Cybersecurity regulations
22 regulations worldwide that deal with cybersecurity, with every phased deadline and the official source for each.
22 regulations
Add to calendar
- UK Cyber Security and Resilience Bill
United Kingdom
ProposedCybersecurityBreach notificationNext: Oct 26, 2026 Lords report stage scheduled
- CMMC 2.0
United States (Federal)
In forceCybersecurityNext: Nov 10, 2026 Phase 2: Level 2 C3PAO certification
- Product Liability Directive
European Union
EnactedAICybersecurityNext: Dec 9, 2026 Transposition deadline; old PLD repealed
- CCPA / CPRA
California
AmendedPrivacyAINext: Jan 1, 2027 ADMT requirements compliance date
- NIS2
European Union
AmendedCybersecurityBreach notificationNext: Apr 17, 2027 Next biennial entity notification
- Cyber Resilience Act
European Union
EnactedCybersecurityBreach notificationNext: Dec 11, 2027 CRA fully applies
- In forceCybersecurityBreach notification
Effective Nov 30, 2024
- Canada Bill C-8 / CCSPA
Canada
EnactedCybersecurityBreach notification - AmendedCybersecurityData residency
Effective Jun 1, 2017
- In forceCybersecurityData residency
Effective Sep 1, 2021
- In forcePrivacyCybersecurity
Effective Jan 1, 2025
- CIRCIA
United States (Federal)
EnactedCybersecurityBreach notification - Digital Omnibus (data/GDPR)
European Union
ProposedPrivacyData access and sharing - DOJ Bulk Data Rule
United States (Federal)
In forcePrivacyData residencyEffective Apr 8, 2025
- DORA
European Union
In forceCybersecurityFinancialEffective Jan 16, 2023
- FCC CPNI Breach Rule
United States (Federal)
AmendedPrivacyBreach notificationEffective Mar 13, 2024
- GLBA Safeguards Rule
United States (Federal)
AmendedFinancialCybersecurityEffective May 23, 2003
- HIPAA
United States (Federal)
AmendedPrivacyHealth dataEffective Apr 14, 2003
- In forceCybersecurityBreach notification
Effective Jan 1, 2026
- AmendedCybersecurityBreach notification
Effective Mar 1, 2017
- SEC Cyber Disclosure Rules
United States (Federal)
In forceCybersecurityBreach notificationEffective Sep 5, 2023
- SEC Regulation S-P
United States (Federal)
AmendedFinancialPrivacyEffective Aug 2, 2024
Upcoming deadlines
October 20261 deadline
Lords report stage scheduled
House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).
November 20261 deadline
December 20261 deadline
- Product Liability DirectiveEuropean Union
Transposition deadline; old PLD repealed
Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).
January 20272 deadlines
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
April 20271 deadline
October 20271 deadline
November 20271 deadline
December 20272 deadlines
- Cyber Resilience ActEuropean Union
CRA fully applies
All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
June 20281 deadline
- Cyber Resilience ActEuropean Union
Legacy type-examination certificates expire
EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).
September 20281 deadline
- Cyber Resilience ActEuropean Union
Report on single reporting platform
Commission report assessing the single reporting platform's effectiveness (Art 70(2)).
November 20281 deadline
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
December 20301 deadline
- Cyber Resilience ActEuropean Union
First CRA evaluation
Commission evaluation and review report, then every four years (Art 70(1)).
Past deadlines
September 20261 deadline
- Cyber Resilience ActEuropean Union
Vulnerability and incident reporting obligations apply
Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).
June 20264 deadlines
Passes House of Commons
Report stage and third reading completed in the Commons after carry-over into the new session.
Royal Assent
Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.
- Cyber Resilience ActEuropean Union
Conformity assessment body provisions apply
Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).
Smaller entities must comply
Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.
April 20261 deadline
Annual compliance notification
Annual certification or acknowledgment covering calendar year 2025 due.
February 20261 deadline
Notice of Privacy Practices updates (Part 2 alignment)
Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.
January 20264 deadlines
PCICSO comes into operation
Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.
2025 amendments take effect
Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.
New CCPA regulations take effect
ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.
Ransomware reporting moves to compliance phase
The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.
December 20251 deadline
Larger entities must comply
Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.
November 20254 deadlines
Introduced (Commons first reading)
Bill introduced in the House of Commons.
Universal MFA and asset inventory
500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.
October 20251 deadline
Due diligence, audit and reporting obligations apply
Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.
September 20251 deadline
ADMT, risk assessment and cybersecurity audit regulations approved
OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.
July 20251 deadline
June 20251 deadline
Bill C-8 introduced
First reading in the House of Commons.
May 20252 deadlines
Ransomware payment reporting starts
Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.
Vulnerability scans, access privileges, malware controls, Class A monitoring
500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.
April 20253 deadlines
- DORAEuropean Union
First registers of information submitted to the ESAs
Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.
Prohibitions and restrictions take effect
Core prohibitions on covered data transactions and security requirements for restricted transactions apply.
March 20251 deadline
January 20254 deadlines
- NIS2European Union
Digital infrastructure entities submit registration data
DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).
Network Data Regulations take effect
All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.
CPI adjustment of thresholds and fines
Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.
December 20246 deadlines
Inline XBRL tagging of Item 1.05 disclosures
Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.
Inline XBRL tagging of annual cybersecurity disclosures
Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.
- Cyber Resilience ActEuropean Union
CRA enters into force
Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).
- Product Liability DirectiveEuropean Union
New PLD enters into force
Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).
November 20242 deadlines
- NIS2European Union
Implementing Regulation 2024/2690 enters into force
Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.
Governance, encryption, IR/BCDR, exemptions
500.4 governance, 500.15 encryption, 500.16 incident response and business continuity plans, and 500.19(a) revised exemptions apply.