Skip to content

Cybersecurity regulations

22 regulations worldwide that deal with cybersecurity, with every phased deadline and the official source for each.

Upcoming deadlines

October 20261 deadline

  1. Lords report stage scheduled

    House of Lords report stage scheduled (committee stage sat 1, 3 and 7 Sept 2026).

    Takes effectTentativein 32 daysSource

November 20261 deadline

  1. CMMC 2.0

    Phase 2: Level 2 C3PAO certification

    Phase 2 begins one calendar year after Phase 1; applicable solicitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 170.3(e)(2)).

    Compliance deadlinein 47 daysSource

December 20261 deadline

  1. Transposition deadline; old PLD repealed

    Member States must transpose by 9 Dec 2026 (Art 22). Directive 85/374/EEC is repealed from that date but still applies to products placed on the market before it (Art 21).

    Transitionin 3 monthsSource

January 20272 deadlines

  1. CCPA / CPRA

    ADMT requirements compliance date

    Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).

    Compliance deadlinein 3 monthsSource
  2. CCPA / CPRA

    Browsers must support opt-out preference signal (AB 566)

    Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).

    Compliance deadlinein 3 monthsSource

April 20271 deadline

  1. NIS2

    Next biennial entity notification

    Competent authorities notify the Commission and Cooperation Group of the number of essential and important entities, repeated every two years after 17 Apr 2025 (Art 3(5)).

    Reportingin 7 monthsSource

October 20271 deadline

  1. NIS2

    Commission review of NIS2

    Commission must review the functioning of NIS2 and report to Parliament and Council, then every 36 months (Art 40).

    Reportingin 13 monthsSource

November 20271 deadline

  1. CMMC 2.0

    Phase 3: Level 3 certification

    Phase 3 begins one year after Phase 2; Level 3 (DIBCAC) requirements added to applicable solicitations (32 CFR 170.3(e)(3)).

    Compliance deadlinein 14 monthsSource

December 20272 deadlines

  1. Cyber Resilience Act

    CRA fully applies

    All remaining obligations, including essential cybersecurity requirements, conformity assessment and CE marking, apply (Art 71(2)). Products placed on the market earlier are covered only if substantially modified (Art 69(2)).

    Compliance deadlinein 15 monthsSource
  2. CCPA / CPRA

    Risk assessments for pre-existing processing due

    Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).

    Compliance deadlinein 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

June 20281 deadline

  1. Cyber Resilience Act

    Legacy type-examination certificates expire

    EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).

    Sunsetin 21 monthsSource

September 20281 deadline

  1. Cyber Resilience Act

    Report on single reporting platform

    Commission report assessing the single reporting platform's effectiveness (Art 70(2)).

    Reportingin 24 monthsSource

November 20281 deadline

  1. CMMC 2.0

    Phase 4: full implementation

    CMMC requirements included in all applicable DoD solicitations and contracts, including option periods (32 CFR 170.3(e)(4)).

    Compliance deadlinein 2.1 yearsSource

April 20291 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue $50M-$100M

    First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).

    Reportingin 2.5 yearsSource

April 20301 deadline

  1. CCPA / CPRA

    Cybersecurity audit due: revenue under $50M

    First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.

    Reportingin 3.5 yearsSource

December 20301 deadline

  1. Cyber Resilience Act

    First CRA evaluation

    Commission evaluation and review report, then every four years (Art 70(1)).

    Reportingin 4.2 yearsSource

Past deadlines

September 20261 deadline

  1. Cyber Resilience Act

    Vulnerability and incident reporting obligations apply

    Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before 11 Dec 2027 (Art 69(3)).

    Reporting13 days agoSource

June 20264 deadlines

  1. Passes House of Commons

    Report stage and third reading completed in the Commons after carry-over into the new session.

    Takes effect3 months agoSource
  2. Royal Assent

    Bill C-8 receives Royal Assent (S.C. 2026, c. 9); Telecommunications Act amendments take effect.

