatio
 ns/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-45@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: High-risk obligations apply to Annex I product-embedded 
 systems
DESCRIPTION:Chapter III Sections 1-3 apply to AI systems classified high-ri
 sk under Art 6(1) and Annex I (safety components of products covered by EU
  harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2
 026/1744.\n\nRegulation (EU) 2024/1689 laying down harmonised rules on art
 ificial intelligence (Artificial Intelligence Act)\, as amended by Regulat
 ion (EU) 2026/1744 (Digital Omnibus on AI) (European Union)\n\nSource: htt
 ps://eur-lex.europa.eu/eli/reg/2026/1744/oj\n\nhttps://rulebook.fru.dev/re
 gulations/eu-ai-act
URL:https://rulebook.fru.dev/regulations/eu-ai-act
CATEGORIES:European Union,ai,biometrics,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://rulebook.fru.dev/regulations/eu-cra
URL:https://rulebook.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-62@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20280912
DTEND;VALUE=DATE:20280913
SUMMARY:EU Data Act: Commission evaluation
DESCRIPTION:Commission evaluation report due\, including the impact of clou
 d switching rules (Arts 23-31) (Art 49(2)).\n\nRegulation (EU) 2023/2854 o
 n harmonised rules on fair access to and use of data (Data Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2023/2854/oj\n\nhttps:
 //rulebook.fru.dev/regulations/eu-data-act
URL:https://rulebook.fru.dev/regulations/eu-data-act
CATEGORIES:European Union,data-access,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-222@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20281001
DTEND;VALUE=DATE:20281002
SUMMARY:Connecticut Data Privacy Act (CTDPA): Data brokers must process sta
 te deletion mechanism requests
DESCRIPTION:Registered data brokers must access the DCP accessible deletion
  mechanism at least every 45 days and process deletion requests.\n\nConnec
 ticut Data Privacy Act (Public Act 22-15)\, Conn. Gen. Stat. 42-515 et seq
 .\, as amended by Public Act 25-113 (SB 1295) and Public Act 26-64 (SB 4) 
 (Connecticut)\n\nSource: https://www.cga.ct.gov/2026/ACT/PA/PDF/2026PA-000
 64-R00SB-00004-PA.PDF\n\nhttps://rulebook.fru.dev/regulations/us-ct-ctdpa
URL:https://rulebook.fru.dev/regulations/us-ct-ctdpa
CATEGORIES:Connecticut,privacy,children,ai,health
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260924T132329Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://rulebook.fru.dev/regulations/us-cmmc
URL:https://rulebook.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
