BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//fru.dev//Regulations//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Regulation deadlines (regulations.fru.dev)
X-WR-CALDESC:Compliance deadlines tracked at regulations.fru.dev
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:deadline-269@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20170301
DTEND;VALUE=DATE:20170302
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Part 500 effective
DESCRIPTION:Original cybersecurity regulation takes effect.\n\nNew York DFS
  Cybersecurity Requirements for Financial Services Companies (23 NYCRR Par
 t 500)\, Second Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cyb
 ersecurity/23-NYCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us
 -ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-31@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20170601
DTEND;VALUE=DATE:20170602
SUMMARY:China Cybersecurity Law: Cybersecurity Law takes effect
DESCRIPTION:Original CSL obligations for network operators and CII operator
 s apply.\n\nCybersecurity Law of the People's Republic of China (as amende
 d by the NPC Standing Committee Decision of 28 October 2025) (China)\n\nSo
 urce: https://www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttp
 s://regulations.fru.dev/regulations/cn-csl
URL:https://regulations.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7041@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20180530
DTEND;VALUE=DATE:20180531
SUMMARY:Kenya Computer Misuse and Cybercrimes Act: Act commences
DESCRIPTION:Assented 16 May 2018\, published 18 May 2018\, commenced 30 May
  2018.\n\nComputer Misuse and Cybercrimes Act\, 2018 (Kenya)\n\nSource: ht
 tps://new.kenyalaw.org/akn/ke/act/2018/5/eng@2022-12-31\n\nhttps://regulat
 ions.fru.dev/regulations/ke-cmca
URL:https://regulations.fru.dev/regulations/ke-cmca
CATEGORIES:Kenya,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7024@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20180711
DTEND;VALUE=DATE:20180712
SUMMARY:Australia SOCI Act: SOCI Act commences
DESCRIPTION:The whole Act commences by Proclamation.\n\nSecurity of Critica
 l Infrastructure Act 2018 (Australia)\n\nSource: https://www.legislation.g
 ov.au/C2018A00029/asmade\n\nhttps://regulations.fru.dev/regulations/au-soc
 i-act
URL:https://regulations.fru.dev/regulations/au-soci-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7011@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20180831
DTEND;VALUE=DATE:20180901
SUMMARY:Singapore Cybersecurity Act: Cybersecurity Act main provisions comm
 ence
DESCRIPTION:Parts 1 to 4\, 6 and the First Schedule (CII regime) commence.\
 n\nCybersecurity Act 2018 (Singapore)\n\nSource: https://sso.agc.gov.sg/Ac
 ts-Supp/9-2018/Published/20211231?DocDate=20180312\n\nhttps://regulations.
 fru.dev/regulations/sg-cybersecurity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7021@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20190528
DTEND;VALUE=DATE:20190529
SUMMARY:Thailand Cybersecurity Act: Cybersecurity Act in force
DESCRIPTION:NCSA states the Act took effect on 28 May 2019.\n\nCybersecurit
 y Act B.E. 2562 (2019) (Thailand)\n\nSource: https://www.ncsa.or.th/about\
 n\nhttps://regulations.fru.dev/regulations/th-cybersecurity-act
URL:https://regulations.fru.dev/regulations/th-cybersecurity-act
CATEGORIES:Thailand,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6852@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20190627
DTEND;VALUE=DATE:20190628
SUMMARY:EU Cybersecurity Act: Cybersecurity Act enters into force
DESCRIPTION:Published in the OJ on 2019-06-07\; enters into force on the 20
 th day.\n\nRegulation (EU) 2019/881 on ENISA and on information and commun
 ications technology cybersecurity certification (Cybersecurity Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng\n\
 nhttps://regulations.fru.dev/regulations/eu-cybersecurity-act
URL:https://regulations.fru.dev/regulations/eu-cybersecurity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-164@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20200101
DTEND;VALUE=DATE:20200102
SUMMARY:CCPA / CPRA: CCPA takes effect
DESCRIPTION:Original CCPA consumer rights and business obligations take eff
 ect.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Califo
 rnia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA
  regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSour
 ce: https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nh
 ttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6853@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20210628
DTEND;VALUE=DATE:20210629
SUMMARY:EU Cybersecurity Act: Certification enforcement articles apply
DESCRIPTION:Articles 58\, 60\, 61\, 63\, 64 and 65 on national certificatio
 n authorities\, conformity assessment bodies\, complaints and remedies app
 ly.\n\nRegulation (EU) 2019/881 on ENISA and on information and communicat
 ions technology cybersecurity certification (Cybersecurity Act) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng\n\nhtt
 ps://regulations.fru.dev/regulations/eu-cybersecurity-act
URL:https://regulations.fru.dev/regulations/eu-cybersecurity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-33@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20210901
DTEND;VALUE=DATE:20210902
SUMMARY:China Data Security Law: Data Security Law takes effect
DESCRIPTION:Data classification\, important-data protection and data export
  restrictions apply (Art. 55).\n\nData Security Law of the People's Republ
 ic of China (China)\n\nSource: http://www.cac.gov.cn/2021-06/11/c_16249945
 66919140.htm\n\nhttps://regulations.fru.dev/regulations/cn-dsl
URL:https://regulations.fru.dev/regulations/cn-dsl
CATEGORIES:China,cybersecurity,data-residency,data-access
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6875@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20211117
DTEND;VALUE=DATE:20211118
SUMMARY:UK Telecommunications Security Act: Royal Assent
DESCRIPTION:Telecommunications (Security) Act receives Royal Assent.\n\nTel
 ecommunications (Security) Act 2021 and the Electronic Communications (Sec
 urity Measures) Regulations 2022 (United Kingdom)\n\nSource: https://www.l
 egislation.gov.uk/ukpga/2021/31/introduction/enacted\n\nhttps://regulation
 s.fru.dev/regulations/uk-telecom-security
URL:https://regulations.fru.dev/regulations/uk-telecom-security
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7040@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20211201
DTEND;VALUE=DATE:20211202
SUMMARY:South Africa Cybercrimes Act: Most of the Act commences
DESCRIPTION:Commenced by proclamation in Gazette 45562 of 30 November 2021\
 , excluding Part VI of Chapter 2\, some Chapter 4 sections and section 54.
