Skip to content
Jurisdiction ยท 12 regulations

United States (Federal): data, AI and cyber laws

12 regulations in United States (Federal) that affect companies handling data: CIRCIA, CMMC 2.0, COPPA Rule, DOJ Bulk Data Rule, FCC CPNI Breach Rule, FTC Health Breach Notification Rule, GLBA Safeguards Rule, HIPAA, PADFA, SEC Cyber Disclosure Rules, SEC Regulation S-P, TAKE IT DOWN Act. Part of US Federal.

  • CMMC 2.0

    United States (Federal)

    In forceCybersecurity

    Next: Nov 10, 2026 Phase 2: Level 2 C3PAO certification

  • CIRCIA

    United States (Federal)

    EnactedCybersecurityBreach notification

  • COPPA Rule

    United States (Federal)

    AmendedPrivacyChildren

    Effective Apr 21, 2000

  • DOJ Bulk Data Rule

    United States (Federal)

    In forcePrivacyData residency

    Effective Apr 8, 2025

  • FCC CPNI Breach Rule

    United States (Federal)

    AmendedPrivacyBreach notification

    Effective Mar 13, 2024

  • AmendedHealth dataPrivacy

    Effective Sep 24, 2009

  • GLBA Safeguards Rule

    United States (Federal)

    AmendedFinancialCybersecurity

    Effective May 23, 2003

  • HIPAA

    United States (Federal)

    AmendedPrivacyHealth data

    Effective Apr 14, 2003

  • PADFA

    United States (Federal)

    In forcePrivacyData residency

    Effective Jun 23, 2024

  • SEC Cyber Disclosure Rules

    United States (Federal)

    In forceCybersecurityBreach notification

    Effective Sep 5, 2023

  • SEC Regulation S-P

    United States (Federal)

    AmendedFinancialPrivacy

    Effective Aug 2, 2024

  • TAKE IT DOWN Act

    United States (Federal)

    In forceOnline safetyAI

    Effective May 19, 2025

Upcoming deadlines

November 20261 deadline

  1. CMMC 2.0

    Phase 2: Level 2 C3PAO certification

    Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).

    Compliance deadlinein 47 daysSource

November 20271 deadline

  1. CMMC 2.0

    Phase 3: Level 3 certification

    Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requirements added to applicable solicitations (32 CFR 170.3(e)(3)).

    Compliance deadlinein 14 monthsSource

November 20281 deadline

  1. CMMC 2.0

    Phase 4: full implementation

    CMMC requirements included in all applicable DoD solicitations and contracts, including option periods (32 CFR 170.3(e)(4)).

    Compliance deadlinein 2.1 yearsSource

Past deadlines

June 20261 deadline

  1. SEC Regulation S-P

    Smaller entities must comply

    Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.

    Compliance deadline4 months agoSource

May 20261 deadline

  1. TAKE IT DOWN Act

    Platform notice-and-removal process required

    Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).

    Compliance deadline4 months agoSource

April 20261 deadline

  1. COPPA Rule

    Full compliance with amended COPPA Rule

    Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.

    Compliance deadline5 months agoSource

February 20261 deadline

  1. HIPAA

    Notice of Privacy Practices updates (Part 2 alignment)

    Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.

    Compliance deadline7 months agoSource

December 20251 deadline

  1. SEC Regulation S-P

    Larger entities must comply

    Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.

    Compliance deadline10 months agoSource

November 20251 deadline

  1. CMMC 2.0

    DFARS rule effective; Phase 1 begins

    CMMC Level 1 and Level 2 self-assessment requirements begin appearing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).

    Takes effect10 months agoSource

October 20251 deadline

  1. DOJ Bulk Data Rule

    Due diligence, audit and reporting obligations apply

    Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.

    Compliance deadline12 months agoSource

June 20251 deadline

  1. COPPA Rule

    Amended COPPA Rule takes effect

    The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.

    Takes effect15 months agoSource

May 20251 deadline

  1. TAKE IT DOWN Act

    Criminal provisions effective on enactment

    Publishing or threatening to publish non-consensual intimate images, including digital forgeries, became a federal crime upon signature.

