Compliance deadlines
41 dated obligations across 19 regimes — what has already bound you, what is coming, and which of them moved. Every row links the product that covers it, and nothing here is hand-maintained: the dates are typed data, and a build check flags any that pass while still marked pending.
Rows marked verify are not final in their source — a pending rule, an unpublished Official Journal text, or trackers that disagree. We mark them rather than resolve them. Not legal advice.
This calendar is scoped to obligations the catalogue actually covers — every row links the product that does the work. For the wider view, including the industry calendar and the managed side, see the CISO calendar on our services arm.
By regime: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum
Current as of 9 Sept 2026
2026
7 deadlines
EU Cyber Resilience Act
Article 14 reporting obligations apply — actively exploited vulnerabilities and severe incidents
CMMC
Reform Task Force report to the DoW CIO
The workbook ships with the outcome marked PENDING and a reform-watch page built to absorb it.
CIRCIA
Final rule targeted — 72-hour incident and 24-hour ransom-payment reporting to CISA
Built on the NPRM; the updated edition is free when the final rule publishes.
CMMC
Phase 2 (third-party certification) was to begin — suspended, not rescheduled
Post-quantum (EO 14412)
FAR proposed rule due — contractors to PQC-capable FIPS by end-2030
2027
9 deadlines
UK Cyber Security & Resilience Act
Royal Assent and secondary legislation — section numbers and thresholds become final
No date set. The post-Assent edition is promised free to purchasers.
CNSA 2.0
New national-security system acquisitions must support CNSA 2.0 algorithms
TSA pipeline directives
SD Pipeline-2021-01G expires — reissue or the permanent rule
The "Enhancing Surface Cyber Risk Management" NPRM is still pending.
HIPAA Security Rule
OMB target for final action on the Security Rule
Spring 2026 Unified Agenda. The final-rule edition is promised free to purchasers.
EU Cyber Resilience Act
Annex I essential-properties harmonised standard expected — a Class I product without one has no self-assessment route
Commission FAQ timeline as reported; the notified-body bottleneck follows from it.
EU AI Act
Annex III high-risk obligations apply, moved by the Digital Omnibus
Depends on Official Journal publication of the Omnibus.
EU Cyber Resilience Act
Full application — classification, Annex I, conformity assessment, technical file, declaration and CE marking
CCPA / CPPA
Risk assessments due for processing already under way
2028
2 deadlines
CCPA / CPPA
First audit certifications and risk-assessment submissions due
NERC CIP
CIP-015 internal network security monitoring — compliance for control centres
Trackers disagree: some list 1 October 2028. The kit flags the discrepancy rather than resolving it.
2029
1 deadline
2030
2 deadlines
NERC CIP
CIP-015 internal network security monitoring — compliance for remaining medium-impact assets with ERC
NIST IR 8547
RSA-2048 and P-256 deprecated; federal encryption must be post-quantum
2031
1 deadline
2035
1 deadline
Already in force
18 obligations that have already bound, most recent first. Included because "when did this start" is asked at least as often as "when does this land" — and because a date that has passed is the one most likely to be quietly wrong somewhere.
19 products cover the obligations on this page. Browse all 181, or see the bundles if more than one regime reaches you.
Would rather someone else ran the clock? The CISO calendar and the managed programme are on cisomarketplace.services.