Skip to content

2028 compliance deadlines

11 data, privacy, AI and cybersecurity deadlines fall in 2028, across 9 regulations.

January 20283 deadlines

  1. Capture device manufacturer duties

    Capture device manufacturer provenance requirements become operative.

    Compliance deadlinein 15 monthsSource
  2. Independent third-party audits begin

    Beginning Jan 1, 2028 and every 3 years thereafter, data brokers must undergo an independent audit of Delete Act compliance.

    Compliance deadlinein 15 monthsSource
  3. Vermont Data Privacy and Online Surveillance Act takes effect

    All obligations under Act 145 apply (sec. 4).

    Takes effectin 15 monthsSource

April 20282 deadlines

  1. CCPA / CPRA

    First risk assessment submission to CPPA

    Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.

    Reportingin 18 monthsSource
  2. CCPA / CPRA

    Cybersecurity audit due: revenue over $100M

    First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).

    Reportingin 18 monthsSource

June 20281 deadline

  1. Cyber Resilience Act

    Legacy type-examination certificates expire

    EU type-examination certificates and approval decisions on cybersecurity requirements under other harmonisation legislation remain valid until this date unless they expire earlier (Art 69(1)).

    Sunsetin 21 monthsSource

August 20281 deadline

  1. EU AI Act

    High-risk obligations apply to Annex I product-embedded systems

    Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.

    Compliance deadlinein 22 monthsSource

September 20282 deadlines

  1. Cyber Resilience Act

    Report on single reporting platform

    Commission report assessing the single reporting platform's effectiveness (Art 70(2)).

    Reportingin 24 monthsSource
  2. EU Data Act

    Commission evaluation

    Commission evaluation report due, including the impact of cloud switching rules (Arts 23-31) (Art 49(2)).

    Reportingin 24 monthsSource

October 20281 deadline

  1. Data brokers must process state deletion mechanism requests

    Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.

    Compliance deadlinein 2 yearsSource

November 20281 deadline

  1. CMMC 2.0

    Phase 4: full implementation

    CMMC requirements included in all applicable DoD solicitations and contracts, including option periods (32 CFR 170.3(e)(4)).

    Compliance deadlinein 2.1 yearsSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.