Every obligation, every region

The whole register as it stands, 24 obligations across 11 regions, with every milestone and every citation. Your region is moved to the top; nothing is hidden.

Showing: everywhere

Shown for your region, from your browser's language and time zone; nothing is sent anywhere.

European Union 6

AI Act as amended by the Digital Omnibus on AI

EU · binds providers and deployers of AI systems on the EU market; GPAI model providers

you deploy AI that talks to EU users, or build a high-risk system for the EU market

  • 27 Jul 2026 Digital Omnibus on AI in force (OJ 24 Jul 2026) — deferred high-risk dates
  • 2 Aug 2026 Art 50 transparency obligations applied (disclosure of AI interaction, deepfake labelling, emotion-recognition notices); GPAI obligations enforceable
  • 2 Dec 2026 end of 4-month grace for machine-readable marking (Art 50(2)) on generative systems already on the market
  • 2 Dec 2027 Annex III stand-alone high-risk obligations apply (was 2 Aug 2026)
  • 2 Aug 2028 Annex I high-risk (AI in regulated products) obligations apply

Regulation (EU) 2024/1689 as amended; Digital Omnibus on AI, OJ 24 Jul 2026. Secondary: Cyber Law Watch 31 Jul 2026, https://www.cyberlawwatch.com/2026/07/31/eu-digital-omnibus-on-ai-enters-into-force/; Gibson Dunn 27 May 2026

Watch for: Commission guidance on Annex III classification; harmonised standards publication · verified 2026-09-08 secondary source

Cyber Resilience Act — reporting obligations, then full application

EU · binds manufacturers (and their importers/distributors) of products with digital elements placed on the EU market

you sell hardware or software with a digital element into the EU

  • 11 Sep 2026 reporting obligations apply — actively exploited vulnerabilities and severe incidents to ENISA single reporting platform (24h early warning, 72h notification, 14-day final report)
  • 11 Dec 2027 full application (essential requirements, conformity assessment, CE marking)

Regulation (EU) 2024/2847 Art 71; ENISA Single Reporting Platform page

Watch for: ENISA platform go-live notice; Commission implementing acts on reporting format · verified 2026-09-08 primary source

DORA — register of information and threat-led penetration testing

EU · binds financial entities and their critical ICT third-party providers

you are an EU financial entity or an ICT provider to one

  • 17 Jan 2025 in application
  • 31 Mar 2026 2026 register-of-information cycle — competent authorities submitted to ESAs (entity windows Feb–Mar 2026)
  • 2027-03 next annual register-of-information cycle (expected same shape) to verify
  • 17 Jan 2028 first TLPT cycle for designated entities (every 3 years; "by 2028") to verify

Regulation (EU) 2022/2554; CSSF RoI notice 11 Feb 2026, https://www.cssf.lu/en/2026/02/dora-submission-timeframe-for-register-of-information-edesk-portal-open-as-of-11-february-2026/ (secondary: bastion.tech timeline)

Watch for: ESAs' 2027 RoI timetable; TLPT designation letters · verified 2026-09-08 secondary source

Data Act — access-by-design for connected products; cloud switching

EU · binds manufacturers of connected products, providers of related services, data-processing (cloud) services

you ship connected products or sell cloud services into the EU

  • 12 Sep 2025 in application (data access and sharing duties, cloud switching)
  • 12 Sep 2026 Art 3(1) — connected products placed on the market must be designed for data access by default
  • 12 Jan 2027 Art 29 — cloud switching charges fully abolished
  • 12 Sep 2027 Art 13 unfair-terms rules extend to long-standing pre-2025 contracts

Regulation (EU) 2023/2854 Art 50; KPMG Law deadlines note (secondary), https://kpmglaw.ie/insight-eu-data-act-deadlines.html. Cyber Solidarity Act (Reg (EU) 2025/38, in force Feb 2025) noted; no dated obligation rowed — to-verify

Watch for: Commission model contractual terms; national enforcement bodies designated · verified 2026-09-08 secondary source