    Takes effect16 months agoSource

April 20251 deadline

  1. DOJ Bulk Data Rule

    Prohibitions and restrictions take effect

    Core prohibitions on covered data transactions and security requirements for restricted transactions apply.

    Takes effect18 months agoSource

March 20251 deadline

  1. HIPAA

    Security Rule NPRM comment period closed

    Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.

    Transition19 months agoSource

December 20244 deadlines

  1. HIPAA

    Reproductive health privacy compliance date (vacated)

    Original compliance date for the reproductive health care privacy provisions, including the attestation requirement; these provisions no longer apply after the June 2025 vacatur.

    Compliance deadline21 months agoSource
  2. SEC Cyber Disclosure Rules

    Inline XBRL tagging of Item 1.05 disclosures

    Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.

    Compliance deadline21 months agoSource
  3. CMMC 2.0

    CMMC Program rule (32 CFR Part 170) effective

    The program rule establishing CMMC levels and assessment processes took effect; contract enforcement awaited the DFARS rule.

    Takes effect21 months agoSource
  4. SEC Cyber Disclosure Rules

    Inline XBRL tagging of annual cybersecurity disclosures

    Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.

    Compliance deadline21 months agoSource

August 20241 deadline

  1. SEC Regulation S-P

    Amendments effective

    The Regulation S-P amendments became effective; compliance tiered by entity size.

    Takes effect2.1 years agoSource

July 20242 deadlines

  1. 2024 amendments effective

    Amendments clarifying health app coverage, unauthorized disclosure as breach, email notice and FTC notice timing took effect.

    Takes effect2.2 years agoSource
  2. CIRCIA

    NPRM comment period closed

    Extended comment period on the CIRCIA proposed rule closed.

    Transition2.2 years agoSource

June 20243 deadlines

  1. HIPAA

    Reproductive health care privacy rule effective (later vacated)

    The HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976) took effect; it was vacated nationwide on June 18, 2025 in Purl v. HHS (N.D. Tex.).

    Takes effect2.2 years agoSource
  2. PADFA

    PADFA takes effect

    The prohibition takes effect 60 days after enactment (April 24, 2024).

    Takes effect2.3 years agoSource
  3. SEC Cyber Disclosure Rules

    Smaller reporting companies: Item 1.05 compliance

    Smaller reporting companies must begin complying with Form 8-K Item 1.05 incident disclosure.

    Compliance deadline2.3 years agoSource

May 20241 deadline

  1. GLBA Safeguards Rule

    FTC breach notification requirement effective

    Section 314.4(j) requires notice to the FTC within 30 days of discovering a notification event involving at least 500 consumers.

    Takes effect2.4 years agoSource

March 20241 deadline

  1. FCC CPNI Breach Rule

    Order effective except revised notification rules

    Definitions and other parts of the order took effect; the revised 64.2011 and 64.5111 notification requirements were delayed pending OMB approval.

    Takes effect2.5 years agoSource

December 20232 deadlines

  1. SEC Cyber Disclosure Rules

    Form 8-K Item 1.05 incident disclosure begins

    All registrants other than smaller reporting companies must file material incident disclosures from this date.

    Compliance deadline2.8 years agoSource
  2. SEC Cyber Disclosure Rules

    Annual cybersecurity disclosures begin (Item 106 / 16K)

    Required in annual reports for fiscal years ending on or after this date.

    Compliance deadline2.8 years agoSource

June 20231 deadline

  1. GLBA Safeguards Rule

    Compliance with expanded security program elements

    Applicability of the 314.5 provisions (qualified individual, written risk assessment, encryption, MFA, pen testing, incident response plan, board reporting) was delayed from December 9, 2022 to this date.

    Compliance deadline3.3 years agoSource

January 20221 deadline

  1. GLBA Safeguards Rule

    2021 Safeguards Rule amendments effective

    The amended Safeguards Rule published December 9, 2021 took effect, with the more detailed program elements in 314.5 deferred.

    Takes effect4.7 years agoSource

February 20101 deadline

  1. Full compliance with original Rule

    Full compliance with the 2009 Health Breach Notification Rule was required.

    Compliance deadline16.6 years agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.