 \n\nCybercrimes Act 19 of 2020 (South Africa)\n\nSource: https://www.gov.z
 a/documents/cybercrimes-act-19-2020-1-jun-2021-0000\n\nhttps://regulations
 .fru.dev/regulations/za-cybercrimes-act
URL:https://regulations.fru.dev/regulations/za-cybercrimes-act
CATEGORIES:South Africa,cybersecurity,online-safety,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-233@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20220110
DTEND;VALUE=DATE:20220111
SUMMARY:GLBA Safeguards Rule: 2021 Safeguards Rule amendments effective
DESCRIPTION:The amended Safeguards Rule published December 9\, 2021 took ef
 fect\, with the more detailed program elements in 314.5 deferred.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2021/12/09/2021-25736/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7012@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20220411
DTEND;VALUE=DATE:20220412
SUMMARY:Singapore Cybersecurity Act: Cybersecurity service provider licensi
 ng commences
DESCRIPTION:Part 5 and the Second Schedule take effect. Penetration testing
  and managed SOC providers need a licence.\n\nCybersecurity Act 2018 (Sing
 apore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/9-2018/Published/202112
 31?DocDate=20180312\n\nhttps://regulations.fru.dev/regulations/sg-cybersec
 urity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6991@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20220627
DTEND;VALUE=DATE:20220628
SUMMARY:India CERT-In Cyber Security Directions: CERT-In Directions take ef
 fect
DESCRIPTION:The Directions apply 60 days after issue on 28 Apr 2022. The ex
 act day (27 or 28 June 2022) depends on how the 60 days are counted.\n\nTe
 ntative: depends on a proposal not yet adopted.\n\nDirections under sectio
 n 70B(6) of the Information Technology Act\, 2000 relating to information 
 security practices\, procedure\, prevention\, response and reporting of cy
 ber incidents for Safe and Trusted Internet (India)\n\nSource: https://www
 .cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf\n\nhttps://regul
 ations.fru.dev/regulations/in-certin-directions
URL:https://regulations.fru.dev/regulations/in-certin-directions
CATEGORIES:India,cybersecurity,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7025@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20220708
DTEND;VALUE=DATE:20220709
SUMMARY:Australia SOCI Act: Mandatory cyber incident reporting starts for m
 ost assets
DESCRIPTION:The Application Rules registered on 7 April 2022 gave most asse
 t classes a 3-month grace period before Part 2B incident reporting applied
 . The date is worked out from that grace period.\n\nTentative: depends on 
 a proposal not yet adopted.\n\nSecurity of Critical Infrastructure Act 201
 8 (Australia)\n\nSource: https://www.legislation.gov.au/F2022L00562/asmade
 \n\nhttps://regulations.fru.dev/regulations/au-soci-act
URL:https://regulations.fru.dev/regulations/au-soci-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6977@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20220901
DTEND;VALUE=DATE:20220902
SUMMARY:China Data Export Security Assessment Measures: Security assessment
  measures take effect
DESCRIPTION:Covered data exports require a CAC security assessment.\n\nMeas
 ures for the Security Assessment of Outbound Data Transfers (China)\n\nSou
 rce: https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm\n\nhttps://r
 egulations.fru.dev/regulations/cn-sa-measures
URL:https://regulations.fru.dev/regulations/cn-sa-measures
CATEGORIES:China,data-residency,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6992@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20220925
DTEND;VALUE=DATE:20220926
SUMMARY:India CERT-In Cyber Security Directions: Extended date for MSMEs an
 d subscriber validation
DESCRIPTION:The Directions apply to micro\, small and medium enterprises\, 
 and subscriber validation duties apply to data centres\, VPS\, cloud and V
 PN providers\, from this date.\n\nDirections under section 70B(6) of the I
 nformation Technology Act\, 2000 relating to information security practice
 s\, procedure\, prevention\, response and reporting of cyber incidents for
  Safe and Trusted Internet (India)\n\nSource: https://www.cert-in.org.in/P
 DF/CERT-In_directions_extension_MSMEs_and_validation_27.06.2022.pdf\n\nhtt
 ps://regulations.fru.dev/regulations/in-certin-directions
URL:https://regulations.fru.dev/regulations/in-certin-directions
CATEGORIES:India,cybersecurity,breach-notification,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6876@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20221001
DTEND;VALUE=DATE:20221002
SUMMARY:UK Telecommunications Security Act: Security measures regulations i
 n force
DESCRIPTION:Electronic Communications (Security Measures) Regulations 2022 
 come into force.\n\nTelecommunications (Security) Act 2021 and the Electro
 nic Communications (Security Measures) Regulations 2022 (United Kingdom)\n
 \nSource: https://www.legislation.gov.uk/uksi/2022/933/made\n\nhttps://reg
 ulations.fru.dev/regulations/uk-telecom-security
URL:https://regulations.fru.dev/regulations/uk-telecom-security
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6873@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20221206
DTEND;VALUE=DATE:20221207
SUMMARY:UK PSTI Act (product security): Royal Assent
DESCRIPTION:PSTI Act receives Royal Assent.\n\nProduct Security and Telecom
 munications Infrastructure Act 2022 and the Product Security Regulations 2
 023 (United Kingdom)\n\nSource: https://www.legislation.gov.uk/ukpga/2022/
 46/introduction/enacted\n\nhttps://regulations.fru.dev/regulations/uk-psti
URL:https://regulations.fru.dev/regulations/uk-psti
CATEGORIES:United Kingdom,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-165@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20230101
DTEND;VALUE=DATE:20230102
SUMMARY:CCPA / CPRA: CPRA amendments operative
DESCRIPTION:CPRA amendments (correction right\, sensitive PI limits\, shari
 ng opt-out\, employee/B2B data coverage) become operative.\n\nCalifornia C
 onsumer Privacy Act of 2018\, as amended by the California Privacy Rights 
 Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. C
 ode Regs. tit. 11\, 7000 et seq.) (California)\n\nSource: https://cppa.ca.
 gov/regulations/pdf/ccpa_statute_eff_20260101.pdf\n\nhttps://regulations.f
 ru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-70@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:DORA: DORA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in OJ
  L 333 of 27 Dec 2022 (Art 64).\n\nRegulation (EU) 2022/2554 on digital op
 erational resilience for the financial sector (Digital Operational Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 2/2554/oj\n\nhttps://regulations.fru.dev/regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-98@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20230116
DTEND;VALUE=DATE:20230117
SUMMARY:NIS2: NIS2 enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in OJ L 333 of 27 Dec 2022.\n\nDirective (EU) 2022/2555 on measures f
 or a high common level of cybersecurity across the Union (NIS2 Directive) 
 (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
 \n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6978@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20230301
DTEND;VALUE=DATE:20230302
SUMMARY:China Data Export Security Assessment Measures: Remediation window 
 for existing transfers ends
DESCRIPTION:Existing exports had to be remediated within six months of 2022
 -09-01. The exact end date is computed\, not stated.\n\nTentative: depends
  on a proposal not yet adopted.\n\nMeasures for the Security Assessment of
  Outbound Data Transfers (China)\n\nSource: https://www.cac.gov.cn/2022-07
 /07/c_1658811536396503.htm\n\nhttps://regulations.fru.dev/regulations/cn-s
 a-measures
URL:https://regulations.fru.dev/regulations/cn-sa-measures
CATEGORIES:China,data-residency,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-234@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20230609
DTEND;VALUE=DATE:20230610
SUMMARY:GLBA Safeguards Rule: Compliance with expanded security program ele
 ments
DESCRIPTION:Applicability of the 314.5 provisions (qualified individual\, w
 ritten risk assessment\, encryption\, MFA\, pen testing\, incident respons
 e plan\, board reporting) was delayed from December 9\, 2022 to this date.