NIS2 — national transposition and enforcement

EU (27 national laws) · binds essential and important entities in 18 sectors, by national designation; managed service providers are in scope

you are an essential/important entity, or an MSP serving one, in any EU state

  • 17 Oct 2024 transposition deadline (missed by most)
  • 9 Jul 2026 Commission referred Ireland, Spain, France and the Netherlands to the CJEU; roughly 20 of 27 transposed by Jan 2026
  • tbd remaining national laws and registration deadlines — per member state to verify

Directive (EU) 2022/2555; Commission infringement decisions Jul 2026 (secondary: ComplianceHub 9 Jul 2026)

Watch for: national transposition acts in IE/ES/FR/NL; registration windows opening · verified 2026-09-08 secondary source

Product Liability Directive (software in scope; missing security updates can be a defect)

EU · binds manufacturers of products incl. software and AI placed on the EU market; importers/fulfilment providers as fallback defendants

you ship software into the EU and your patch cadence is a liability question

  • 9 Dec 2026 transposition deadline; applies to products placed on the market from this date

Directive (EU) 2024/2853 Arts 2, 22 (secondary: Reed Smith 2 Jul 2025)

Watch for: national transposition acts · verified 2026-09-08 secondary source

US 5

CIRCIA cyber incident reporting (final rule)

US (federal) · binds covered entities in the 16 critical-infrastructure sectors (scope set by the final rule)

you operate in a critical-infrastructure sector in the US

  • 2026-09 final rule targeted for September 2026 (CISA / unified agenda); NOT published as of 8 Sep 2026 pending
  • tbd compliance date set by the final rule (statutory clocks 72h incident / 24h ransom payment) to verify

CISA CIRCIA FAQs, https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs; Hunton (secondary), https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026

Watch for: Federal Register publication of the final rule · verified 2026-09-08 secondary source

CMMC 2.0 phased rollout

US (DoD / Department of War contracts) · binds defense contractors and subcontractors handling FCI/CUI

you hold or bid on DoD contracts, or sit in that supply chain

  • 10 Nov 2025 Phase 1 in force — self-assessments (L1, L2) and SPRS scores; DFARS 252.204-7012 / NIST SP 800-171 r2 continue
  • 13 Jul 2026 Phase 2 (third-party C3PAO L2 certification, was 10 Nov 2026) SUSPENDED pending a 60-day CMMC Reform Task Force review
  • 2026-09 task-force report due to DoW CIO (~mid-September); no decision date stated pending
  • 10 Nov 2026 original Phase 2 date — now uncertain to verify

Department of War release 13 Jul 2026, https://www.war.gov/News/Releases/Release/Article/4542329/; 32 CFR Part 170

Watch for: task-force outcome; DFARS class deviation · verified 2026-09-08 primary source

FTC Safeguards Rule (GLBA) — security programme and 30-day breach notice

US (federal, non-bank financial institutions) · binds financial institutions under FTC jurisdiction — mortgage brokers, auto dealers with financing, tax preparers, collection agencies, non-bank lenders and others

you extend credit or handle customer financial data and are not a bank

  • 9 Jun 2023 amended rule's programme requirements in force (qualified individual, risk assessment, MFA, encryption, monitoring)
  • 13 May 2024 notification to the FTC within 30 days of discovering a breach affecting 500+ consumers

16 CFR Part 314; FTC blog 13 May 2024, https://www.ftc.gov/business-guidance/blog/2024/05/safeguards-rule-notification-requirement-now-effect

Watch for: FTC enforcement orders naming a Safeguards count · verified 2026-09-08 primary source

HIPAA Security Rule modernisation (NPRM Jan 2025)

US (federal) · binds covered entities and business associates

you handle US health data as a covered entity or business associate

  • 2027-07 final rule projected July 2027 (Reginfo / unified agenda)
  • tbd compliance date (set in final rule) to verify

Reginfo.gov unified agenda; Holland & Knight 6 Jul 2026, https://www.hklaw.com/en/insights/publications/2026/07/hipaa-security-rule-amendments-now-projected-for-july-2027

Watch for: OMB/OIRA review listing · verified 2026-09-08 secondary source

SEC cybersecurity disclosure (Item 1.05 8-K; Reg S-K Item 106)

