ciso.diy

Compliance deadlines

41 dated obligations across 19 regimes — what has already bound you, what is coming, and which of them moved. Every row links the product that covers it, and nothing here is hand-maintained: the dates are typed data, and a build check flags any that pass while still marked pending.

Rows marked verify are not final in their source — a pending rule, an unpublished Official Journal text, or trackers that disagree. We mark them rather than resolve them. Not legal advice.

This calendar is scoped to obligations the catalogue actually covers — every row links the product that does the work. For the wider view, including the industry calendar and the managed side, see the CISO calendar on our services arm.

By regime: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum

Current as of 9 Sept 2026

2026

7 deadlines

Pending EU 2 days

EU Cyber Resilience Act

Article 14 reporting obligations apply — actively exploited vulnerabilities and severe incidents

Pending US federal 4 days

CMMC

Reform Task Force report to the DoW CIO

The workbook ships with the outcome marked PENDING and a reform-watch page built to absorb it.

Pending US federal verify 21 days

CIRCIA

Final rule targeted — 72-hour incident and 24-hour ransom-payment reporting to CISA

Built on the NPRM; the updated edition is free when the final rule publishes.

Pending US federal 52 days

Post-quantum (EO 14412)

OMB — agency migration plans due

Suspended US federal

CMMC

Phase 2 (third-party certification) was to begin — suspended, not rescheduled

Pending US federal verify

Post-quantum (EO 14412)

FAR proposed rule due — contractors to PQC-capable FIPS by end-2030

Pending US federal

AWIA / water

Mid-size systems — emergency response plan due

2027

9 deadlines

Pending UK verify

UK Cyber Security & Resilience Act

Royal Assent and secondary legislation — section numbers and thresholds become final

No date set. The post-Assent edition is promised free to purchasers.

Pending US federal verify

CNSA 2.0

New national-security system acquisitions must support CNSA 2.0 algorithms

Pending US federal

TSA pipeline directives

SD Pipeline-2021-01G expires — reissue or the permanent rule

The "Enhancing Surface Cyber Risk Management" NPRM is still pending.

Pending US federal verify

Post-quantum (EO 14412)

VDP rule and CISA/NIST CBOM minimum elements due

Pending US federal verify

HIPAA Security Rule

OMB target for final action on the Security Rule

Spring 2026 Unified Agenda. The final-rule edition is promised free to purchasers.

Pending EU verify

EU Cyber Resilience Act

Annex I essential-properties harmonised standard expected — a Class I product without one has no self-assessment route

Commission FAQ timeline as reported; the notified-body bottleneck follows from it.

Pending EU verify

EU AI Act

Annex III high-risk obligations apply, moved by the Digital Omnibus

Depends on Official Journal publication of the Omnibus.

Pending EU

EU Cyber Resilience Act

Full application — classification, Annex I, conformity assessment, technical file, declaration and CE marking

Pending US state

CCPA / CPPA

Risk assessments due for processing already under way

2028

2 deadlines

Pending US state

CCPA / CPPA

First audit certifications and risk-assessment submissions due

Pending US federal verify

NERC CIP

CIP-015 internal network security monitoring — compliance for control centres

Trackers disagree: some list 1 October 2028. The kit flags the discrepancy rather than resolving it.

2029

1 deadline

Pending US federal verify

NERC CIP

CIP-003-11 becomes enforceable

2030

2 deadlines

Pending US federal verify

NERC CIP

CIP-015 internal network security monitoring — compliance for remaining medium-impact assets with ERC

Pending US federal verify

NIST IR 8547

RSA-2048 and P-256 deprecated; federal encryption must be post-quantum

2031

1 deadline

Pending US federal verify

Post-quantum (EO 14412)

Federal authentication must be post-quantum

2035

1 deadline

Pending US federal verify

NIST IR 8547

112-bit classical algorithms disallowed

Already in force

18 obligations that have already bound, most recent first. Included because "when did this start" is asked at least as often as "when does this land" — and because a date that has passed is the one most likely to be quietly wrong somewhere.

EU AI Act Article 50 transparency obligations apply — chatbots must disclose they are AI, synthetic media must be marked EU AI Act Compliance ClockSynthetic Media & Deepfake Defense Kit
CMMC Phase 2 suspended by memo 26-P-1023 pending a reform review — C3PAO and DIBCAC designations paused CMMC 2.0 Readiness Accelerator
NERC CIP CIP-012-2 — communications between control centres, including availability Critical Infrastructure Regime Kit
NY synthetic performer disclosure Synthetic-performer advertising disclosure takes effect Synthetic Media & Deepfake Defense Kit
AWIA / water Mid-size systems — risk and resilience assessment due Critical Infrastructure Regime Kit
Post-quantum (EO 14412) Executive Order 14412 signed — federal PQC dates, a FAR rule, VDP extension and a CBOM standard Post-Quantum Migration Kit
UK Cyber Security & Resilience Act HL Bill 32 passed the Commons; Lords Committee from 1 September UK Cyber Security & Resilience Act Kit
TAKE IT DOWN Act Covered-platform notice-and-removal becomes enforceable — 48 hours, copies included; FTC enforces Synthetic Media & Deepfake Defense Kit
EU Energy Efficiency Directive Annual reporting for data centres at or above 500 kW; mandatory sustainability rating arriving Data Center Assessment Kit
NERC CIP CIP-003-9 — vendor electronic remote-access controls for low-impact assets become enforceable Critical Infrastructure Regime KitOT Security Program Kit for the Plant
TSA pipeline directives SD Pipeline-2021-01G in force — 12-hour CISA reporting, annual assessment plan, 100% coverage in three years Critical Infrastructure Regime KitOT Security Program Kit for the Plant
CCPA / CPPA CPPA cybersecurity audit and risk assessment regulations take effect CCPA Cybersecurity Audit & Privacy Risk Assessment Kit
CMMC Phase 1 — Level 1 and Level 2 self-assessments with annual affirmation become pre-award conditions CMMC 2.0 Readiness Accelerator
PCI DSS All 51 future-dated v4.0.1 requirements become mandatory — no grace argument remains PCI DSS for Healthcare KitPCI DSS v4.0.1 Readiness Accelerator
PCI DSS SAQ A revised — 6.4.3 and 11.6.1 removed and replaced with an eligibility criterion PCI DSS for Healthcare KitPCI DSS v4.0.1 Readiness Accelerator
DORA Regulation applies to financial entities and their critical ICT third parties DORA + NIS2 EU Compliance Workbook
HIPAA Security Rule Notice of proposed rulemaking published (90 FR 898) — "addressable" would end HIPAA Security Rule 2027 Readiness KitHIPAA Readiness Accelerator
NIS2 Member-state transposition deadline — essential and important entities in scope DORA + NIS2 EU Compliance Workbook

19 products cover the obligations on this page. Browse all 181, or see the bundles if more than one regime reaches you.

Would rather someone else ran the clock? The CISO calendar and the managed programme are on cisomarketplace.services.