 \n\nFTC Standards for Safeguarding Customer Information (Safeguards Rule)\
 , 16 CFR Part 314\, under the Gramm-Leach-Bliley Act (United States (Feder
 al))\n\nSource: https://www.federalregister.gov/documents/2022/11/23/2022-
 25201/standards-for-safeguarding-customer-information\n\nhttps://regulatio
 ns.fru.dev/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-270@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20231101
DTEND;VALUE=DATE:20231102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Second Amendment effecti
 ve
DESCRIPTION:Second Amendment takes effect\; 500.19(e)-(h)\, 500.20\, 500.21
 \, 500.22 and 500.24 apply immediately.\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-271@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20231201
DTEND;VALUE=DATE:20231202
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Amended notification req
 uirements (500.17)
DESCRIPTION:New 72-hour event notice\, 24-hour extortion payment notice and
  certification changes apply (30 days).\n\nNew York DFS Cybersecurity Requ
 irements for Financial Services Companies (23 NYCRR Part 500)\, Second Ame
 ndment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR
 -Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-290@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20231215
DTEND;VALUE=DATE:20231216
SUMMARY:SEC Cyber Disclosure Rules: Annual cybersecurity disclosures begin 
 (Item 106 / 16K)
DESCRIPTION:Required in annual reports for fiscal years ending on or after 
 this date.\n\nSEC Cybersecurity Risk Management\, Strategy\, Governance\, 
 and Incident Disclosure (Release No. 33-11216) (United States (Federal))\n
 \nSource: https://www.federalregister.gov/documents/2023/08/04/2023-16194/
 cybersecurity-risk-management-strategy-governance-and-incident-disclosure\
 n\nhttps://regulations.fru.dev/regulations/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-291@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20231218
DTEND;VALUE=DATE:20231219
SUMMARY:SEC Cyber Disclosure Rules: Form 8-K Item 1.05 incident disclosure 
 begins
DESCRIPTION:All registrants other than smaller reporting companies must fil
 e material incident disclosures from this date.\n\nSEC Cybersecurity Risk 
 Management\, Strategy\, Governance\, and Incident Disclosure (Release No. 
 33-11216) (United States (Federal))\n\nSource: https://www.federalregister
 .gov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strateg
 y-governance-and-incident-disclosure\n\nhttps://regulations.fru.dev/regula
 tions/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-229@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240313
DTEND;VALUE=DATE:20240314
SUMMARY:FCC CPNI Breach Rule: Order effective except revised notification r
 ules
DESCRIPTION:Definitions and other parts of the order took effect\; the revi
 sed 64.2011 and 64.5111 notification requirements were delayed pending OMB
  approval.\n\nFCC Data Breach Reporting Requirements for telecommunication
 s carriers\, interconnected VoIP and TRS providers (47 CFR 64.2011\, 64.51
 11) (United States (Federal))\n\nSource: https://www.federalregister.gov/d
 ocuments/2024/02/12/2024-01667/data-breach-reporting-requirements\n\nhttps
 ://regulations.fru.dev/regulations/us-fcc-cpni-breach
URL:https://regulations.fru.dev/regulations/us-fcc-cpni-breach
CATEGORIES:United States (Federal),privacy,breach-notification,cybersecurit
 y
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-272@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240415
DTEND;VALUE=DATE:20240416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Certification of compliance or acknowledgment of non-compliance
  due (recurs every April 15).\n\nNew York DFS Cybersecurity Requirements f
 or Financial Services Companies (23 NYCRR Part 500)\, Second Amendment (Ne
 w York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\
 n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6877@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240425
DTEND;VALUE=DATE:20240426
SUMMARY:UK Investigatory Powers (Amendment) Act 2024: Royal Assent
DESCRIPTION:Investigatory Powers (Amendment) Act 2024 receives Royal Assent
 .\n\nInvestigatory Powers (Amendment) Act 2024 (United Kingdom)\n\nSource:
  https://www.legislation.gov.uk/ukpga/2024/9/introduction/enacted\n\nhttps
 ://regulations.fru.dev/regulations/uk-ipa-2024
URL:https://regulations.fru.dev/regulations/uk-ipa-2024
CATEGORIES:United Kingdom,privacy,data-access,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-273@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): General 180-day transiti
 on ends
DESCRIPTION:Most new Second Amendment requirements apply\, e.g. annual repo
 rting to the board and risk assessment updates.\n\nNew York DFS Cybersecur
 ity Requirements for Financial Services Companies (23 NYCRR Part 500)\, Se
 cond Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/
 23-NYCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6874@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240429
DTEND;VALUE=DATE:20240430
SUMMARY:UK PSTI Act (product security): Product security requirements apply
DESCRIPTION:Security requirements regulations (SI 2023/1007) come into forc
 e.\n\nProduct Security and Telecommunications Infrastructure Act 2022 and 
 the Product Security Regulations 2023 (United Kingdom)\n\nSource: https://
 www.legislation.gov.uk/uksi/2023/1007/made\n\nhttps://regulations.fru.dev/
 regulations/uk-psti
URL:https://regulations.fru.dev/regulations/uk-psti
CATEGORIES:United Kingdom,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-235@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240513
DTEND;VALUE=DATE:20240514