US (federal) · binds SEC registrants

you are listed in the US

  • standing Item 1.05 within four business days of a materiality determination; Item 106 in each 10-K
  • 3 Sep 2026 no amendment or rescission proposed; cyber listed only as a possible "disclosure rationalisation" topic in the fall agenda preview

17 CFR 229.106; Form 8-K Item 1.05; NatLawReview fall rulemaking preview 3 Sep 2026

Watch for: SEC proposing release touching Item 1.05 · verified 2026-09-08 secondary source

US · CA 1

CCPA regulations — cybersecurity audits, risk assessments, ADMT

US (California) · binds businesses subject to CCPA meeting the processing/revenue thresholds

you meet the CCPA thresholds and process Californians' data at scale

  • 1 Jan 2026 regulations effective
  • 31 Dec 2027 risk assessments complete for processing that began before 1 Jan 2026
  • 1 Apr 2028 first risk-assessment submission to CPPA; cyber-audit certification for >$100M revenue
  • 1 Apr 2029 cyber-audit certification, $50–100M revenue
  • 1 Apr 2030 cyber-audit certification, <$50M revenue

CPPA regulations, https://cppa.ca.gov/regulations/ccpa_updates.html; Alston & Bird 17 Aug 2026

Watch for: CPPA audit-format guidance · verified 2026-09-08 secondary source

US · NY 2

NYDFS Part 500 (second amendment) — final tranche and annual certification

US (New York, DFS-licensed entities) · binds banks, insurers, and other DFS licensees; class A companies carry extra duties

you hold a New York DFS licence

  • 1 Nov 2025 universal MFA and asset-inventory requirements in force
  • 15 Apr 2026 certification of compliance for CY2025 (filed)
  • 15 Apr 2027 next annual certification of compliance

23 NYCRR Part 500 §§500.12, 500.13, 500.17 (secondary: Hogan Lovells)

Watch for: DFS guidance letters · verified 2026-09-08 secondary source

New York hospital cybersecurity regulation (10 NYCRR 405.46)

US (New York State, general hospitals) · binds general hospitals licensed in New York

you run or serve a New York hospital

  • 2 Oct 2024 in force; 72-hour material-incident reporting to NYS DOH from day one
  • 2 Oct 2025 compliance deadline for the full programme (CISO, risk assessment, MFA, testing)

NYS DOH hospital cybersecurity page, https://www.health.ny.gov/facilities/hospital/cybersecurity/ (secondary: HIPAA Journal 5 Sep 2025)

Watch for: DOH enforcement or amendment · verified 2026-09-08 secondary source

Everywhere 3

PCI DSS v4.0.1 — all future-dated requirements now mandatory

global (card-brand contractual) · binds any entity that stores, processes or transmits cardholder data, and its service providers

you take card payments

  • 31 Mar 2025 the 51 future-dated requirements became mandatory (v4.0 retired 31 Dec 2024)
  • tbd next major version — PCI SSC has announced no date to verify

PCI SSC blog on future-dated requirements, https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x

Watch for: PCI SSC announcement of v5 timeline · verified 2026-09-08 primary source

Post-quantum cryptography transition milestones

US (NIST, NSA) and EU (coordinated roadmap) · binds US federal systems and NSS directly; everyone else by procurement pull

you sell to the US government or run long-lived keys

  • 1 Jan 2027 CNSA 2.0 — new NSS acquisitions must support quantum-resistant algorithms; software/firmware signing exclusive to verify
  • 2030 NIST IR 8547 (draft) deprecates 112-bit classical (RSA-2048, P-256); EU roadmap: high-risk use cases migrated
  • 2035 NIST disallows quantum-vulnerable algorithms; CNSA 2.0 full; EU medium-risk migrated

NIST IR 8547 ipd, https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf; NSA CNSA 2.0 FAQ; EU coordinated implementation roadmap (2025)

Watch for: NIST IR 8547 final; SP 800-131A rev 3 · verified 2026-09-08 secondary source

Public TLS certificate lifetime reductions (CA/Browser Forum ballot SC-081v3)

global (industry rule, enforced by browsers) · binds anyone operating a public TLS endpoint

any certificate in your estate is renewed by hand

  • 15 Mar 2026 max validity 200 days; DCV reuse 200 days; SII reuse 398 days
  • 15 Mar 2027 max validity 100 days; DCV reuse 100 days
  • 15 Mar 2029 max validity 47 days; DCV reuse 10 days