    Takes effect3 months agoSource
  3. Cyber Resilience Act

    Conformity assessment body provisions apply

    Chapter IV (Arts 35-51, notification of conformity assessment bodies) applies (Art 71(2)).

    Takes effect3 months agoSource
  4. SEC Regulation S-P

    Smaller entities must comply

    Smaller covered institutions (24 months after Federal Register publication) must comply with the amended Regulation S-P.

    Compliance deadline4 months agoSource

April 20261 deadline

  1. Annual compliance notification

    Annual certification or acknowledgment covering calendar year 2025 due.

    Reporting5 months agoSource

February 20261 deadline

  1. HIPAA

    Notice of Privacy Practices updates (Part 2 alignment)

    Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.

    Compliance deadline7 months agoSource

January 20264 deadlines

  1. PCICSO comes into operation

    Commissioner's Office is established and designation of CIOs begins; obligations apply to designated operators.

    Takes effect9 months agoSource
  2. 2025 amendments take effect

    Higher fines, first-violation fines, AI governance provisions and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.

    Takes effect9 months agoSource
  3. CCPA / CPRA

    New CCPA regulations take effect

    ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.

    Takes effect9 months agoSource
  4. Ransomware reporting moves to compliance phase

    The education-first phase (30 May-31 Dec 2025) ends; Home Affairs moves to a compliance and education approach for missed reports.

    Enforcement9 months agoSource

December 20251 deadline

  1. SEC Regulation S-P

    Larger entities must comply

    Larger covered institutions (18 months after Federal Register publication) must have incident response programs, 30-day customer notification, and service-provider oversight in place.

    Compliance deadline10 months agoSource

November 20254 deadlines

  1. DORA

    First critical ICT third-party providers designated

    The ESAs published the first list of 19 critical ICT third-party providers (including AWS, Google Cloud and Microsoft), which now come under direct EU oversight.

    Enforcement10 months agoSource
  2. Introduced (Commons first reading)

    Bill introduced in the House of Commons.

    Takes effect10 months agoSource
  3. CMMC 2.0

    DFARS rule effective; Phase 1 begins

    CMMC Level 1 and Level 2 self-assessment requirements begin appearing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).

    Takes effect10 months agoSource
  4. Universal MFA and asset inventory

    500.12 multi-factor authentication for all users and 500.13(a) asset inventory requirements apply.

    Compliance deadline11 months agoSource

October 20251 deadline

  1. DOJ Bulk Data Rule

    Due diligence, audit and reporting obligations apply

    Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.

    Compliance deadline12 months agoSource

September 20251 deadline

  1. CCPA / CPRA

    ADMT, risk assessment and cybersecurity audit regulations approved

    OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.

    Transition12 months agoSource

July 20251 deadline

  1. DORA

    TLPT regulatory technical standards enter into force

    Commission Delegated Regulation (EU) 2025/1190 (published 18 June 2025) sets criteria for which financial entities must run threat-led penetration testing, plus methodology and tester requirements.

    Takes effect15 months agoSource

June 20251 deadline

  1. Bill C-8 introduced

    First reading in the House of Commons.

    Transition15 months agoSource

May 20252 deadlines

  1. Ransomware payment reporting starts

    Reporting business entities must report ransomware/cyber-extortion payments to ASD within 72 hours of payment.

    Takes effect16 months agoSource
  2. Vulnerability scans, access privileges, malware controls, Class A monitoring

    500.5(a)(2) automated scans, 500.7 access privilege restrictions, 500.14(a)(2) malicious code protection, and 500.14(b) Class A endpoint detection and centralized logging apply.

    Compliance deadline17 months agoSource

April 20253 deadlines

  1. DORA

    First registers of information submitted to the ESAs

    Competent authorities had to submit financial entities' registers of ICT third-party contractual arrangements (reference date 31 Mar 2025) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines for entities.