SUMMARY:GLBA Safeguards Rule: FTC breach notification requirement effective
DESCRIPTION:Section 314.4(j) requires notice to the FTC within 30 days of d
 iscovering a notification event involving at least 500 consumers.\n\nFTC S
 tandards for Safeguarding Customer Information (Safeguards Rule)\, 16 CFR 
 Part 314\, under the Gramm-Leach-Bliley Act (United States (Federal))\n\nS
 ource: https://www.federalregister.gov/documents/2023/11/13/2023-24412/sta
 ndards-for-safeguarding-customer-information\n\nhttps://regulations.fru.de
 v/regulations/us-glba-safeguards
URL:https://regulations.fru.dev/regulations/us-glba-safeguards
CATEGORIES:United States (Federal),financial,cybersecurity,breach-notificat
 ion,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-292@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240615
DTEND;VALUE=DATE:20240616
SUMMARY:SEC Cyber Disclosure Rules: Smaller reporting companies: Item 1.05 
 compliance
DESCRIPTION:Smaller reporting companies must begin complying with Form 8-K 
 Item 1.05 incident disclosure.\n\nSEC Cybersecurity Risk Management\, Stra
 tegy\, Governance\, and Incident Disclosure (Release No. 33-11216) (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 23/08/04/2023-16194/cybersecurity-risk-management-strategy-governance-and-
 incident-disclosure\n\nhttps://regulations.fru.dev/regulations/us-sec-cybe
 r
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-236@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240625
DTEND;VALUE=DATE:20240626
SUMMARY:HIPAA: Reproductive health care privacy rule effective (later vacat
 ed)
DESCRIPTION:The HIPAA Privacy Rule to Support Reproductive Health Care Priv
 acy (89 FR 32976) took effect\; it was vacated nationwide on June 18\, 202
 5 in Purl v. HHS (N.D. Tex.).\n\nHIPAA Privacy\, Security and Breach Notif
 ication Rules (45 CFR Parts 160 and 164) (United States (Federal))\n\nSour
 ce: https://www.federalregister.gov/documents/2024/04/26/2024-08503/hipaa-
 privacy-rule-to-support-reproductive-health-care-privacy\n\nhttps://regula
 tions.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-193@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240703
DTEND;VALUE=DATE:20240704
SUMMARY:CIRCIA: NPRM comment period closed
DESCRIPTION:Extended comment period on the CIRCIA proposed rule closed.\n\n
 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) 
 and proposed implementing rule (6 CFR Part 226) (United States (Federal))\
 n\nSource: https://www.federalregister.gov/documents/2024/04/04/2024-06526
 /cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting
 -requirements\n\nhttps://regulations.fru.dev/regulations/us-circia
URL:https://regulations.fru.dev/regulations/us-circia
CATEGORIES:United States (Federal),cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-295@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240802
DTEND;VALUE=DATE:20240803
SUMMARY:SEC Regulation S-P: Amendments effective
DESCRIPTION:The Regulation S-P amendments became effective\; compliance tie
 red by entity size.\n\nRegulation S-P: Privacy of Consumer Financial Infor
 mation and Safeguarding Customer Information (2024 amendments) (United Sta
 tes (Federal))\n\nSource: https://www.federalregister.gov/documents/2024/0
 6/03/2024-11116/regulation-s-p-privacy-of-consumer-financial-information-a
 nd-safeguarding-customer-information\n\nhttps://regulations.fru.dev/regula
 tions/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7014@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20240826
DTEND;VALUE=DATE:20240827
SUMMARY:Malaysia Cyber Security Act: Act 854 and first regulations in force
DESCRIPTION:The Act and its incident notification\, risk assessment and aud
 it\, and licensing regulations take effect.\n\nCyber Security Act 2024 (Ac
 t 854) (Malaysia)\n\nSource: https://lom.agc.gov.my/act-detail.php?a=YWN0P
 Tg1NCZsYW5nPUJJfDM3MjhhYmRhY2U0YWNlOTZlMGI3MmRlODVkNjQ2YzM4ZTNmMTE0YzA3YzY
 5ZGJhOGExZTNmYmQ4ZTc0OWJlYWY=\n\nhttps://regulations.fru.dev/regulations/m
 y-cyber-security-act
URL:https://regulations.fru.dev/regulations/my-cyber-security-act
CATEGORIES:Malaysia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-99@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241017
DTEND;VALUE=DATE:20241018
SUMMARY:NIS2: Transposition deadline
DESCRIPTION:Member States had to adopt and publish national transposing mea
 sures by 17 Oct 2024 (Art 41(1)).\n\nDirective (EU) 2022/2555 on measures 
 for a high common level of cybersecurity across the Union (NIS2 Directive)
  (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/o
 j\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-100@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241018
DTEND;VALUE=DATE:20241019
SUMMARY:NIS2: National NIS2 measures apply\; NIS1 repealed
DESCRIPTION:Member States apply their NIS2 measures from 18 Oct 2024 and Di
 rective (EU) 2016/1148 (NIS1) is repealed (Arts 41(1)\, 44).\n\nDirective 
 (EU) 2022/2555 on measures for a high common level of cybersecurity across
  the Union (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.eu
 ropa.eu/eli/dir/2022/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu
 -nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-274@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241101
DTEND;VALUE=DATE:20241102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Governance\, encryption\
 , IR/BCDR\, exemptions
DESCRIPTION:500.4 governance\, 500.15 encryption\, 500.16 incident response
  and business continuity plans\, and 500.19(a) revised exemptions apply.\n
 \nNew York DFS Cybersecurity Requirements for Financial Services Companies
  (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: https://www.
 dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://regulations.fru.dev/
 regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-101@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241107
DTEND;VALUE=DATE:20241108
SUMMARY:NIS2: Implementing Regulation 2024/2690 enters into force
DESCRIPTION:Commission Implementing Regulation (EU) 2024/2690 (published 18
  Oct 2024) sets technical risk-management measures and significant-inciden
 t thresholds for DNS\, TLD\, cloud\, data centre\, CDN\, managed (security
 ) service providers\, online marketplaces\, search engines\, social networ
 ks and trust service providers.\n\nDirective (EU) 2022/2555 on measures fo
 r a high common level of cybersecurity across the Union (NIS2 Directive) (
 European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg_impl/2024/269
 0/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6943@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241125
DTEND;VALUE=DATE:20241126
SUMMARY:Ontario Bill 194: Royal Assent
DESCRIPTION:Bill 194 receives Royal Assent as S.O. 2024\, c. 24.\n\nStrengt
 hening Cyber Security and Building Trust in the Public Sector Act\, 2024 (
 Ontario\, Canada)\n\nSource: https://www.ontario.ca/laws/statute/s24024\n\
 nhttps://regulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-106@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241208
DTEND;VALUE=DATE:20241209
SUMMARY:Product Liability Directive: New PLD enters into force
DESCRIPTION:Directive entered into force on the twentieth day after publica
 tion in the OJ on 18 Nov 2024 (Art 23).\n\nDirective (EU) 2024/2853 on lia
 bility for defective products (new Product Liability Directive) (European 
 Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps:
 //regulations.fru.dev/regulations/eu-pld
URL:https://regulations.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-48@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241210
DTEND;VALUE=DATE:20241211
SUMMARY:Cyber Resilience Act: CRA enters into force
DESCRIPTION:Entered into force on the twentieth day after publication in th
 e OJ on 20 Nov 2024 (Art 71(1)).\n\nRegulation (EU) 2024/2847 on horizonta
 l cybersecurity requirements for products with digital elements (Cyber Res
 ilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg
 /2024/2847/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-293@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241215
DTEND;VALUE=DATE:20241216
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of annual cybersecu
 rity disclosures
DESCRIPTION:Item 106 / Item 16K disclosures must be tagged in Inline XBRL f
 or fiscal years ending on or after this date.\n\nSEC Cybersecurity Risk Ma
 nagement\, Strategy\, Governance\, and Incident Disclosure (Release No. 33
 -11216) (United States (Federal))\n\nSource: https://www.federalregister.g
 ov/documents/2023/08/04/2023-16194/cybersecurity-risk-management-strategy-
 governance-and-incident-disclosure\n\nhttps://regulations.fru.dev/regulati
 ons/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-194@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241216
DTEND;VALUE=DATE:20241217
SUMMARY:CMMC 2.0: CMMC Program rule (32 CFR Part 170) effective
DESCRIPTION:The program rule establishing CMMC levels and assessment proces
 ses took effect\; contract enforcement awaited the DFARS rule.\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-294@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241218
DTEND;VALUE=DATE:20241219
SUMMARY:SEC Cyber Disclosure Rules: Inline XBRL tagging of Item 1.05 disclo
 sures
DESCRIPTION:Form 8-K Item 1.05 and Form 6-K incident disclosures must be ta
 gged in Inline XBRL.\n\nSEC Cybersecurity Risk Management\, Strategy\, Gov
 ernance\, and Incident Disclosure (Release No. 33-11216) (United States (F
 ederal))\n\nSource: https://www.federalregister.gov/documents/2023/08/04/2
 023-16194/cybersecurity-risk-management-strategy-governance-and-incident-d
 isclosure\n\nhttps://regulations.fru.dev/regulations/us-sec-cyber
URL:https://regulations.fru.dev/regulations/us-sec-cyber
CATEGORIES:United States (Federal),cybersecurity,breach-notification,financ
 ial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-237@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20241223
DTEND;VALUE=DATE:20241224
SUMMARY:HIPAA: Reproductive health privacy compliance date (vacated)
DESCRIPTION:Original compliance date for the reproductive health care priva
 cy provisions\, including the attestation requirement\; these provisions n
 o longer apply after the June 2025 vacatur.\n\nHIPAA Privacy\, Security an
 d Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fed
 eral))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/202
 4-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\n\n
 https://regulations.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-166@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:CCPA / CPRA: CPI adjustment of thresholds and fines
DESCRIPTION:Revenue threshold rises to $26\,625\,000 and fines to $2\,663 /
  $7\,988 per violation.\n\nCalifornia Consumer Privacy Act of 2018\, as am
 ended by the California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.10
 0 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (
 California)\n\nSource: https://cppa.ca.gov/regulations/cpi_adjustment.html
 \n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-34@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250101
DTEND;VALUE=DATE:20250102
SUMMARY:China Network Data Security Regulations: Network Data Regulations t
 ake effect
DESCRIPTION:All provisions\, including the 10-million-person threshold duti
 es and annual important-data risk assessments\, apply.\n\nRegulations on N
 etwork Data Security Management (State Council Order No. 790) (China)\n\nS
 ource: https://www.gov.cn/zhengce/content/202409/content_6977766.htm\n\nht
 tps://regulations.fru.dev/regulations/cn-network-data-regs
URL:https://regulations.fru.dev/regulations/cn-network-data-regs
CATEGORIES:China,privacy,cybersecurity,data-residency
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6890@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250106
DTEND;VALUE=DATE:20250107
SUMMARY:HIPAA Security Rule update (NPRM): NPRM published
DESCRIPTION:Proposed Security Rule changes published in the Federal Registe
 r.\n\nHIPAA Security Rule To Strengthen the Cybersecurity of Electronic Pr
 otected Health Information (proposed rule) (United States)\n\nSource: http
 s://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security
 -rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-infor
 mation\n\nhttps://regulations.fru.dev/regulations/us-hhs-hipaa-security-np
 rm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6880@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:CFPB Open Banking Rule (Section 1033): Final rule effective
DESCRIPTION:Rule published 2024-11-18 takes effect.\n\nRequired Rulemaking 
 on Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSo
 urce: https://www.federalregister.gov/documents/2024/11/18/2024-25079/requ
 ired-rulemaking-on-personal-financial-data-rights\n\nhttps://regulations.f
 ru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-71@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:DORA: DORA applies
DESCRIPTION:All DORA obligations (ICT risk management\, incident reporting\
 , testing\, third-party risk\, register of information) apply from 17 Jan 
 2025 (Art 64).\n\nRegulation (EU) 2022/2554 on digital operational resilie
 nce for the financial sector (Digital Operational Resilience Act) (Europea
 n Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2022/2554/oj\n\nhttp
 s://regulations.fru.dev/regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-102@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250117
DTEND;VALUE=DATE:20250118
SUMMARY:NIS2: Digital infrastructure entities submit registration data
DESCRIPTION:DNS providers\, TLD registries\, domain registration services\,
  cloud\, data centre\, CDN\, managed (security) service providers\, market
 places\, search engines and social networks had to submit registration det
 ails to competent authorities (Art 27(2)).\n\nDirective (EU) 2022/2555 on 