CA/B Forum ballot SC-081v3, https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/; DigiCert schedule

Watch for: none — dates fixed · verified 2026-09-08 primary source

AU 2

Mandatory ransomware and cyber-extortion payment reporting (Cyber Security Act 2024)

Australia · binds businesses with annual turnover > AUD 3M, and SOCI responsible entities

you trade in Australia above AUD 3M turnover

  • 30 May 2025 obligation live; 72h from payment
  • 1 Jan 2026 education-first phase ended; active regulatory focus

Department of Home Affairs factsheet, https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf

Watch for: first published enforcement action · verified 2026-09-08 primary source

Security standards for smart devices (Cyber Security Act 2024; Rules 2025)

Australia · binds manufacturers and suppliers of consumer-grade internet-connectable devices sold in Australia

you make or sell consumer IoT into Australia

  • 4 Mar 2026 standard in force after 12-month transition — no universal default passwords, a vulnerability-reporting channel, published support period; statement of compliance supplied with the product (s16(3))

Department of Home Affairs, https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/security-standards-for-smart-devices; Cyber Security (Security Standards for Smart Devices) Rules 2025, F2025L00276

Watch for: first compliance notice or stop notice · verified 2026-09-08 primary source

CA 1

Bill C-8 — Critical Cyber Systems Protection Act (Royal Assent 16 Jun 2026)

Canada · binds designated operators in finance, telecoms, energy, transportation

you are a federally regulated operator in those four sectors

  • 16 Jun 2026 Royal Assent; Telecommunications Act amendments in force at once
  • tbd CCSPA obligations (cyber security programmes, incident reporting to the Cyber Centre) phased in by regulation to verify

Public Safety Canada release 16 Jun 2026, https://www.canada.ca/en/public-safety-canada/news/2026/06/...; Parliament of Canada bill C-8 (45-1)

Watch for: draft regulations in Canada Gazette Part I · verified 2026-09-08 primary source

GB 1

Cyber Security and Resilience Bill

UK · binds NIS operators plus, newly, relevant managed service providers, data centres, designated critical suppliers

you are an MSP or data centre operator with UK customers

  • 1 Sep 2026 Lords committee stage (Commons cleared Jun 2026; Lords second reading 14 Jul 2026)
  • 2026-Q4 Royal Assent expected late 2026 to verify
  • 2028 substantive obligations expected via secondary legislation (24h initial / 72h full incident reports) to verify

UK Parliament bill page (primary, to add); secondary: ComplianceHub 1 Sep 2026

Watch for: Royal Assent; DSIT implementation consultation · verified 2026-09-08 secondary source

IN 1

Digital Personal Data Protection Rules 2025 — phased

India · binds data fiduciaries processing Indian residents' personal data

you process personal data of people in India

  • 13 Nov 2025 rules notified
  • 13 Nov 2026 consent-manager registration (12 months) to verify
  • 13 May 2027 core obligations — security safeguards, breach reporting to the Board, data-principal rights (18 months) to verify

Gazette notification 13 Nov 2025 (primary, to add); secondary: Tech Observer

Watch for: Data Protection Board constitution · verified 2026-09-08 secondary source

JP 1

Active Cyber Defence law (promulgated 16 May 2025) — phased commencement

Japan · binds ~250 designated critical-infrastructure operators across 15 sectors (incident reporting); telecoms (data provision)

you run designated infrastructure in Japan or supply telecoms there

  • 2025-11 Cyber Council (public-private) within 6 months to verify
  • 2026-11 remote-access / neutralisation provisions within ~18 months (one secondary source says "October 2026") to verify
  • 2027-11 communications-data analysis provisions within ~2.5 years to verify
  • tbd mandatory incident reporting for designated operators — what and when still unclear to verify

Baker McKenzie 22 Jan 2026, https://connectontech.bakermckenzie.com/japans-new-active-cyber-defense-law-impact-on-businesses/; Center for Cybersecurity Policy & Law

Watch for: Cabinet order fixing commencement dates · verified 2026-09-08 secondary source

