What is coming, for where you are

The security and resilience obligations with a date on them in the next 90 days, filtered to your part of the world.

Showing: everywhere

Shown for your region, from your browser's language and time zone; nothing is sent anywhere.

This month

No note this month.

Due for you

Sorted by date. The last column is yours to fill in.

ObligationDateWhat happens Your disposition
CIRCIA cyber incident reporting (final rule)
you operate in a critical-infrastructure sector in the US
2026-09 pending final rule targeted for September 2026 (CISA / unified agenda); NOT published as of 8 Sep 2026
CMMC 2.0 phased rollout
you hold or bid on DoD contracts, or sit in that supply chain
2026-09 pending task-force report due to DoW CIO (~mid-September); no decision date stated
Cyber Security and Resilience Bill
you are an MSP or data centre operator with UK customers
2026-Q4 to verify Royal Assent expected late 2026
Digital Personal Data Protection Rules 2025 — phased
you process personal data of people in India
13 Nov 2026 to verify consent-manager registration (12 months)
AI Act as amended by the Digital Omnibus on AI
you deploy AI that talks to EU users, or build a high-risk system for the EU market
2 Dec 2026 end of 4-month grace for machine-readable marking (Art 50(2)) on generative systems already on the market
Product Liability Directive (software in scope; missing security updates can be a defect)
you ship software into the EU and your patch cadence is a liability question
9 Dec 2026 transposition deadline; applies to products placed on the market from this date

After an incident

The reporting clocks that run in your region once a decision to report is made. Read them as the outer limit, not the plan.

RegimeClockStatus
SEC Item 1.054 business days from materiality determination in force
NYDFS Part 50072h incident notice; 24h extortion-payment notice in force
EU NIS224h early warning; 72h notification; 1-month final per national law
EU DORA4h/24h initial; 72h intermediate; 1-month final in force
EU CRA24h early warning; 72h notification; 14-day final from 2026-09-11
GDPR72h to the supervisory authority in force
Australia ransomware payment72h from payment in force
Singapore CII2h for essential-service disruption (amended Act) in force
FTC Safeguards30 days to the FTC, 500+ consumers in force
NY hospitals (405.46)72h to NYS DOH in force
India CERT-In directions6h in force since 2022
US CIRCIA72h incident; 24h ransom payment (statutory) pending final rule
UK CS&R Bill24h initial; 72h full pending
Australia SOCI Act (Part 2B)12h significant impact (written follow-up 84h); 72h relevant impact; to ASD/ACSC in force
UK NIS Regulations 2018without undue delay and no later than 72h after awareness, to the competent authority (reg 11(3)) in force
South Korea PIPA72h to notify data subjects and report to PIPC (1,000+ subjects, sensitive data, or external unauthorised access); trigger widened to 'possibility of a breach' by the 2026 amendment in force; amendment effective 2026-09-11
Japan APPIpreliminary report to PPC promptly (PPC guideline: within 3-5 days); final report 30 days (60 days where the cause is malicious) in force since 2022-04-01

What the flagship reports say

The two most recent flagship studies. These are global and are shown to every reader; where a figure was read through trade press rather than the report itself, it is marked.

IBM Cost of a Data Breach 2026 not read at source

published 29 Jul 2026 · breaches at 602 organisations, Mar 2025 – Feb 2026 · read via trade press (Infosecurity Magazine, 30 Jul 2026)

IBM's 2026 Cost of a Data Breach study puts the global average cost of a breach at $4.99 million, up 12% on the year.

It reports that more than a quarter of the organisations studied met an AI-driven attack, a 56% rise, and that such attacks added about $1 million to the cost of a breach.

Sophos State of Ransomware 2026 not read at source

published 2026-07 · 2,158 IT and security leaders in 17 countries whose organisation was hit in the prior 12 months · read via the Sophos blog post and press release (July 2026)

Sophos's 2026 State of Ransomware survey finds that 56% of attacks succeeded in encrypting data, up from 50% a year earlier, while 48% of encrypted victims paid.

It attributes 79% of attacks to an initial foothold gained through a compromised identity (credentials, phishing, malicious email), with exploited vulnerabilities down to 18% of incidents from 32%.

What your authority says

The national assessment for where you are, which is a different thing from the flagship studies above: this one is your own government's. Each link goes to the authority's collection, which carries the current edition however old that edition is; the date is when the next is expected.

The landscape

Six measures, published here once each is generated rather than estimated. The slots are shown empty on purpose.

Every obligation, every region →