 measures for a high common level of cybersecurity across the Union (NIS2 D
 irective) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/20
 22/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6944@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250129
DTEND;VALUE=DATE:20250130
SUMMARY:Ontario Bill 194: Enhancing Digital Security and Trust Act in force
DESCRIPTION:Schedule 1 (cyber security\, AI and minors' data framework) and
  some FIPPA amendments come into force by OIC 361/2025.\n\nStrengthening C
 yber Security and Building Trust in the Public Sector Act\, 2024 (Ontario\
 , Canada)\n\nSource: https://www.ontario.ca/laws/oic/o250361\n\nhttps://re
 gulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7008@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250129
DTEND;VALUE=DATE:20250130
SUMMARY:Pakistan PECA: PECA amendment takes effect
DESCRIPTION:Act No. II of 2025 got presidential assent and took effect on 2
 9 Jan 2025\, per the Gazette of Pakistan.\n\nPrevention of Electronic Crim
 es Act\, 2016 (as amended by the Prevention of Electronic Crimes (Amendmen
 t) Act\, 2025) (Pakistan)\n\nSource: https://na.gov.pk/uploads/documents/6
 79b243193585_457.pdf\n\nhttps://regulations.fru.dev/regulations/pk-peca
URL:https://regulations.fru.dev/regulations/pk-peca
CATEGORIES:Pakistan,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6858@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250204
DTEND;VALUE=DATE:20250205
SUMMARY:EU Cyber Solidarity Act: Cyber Solidarity Act enters into force
DESCRIPTION:Published in the OJ on 2025-01-15\; enters into force on the 20
 th day.\n\nRegulation (EU) 2025/38 laying down measures to strengthen soli
 darity and capacities in the Union to detect\, prepare for and respond to 
 cyber threats and incidents (Cyber Solidarity Act) (European Union)\n\nSou
 rce: https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng\n\nhttps://regulatio
 ns.fru.dev/regulations/eu-cyber-solidarity-act
URL:https://regulations.fru.dev/regulations/eu-cyber-solidarity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-238@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA: Security Rule NPRM comment period closed
DESCRIPTION:Comments closed on the proposed HIPAA Security Rule update (90 
 FR 898)\; OCR has not issued a final rule.\n\nHIPAA Privacy\, Security and
  Breach Notification Rules (45 CFR Parts 160 and 164) (United States (Fede
 ral))\n\nSource: https://www.federalregister.gov/documents/2025/01/06/2024
 -30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-p
 rotected-health-information\n\nhttps://regulations.fru.dev/regulations/us-
 hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6891@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250307
DTEND;VALUE=DATE:20250308
SUMMARY:HIPAA Security Rule update (NPRM): Comment period closes
DESCRIPTION:Public comments on the NPRM due.\n\nHIPAA Security Rule To Stre
 ngthen the Cybersecurity of Electronic Protected Health Information (propo
 sed rule) (United States)\n\nSource: https://www.federalregister.gov/docum
 ents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecu
 rity-of-electronic-protected-health-information\n\nhttps://regulations.fru
 .dev/regulations/us-hhs-hipaa-security-nprm
URL:https://regulations.fru.dev/regulations/us-hhs-hipaa-security-nprm
CATEGORIES:United States,health,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-227@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250408
DTEND;VALUE=DATE:20250409
SUMMARY:DOJ Bulk Data Rule: Prohibitions and restrictions take effect
DESCRIPTION:Core prohibitions on covered data transactions and security req
 uirements for restricted transactions apply.\n\nPreventing Access to U.S. 
 Sensitive Personal Data and Government-Related Data by Countries of Concer
 n or Covered Persons (28 CFR Part 202) - DOJ Data Security Program (United
  States (Federal))\n\nSource: https://www.federalregister.gov/documents/20
 25/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-go
 vernment-related-data-by-countries-of-concern\n\nhttps://regulations.fru.d
 ev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-103@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250417
DTEND;VALUE=DATE:20250418
SUMMARY:NIS2: Member States establish entity lists
DESCRIPTION:Member States had to establish lists of essential and important
  entities and notify the Commission of entity numbers (Art 3(3) and (5)). 
 Repeated every two years.\n\nDirective (EU) 2022/2555 on measures for a hi
 gh common level of cybersecurity across the Union (NIS2 Directive) (Europe
 an Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555/oj\n\nhtt
 ps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-72@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250430
DTEND;VALUE=DATE:20250501
SUMMARY:DORA: First registers of information submitted to the ESAs
DESCRIPTION:Competent authorities had to submit financial entities' registe
 rs of ICT third-party contractual arrangements (reference date 31 Mar 2025
 ) to the ESAs by 30 Apr 2025. National authorities set earlier deadlines f
 or entities.\n\nRegulation (EU) 2022/2554 on digital operational resilienc
 e for the financial sector (Digital Operational Resilience Act) (European 
 Union)\n\nSource: https://www.eba.europa.eu/publications-and-media/press-r
 eleases/esas-announce-timeline-collect-information-designation-critical-ic
 t-third-party-service-providers\n\nhttps://regulations.fru.dev/regulations
 /eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-275@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250501
DTEND;VALUE=DATE:20250502
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Vulnerability scans\, ac
 cess privileges\, malware controls\, Class A monitoring
DESCRIPTION:500.5(a)(2) automated scans\, 500.7 access privilege restrictio
 ns\, 500.14(a)(2) malicious code protection\, and 500.14(b) Class A endpoi
 nt detection and centralized logging apply.\n\nNew York DFS Cybersecurity 
 Requirements for Financial Services Companies (23 NYCRR Part 500)\, Second
  Amendment (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-N
 YCRR-Part-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6993@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250523
DTEND;VALUE=DATE:20250524
SUMMARY:Japan Active Cyber Defense Act: Act promulgated
DESCRIPTION:Act No. 42 of 2025 promulgated\; preparatory supplementary prov
 isions apply from this day.\n\nAct on the Prevention of Damage from Unauth
 orized Acts against Important Computers (Act No. 42 of 2025) (Japan)\n\nSo
 urce: https://laws.e-gov.go.jp/api/2/law_revisions/507AC0000000042?respons
 e_format=json\n\nhttps://regulations.fru.dev/regulations/jp-active-cyber-d
 efense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-2@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250530
DTEND;VALUE=DATE:20250531
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware pay
 ment reporting starts
DESCRIPTION:Reporting business entities must report ransomware/cyber-extort
 ion payments to ASD within 72 hours of payment.\n\nCyber Security Act 2024
  (Cth) and Cyber Security (Ransomware Payment Reporting) Rules 2025 (Austr
 alia)\n\nSource: https://www.homeaffairs.gov.au/cyber-security-subsite/fil
 es/factsheet-ransomware-payment-reporting.pdf\n\nhttps://regulations.fru.d
 ev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-16@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250618
DTEND;VALUE=DATE:20250619
SUMMARY:Canada Bill C-8 / CCSPA: Bill C-8 introduced
DESCRIPTION:First reading in the House of Commons.\n\nCritical Cyber System
 s Protection Act (enacted by Bill C-8\, An Act respecting cyber security) 
 (Canada)\n\nSource: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttp
 s://regulations.fru.dev/regulations/ca-ccspa
URL:https://regulations.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6945@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Ontario Bill 194: FIPPA privacy amendments in force
DESCRIPTION:Remaining FIPPA amendments\, including privacy impact assessmen
 ts\, safeguards and breach notification to the IPC\, come into force.\n\nS
 trengthening Cyber Security and Building Trust in the Public Sector Act\, 