SG 1

Cybersecurity (Amendment) Act 2024 — staged commencement

Singapore · binds CII owners (incl. provider-owned and overseas CII); later ESCI and major foundational digital infrastructure providers

you operate CII, cloud, or data-centre services in Singapore

  • 31 Oct 2025 in force — provider-owned/overseas CII designation, expanded incident reporting (APTs, 2h for essential-service disruption), Systems of Temporary Cybersecurity Concern
  • tbd Part 3C (Entities of Special Cybersecurity Interest) and Part 3D (major FDI providers) NOT yet commenced to verify

CSA, https://www.csa.gov.sg/legislation/cybersecurity-act/; HLC 31 Oct 2025 note

Watch for: commencement notification for Parts 3C/3D · verified 2026-09-08 secondary source

Reporting clocks

RegimeRegionClockStatus
SEC Item 1.05 US 4 business days from materiality determinationin force
NYDFS Part 500 US/NY 72h incident notice; 24h extortion-payment noticein force
EU NIS2 EU 24h early warning; 72h notification; 1-month finalper national law
EU DORA EU 4h/24h initial; 72h intermediate; 1-month finalin force
EU CRA EU 24h early warning; 72h notification; 14-day finalfrom 2026-09-11
GDPR EU 72h to the supervisory authorityin force
Australia ransomware payment AU 72h from paymentin force
Singapore CII SG 2h for essential-service disruption (amended Act)in force
FTC Safeguards US 30 days to the FTC, 500+ consumersin force
NY hospitals (405.46) US/NY 72h to NYS DOHin force
India CERT-In directions IN 6hin force since 2022
US CIRCIA US 72h incident; 24h ransom payment (statutory)pending final rule
UK CS&R Bill GB 24h initial; 72h fullpending
Australia SOCI Act (Part 2B) AU 12h significant impact (written follow-up 84h); 72h relevant impact; to ASD/ACSCin force
UK NIS Regulations 2018 GB without undue delay and no later than 72h after awareness, to the competent authority (reg 11(3))in force
South Korea PIPA KR 72h to notify data subjects and report to PIPC (1,000+ subjects, sensitive data, or external unauthorised access); trigger widened to 'possibility of a breach' by the 2026 amendmentin force; amendment effective 2026-09-11
Japan APPI JP preliminary report to PPC promptly (PPC guideline: within 3-5 days); final report 30 days (60 days where the cause is malicious)in force since 2022-04-01

What the flagship reports say

Every flagship takeaway held, newest first. Global.

IBM Cost of a Data Breach 2026 not read at source

published 29 Jul 2026 · breaches at 602 organisations, Mar 2025 – Feb 2026 · read via trade press (Infosecurity Magazine, 30 Jul 2026)

IBM's 2026 Cost of a Data Breach study puts the global average cost of a breach at $4.99 million, up 12% on the year.

It reports that more than a quarter of the organisations studied met an AI-driven attack, a 56% rise, and that such attacks added about $1 million to the cost of a breach.

Sophos State of Ransomware 2026 not read at source

published 2026-07 · 2,158 IT and security leaders in 17 countries whose organisation was hit in the prior 12 months · read via the Sophos blog post and press release (July 2026)

Sophos's 2026 State of Ransomware survey finds that 56% of attacks succeeded in encrypting data, up from 50% a year earlier, while 48% of encrypted victims paid.

It attributes 79% of attacks to an initial foothold gained through a compromised identity (credentials, phishing, malicious email), with exploited vulnerabilities down to 18% of incidents from 32%.

Verizon 2026 Data Breach Investigations Report not read at source

published 20 May 2026 · incidents Nov 2024 – Oct 2025 · read via trade press (Help Net Security 20 May 2026; Tenable)

Verizon's 2026 DBIR finds vulnerability exploitation behind 31% of breaches as the initial way in, and ransomware present in 48% of breaches, up from 44%.

It reports median time to fully patch has lengthened to 43 days from 32, with only 26% of surveyed organisations fully remediating CISA's known-exploited vulnerabilities, and third parties involved in close to half of breaches.

Regional witnesses

Every national assessment in the calendar, all regions. Each link goes to the authority's collection, which carries the current edition; the date is when the next one is expected.

← Back to what is due for you