    Reporting17 months agoSource
  2. NIS2

    Member States establish entity lists

    Member States had to establish lists of essential and important entities and notify the Commission of entity numbers (Art 3(3) and (5)). Repeated every two years.

    Reporting17 months agoSource
  3. DOJ Bulk Data Rule

    Prohibitions and restrictions take effect

    Core prohibitions on covered data transactions and security requirements for restricted transactions apply.

    Takes effect18 months agoSource

March 20251 deadline

  1. HIPAA

    Security Rule NPRM comment period closed

    Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.

    Transition19 months agoSource

January 20254 deadlines

  1. NIS2

    Digital infrastructure entities submit registration data

    DNS providers, TLD registries, domain registration services, cloud, data centre, CDN, managed (security) service providers, marketplaces, search engines and social networks had to submit registration details to competent authorities (Art 27(2)).

    Reporting20 months agoSource
  2. DORA

    DORA applies

    All DORA obligations (ICT risk management, incident reporting, testing, third-party risk, register of information) apply from 17 Jan 2025 (Art 64).

    Takes effect20 months agoSource
  3. Network Data Regulations take effect

    All provisions, including the 10-million-person threshold duties and annual important-data risk assessments, apply.

    Takes effect21 months agoSource
  4. CCPA / CPRA

    CPI adjustment of thresholds and fines

    Revenue threshold rises to $26,625,000 and fines to $2,663 / $7,988 per violation.

    Transition21 months agoSource

December 20246 deadlines

  1. HIPAA

    Reproductive health privacy compliance date (vacated)

    Original compliance date for the reproductive health care privacy provisions, including the attestation requirement; these provisions no longer apply after the June 2025 vacatur.

    Compliance deadline21 months agoSource
  2. SEC Cyber Disclosure Rules

    Inline XBRL tagging of Item 1.05 disclosures

    Form 8-K Item 1.05 and Form 6-K incident disclosures must be tagged in Inline XBRL.

    Compliance deadline21 months agoSource
  3. CMMC 2.0

    CMMC Program rule (32 CFR Part 170) effective

    The program rule establishing CMMC levels and assessment processes took effect; contract enforcement awaited the DFARS rule.

    Takes effect21 months agoSource
  4. SEC Cyber Disclosure Rules

    Inline XBRL tagging of annual cybersecurity disclosures

    Item 106 / Item 16K disclosures must be tagged in Inline XBRL for fiscal years ending on or after this date.

    Compliance deadline21 months agoSource
  5. Cyber Resilience Act

    CRA enters into force

    Entered into force on the twentieth day after publication in the OJ on 20 Nov 2024 (Art 71(1)).

    Takes effect21 months agoSource
  6. New PLD enters into force

    Directive entered into force on the twentieth day after publication in the OJ on 18 Nov 2024 (Art 23).

    Takes effect22 months agoSource

November 20242 deadlines

  1. NIS2

    Implementing Regulation 2024/2690 enters into force

    Commission Implementing Regulation (EU) 2024/2690 (published 18 Oct 2024) sets technical risk-management measures and significant-incident thresholds for DNS, TLD, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers.

    Takes effect23 months agoSource
  2. Governance, encryption, IR/BCDR, exemptions

    500.4 governance, 500.15 encryption, 500.16 incident response and business continuity plans, and 500.19(a) revised exemptions apply.

    Compliance deadline23 months agoSource

October 20242 deadlines

  1. NIS2

    National NIS2 measures apply; NIS1 repealed

    Member States apply their NIS2 measures from 18 Oct 2024 and Directive (EU) 2016/1148 (NIS1) is repealed (Arts 41(1), 44).

    Takes effect23 months agoSource
  2. NIS2

    Transposition deadline

    Member States had to adopt and publish national transposing measures by 17 Oct 2024 (Art 41(1)).

    Transition23 months agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.