 2024 (Ontario\, Canada)\n\nSource: https://www.ontario.ca/laws/oic/o250361
 \n\nhttps://regulations.fru.dev/regulations/ca-on-bill194
URL:https://regulations.fru.dev/regulations/ca-on-bill194
CATEGORIES:Ontario\, Canada,cybersecurity,ai,privacy,children,breach-notifi
 cation
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7018@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250701
DTEND;VALUE=DATE:20250702
SUMMARY:Vietnam Law on Data: Law on Data takes effect
DESCRIPTION:The Law on Data enters into force.\n\nLaw on Data (Law No. 60/2
 024/QH15) (Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&do
 cid=212488\n\nhttps://regulations.fru.dev/regulations/vn-data-law
URL:https://regulations.fru.dev/regulations/vn-data-law
CATEGORIES:Vietnam,data-residency,data-access,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-73@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250708
DTEND;VALUE=DATE:20250709
SUMMARY:DORA: TLPT regulatory technical standards enter into force
DESCRIPTION:Commission Delegated Regulation (EU) 2025/1190 (published 18 Ju
 ne 2025) sets criteria for which financial entities must run threat-led pe
 netration testing\, plus methodology and tester requirements.\n\nRegulatio
 n (EU) 2022/2554 on digital operational resilience for the financial secto
 r (Digital Operational Resilience Act) (European Union)\n\nSource: https:/
 /eur-lex.europa.eu/eli/reg_del/2025/1190/oj\n\nhttps://regulations.fru.dev
 /regulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6881@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250729
DTEND;VALUE=DATE:20250730
SUMMARY:CFPB Open Banking Rule (Section 1033): Court stays Forcht Bank liti
 gation
DESCRIPTION:E.D. Ky. stays the industry challenge after the CFPB says it wi
 ll reconsider the rule\; compliance dates stayed by 90 days.\n\nRequired R
 ulemaking on Personal Financial Data Rights (12 CFR Part 1033) (United Sta
 tes)\n\nSource: https://www.federalregister.gov/documents/2025/08/22/2025-
 16139/personal-financial-data-rights-reconsideration\n\nhttps://regulation
 s.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6882@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250822
DTEND;VALUE=DATE:20250823
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration ANPR publish
 ed
DESCRIPTION:CFPB seeks comment on representatives\, fees\, data security an
 d privacy\, and on extending compliance dates.\n\nRequired Rulemaking on P
 ersonal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSource
 : https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal
 -financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/regu
 lations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-167@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20250922
DTEND;VALUE=DATE:20250923
SUMMARY:CCPA / CPRA: ADMT\, risk assessment and cybersecurity audit regulat
 ions approved
DESCRIPTION:OAL approves the CCPA Updates\, Cybersecurity Audit\, Risk Asse
 ssment\, ADMT and Insurance regulations and files them with the Secretary 
 of State.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the C
 alifornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and
  CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\
 nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://regu
 lations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-228@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251006
DTEND;VALUE=DATE:20251007
SUMMARY:DOJ Bulk Data Rule: Due diligence\, audit and reporting obligations
  apply
DESCRIPTION:Subpart J (data compliance program\, due diligence and audits f
 or restricted transactions) and reporting requirements in 202.1103 and 202
 .1104 apply.\n\nPreventing Access to U.S. Sensitive Personal Data and Gove
 rnment-Related Data by Countries of Concern or Covered Persons (28 CFR Par
 t 202) - DOJ Data Security Program (United States (Federal))\n\nSource: ht
 tps://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-a
 ccess-to-us-sensitive-personal-data-and-government-related-data-by-countri
 es-of-concern\n\nhttps://regulations.fru.dev/regulations/us-doj-bulk-data
URL:https://regulations.fru.dev/regulations/us-doj-bulk-data
CATEGORIES:United States (Federal),privacy,data-residency,cybersecurity,bio
 metrics,health,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6883@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251021
DTEND;VALUE=DATE:20251022
SUMMARY:CFPB Open Banking Rule (Section 1033): Reconsideration comment peri
 od closes
DESCRIPTION:Comments on the ANPR due.\n\nRequired Rulemaking on Personal Fi
 nancial Data Rights (12 CFR Part 1033) (United States)\n\nSource: https://
 www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial
 -data-rights-reconsideration\n\nhttps://regulations.fru.dev/regulations/us
 -cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6884@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251029
DTEND;VALUE=DATE:20251030
SUMMARY:CFPB Open Banking Rule (Section 1033): Court enjoins enforcement
DESCRIPTION:E.D. Ky. enjoins the CFPB from enforcing the rule until it comp
 letes its reconsideration.\n\nRequired Rulemaking on Personal Financial Da
 ta Rights (12 CFR Part 1033) (United States)\n\nSource: https://www.govinf
 o.gov/content/pkg/USCOURTS-kyed-5_24-cv-00304/pdf/USCOURTS-kyed-5_24-cv-00
 304-1.pdf\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7013@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251031
DTEND;VALUE=DATE:20251101
SUMMARY:Singapore Cybersecurity Act: 2024 amendments commence
DESCRIPTION:Most of the Cybersecurity (Amendment) Act 2024 takes effect\, c
 overing foundational digital infrastructure\, entities of special cybersec
 urity interest and systems of temporary cybersecurity concern.\n\nCybersec
 urity Act 2018 (Singapore)\n\nSource: https://sso.agc.gov.sg/Acts-Supp/19-
 2024/Published/20240704?DocDate=20240704\n\nhttps://regulations.fru.dev/re
 gulations/sg-cybersecurity-act
URL:https://regulations.fru.dev/regulations/sg-cybersecurity-act
CATEGORIES:Singapore,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6982@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:China Cyber Incident Reporting Measures: Incident reporting measure
 s take effect
DESCRIPTION:1\, 2 and 4 hour reporting windows apply to relatively major an
 d higher incidents.\n\nAdministrative Measures for National Cybersecurity 
 Incident Reporting (China)\n\nSource: https://www.cac.gov.cn/2025-09/15/c_
 1759583017717009.htm\n\nhttps://regulations.fru.dev/regulations/cn-inciden
 t-reporting
URL:https://regulations.fru.dev/regulations/cn-incident-reporting
CATEGORIES:China,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-276@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251101
DTEND;VALUE=DATE:20251102
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Universal MFA and asset 
 inventory
DESCRIPTION:500.12 multi-factor authentication for all users and 500.13(a) 
 asset inventory requirements apply.\n\nNew York DFS Cybersecurity Requirem
 ents for Financial Services Companies (23 NYCRR Part 500)\, Second Amendme
 nt (New York)\n\nSource: https://www.dfs.ny.gov/cybersecurity/23-NYCRR-Par
 t-500\n\nhttps://regulations.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7042@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251104
DTEND;VALUE=DATE:20251105
SUMMARY:Kenya Computer Misuse and Cybercrimes Act: 2025 amendments commence
DESCRIPTION:Computer Misuse and Cybercrimes (Amendment) Act No. 17 of 2025:
  assented 15 October 2025\, published 21 October 2025\, commenced 4 Novemb
 er 2025.\n\nComputer Misuse and Cybercrimes Act\, 2018 (Kenya)\n\nSource: 
 https://new.kenyalaw.org/akn/ke/act/2025/17\n\nhttps://regulations.fru.dev
 /regulations/ke-cmca
URL:https://regulations.fru.dev/regulations/ke-cmca
CATEGORIES:Kenya,cybersecurity,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-195@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251110
DTEND;VALUE=DATE:20251111
SUMMARY:CMMC 2.0: DFARS rule effective\; Phase 1 begins
DESCRIPTION:CMMC Level 1 and Level 2 self-assessment requirements begin app
 earing in applicable DoD solicitations and contracts (32 CFR 170.3(e)(1)).
 \n\nCybersecurity Maturity Model Certification (CMMC) Program (32 CFR Part
  170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (Uni
 ted States (Federal))\n\nSource: https://www.federalregister.gov/documents
 /2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-a
 ssessing-contractor-implementation-of\n\nhttps://regulations.fru.dev/regul
 ations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-145@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251112
DTEND;VALUE=DATE:20251113
SUMMARY:UK Cyber Security and Resilience Bill: Introduced (Commons first re
 ading)
DESCRIPTION:Bill introduced in the House of Commons.\n\nCyber Security and 
 Resilience (Network and Information Systems) Bill (United Kingdom)\n\nSour
 ce: https://bills.parliament.uk/bills/4035\n\nhttps://regulations.fru.dev/
 regulations/uk-csr-bill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-74@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251118
DTEND;VALUE=DATE:20251119
SUMMARY:DORA: First critical ICT third-party providers designated
DESCRIPTION:The ESAs published the first list of 19 critical ICT third-part
 y providers (including AWS\, Google Cloud and Microsoft)\, which now come 
 under direct EU oversight.\n\nRegulation (EU) 2022/2554 on digital operati
 onal resilience for the financial sector (Digital Operational Resilience A
 ct) (European Union)\n\nSource: https://www.eba.europa.eu/publications-and
 -media/press-releases/european-supervisory-authorities-designate-critical-
 ict-third-party-providers-under-digital\n\nhttps://regulations.fru.dev/reg
 ulations/eu-dora
URL:https://regulations.fru.dev/regulations/eu-dora
CATEGORIES:European Union,cybersecurity,financial,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-296@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20251203
DTEND;VALUE=DATE:20251204
SUMMARY:SEC Regulation S-P: Larger entities must comply
DESCRIPTION:Larger covered institutions (18 months after Federal Register p
 ublication) must have incident response programs\, 30-day customer notific
 ation\, and service-provider oversight in place.\n\nRegulation S-P: Privac
 y of Consumer Financial Information and Safeguarding Customer Information 
 (2024 amendments) (United States (Federal))\n\nSource: https://www.federal
 register.gov/documents/2024/06/03/2024-11116/regulation-s-p-privacy-of-con
 sumer-financial-information-and-safeguarding-customer-information\n\nhttps
 ://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-3@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Australia Cyber Security Act (ransomware reporting): Ransomware rep
 orting moves to compliance phase
DESCRIPTION:The education-first phase (30 May-31 Dec 2025) ends\; Home Affa
 irs moves to a compliance and education approach for missed reports.\n\nCy
 ber Security Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporti
 ng) Rules 2025 (Australia)\n\nSource: https://www.homeaffairs.gov.au/cyber
 -security-subsite/files/factsheet-ransomware-payment-reporting.pdf\n\nhttp
 s://regulations.fru.dev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-168@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:CCPA / CPRA: New CCPA regulations take effect
DESCRIPTION:ADMT\, risk assessment\, cybersecurity audit and updated CCPA r
 egulations become effective\; risk assessments required for new high-risk 
 processing.\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the
  California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) a
 nd CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\
 n\nSource: https://cppa.ca.gov/regulations/ccpa_updates.html\n\nhttps://re
 gulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-32@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:China Cybersecurity Law: 2025 amendments take effect
DESCRIPTION:Higher fines\, first-violation fines\, AI governance provisions
  and PIPL-alignment duties apply under the 28 Oct 2025 NPCSC Decision.\n\n
 Cybersecurity Law of the People's Republic of China (as amended by the NPC
  Standing Committee Decision of 28 October 2025) (China)\n\nSource: https:
 //www.gov.cn/yaowen/liebiao/202510/content_7046194.htm\n\nhttps://regulati
 ons.fru.dev/regulations/cn-csl
URL:https://regulations.fru.dev/regulations/cn-csl
CATEGORIES:China,cybersecurity,data-residency,ai,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-111@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260101
DTEND;VALUE=DATE:20260102
SUMMARY:Hong Kong Critical Infrastructure Cyber Ordinance: PCICSO comes int
 o operation
DESCRIPTION:Commissioner's Office is established and designation of CIOs be
 gins\; obligations apply to designated operators.\n\nProtection of Critica
 l Infrastructures (Computer Systems) Ordinance (Cap. 653) (Hong Kong)\n\nS
 ource: https://www.info.gov.hk/gia/general/202506/27/P2025062700238.htm\n\
 nhttps://regulations.fru.dev/regulations/hk-pcico
URL:https://regulations.fru.dev/regulations/hk-pcico
CATEGORIES:Hong Kong,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6854@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260120
DTEND;VALUE=DATE:20260121
SUMMARY:EU Cybersecurity Act: Cybersecurity Act 2 proposed
DESCRIPTION:Commission proposal COM(2026) 11 to repeal and replace the Act\
 , adding ICT supply chain security rules. Now in the ordinary legislative 
 procedure (2026/0011(COD)).\n\nRegulation (EU) 2019/881 on ENISA and on in
 formation and communications technology cybersecurity certification (Cyber
 security Act) (European Union)\n\nSource: https://publications.europa.eu/r
 esource/celex/52026PC0011\n\nhttps://regulations.fru.dev/regulations/eu-cy
 bersecurity-act
URL:https://regulations.fru.dev/regulations/eu-cybersecurity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-239@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260216
DTEND;VALUE=DATE:20260217
SUMMARY:HIPAA: Notice of Privacy Practices updates (Part 2 alignment)
DESCRIPTION:Covered entities must update Notices of Privacy Practices under
  45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) chang
 es\; this NPP piece survived the Purl vacatur.\n\nHIPAA Privacy\, Security
  and Breach Notification Rules (45 CFR Parts 160 and 164) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/04/26/
 2024-08503/hipaa-privacy-rule-to-support-reproductive-health-care-privacy\
 n\nhttps://regulations.fru.dev/regulations/us-hipaa
URL:https://regulations.fru.dev/regulations/us-hipaa
CATEGORIES:United States (Federal),privacy,health,cybersecurity,breach-noti
 fication
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7043@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260304
DTEND;VALUE=DATE:20260305
SUMMARY:Australia Cyber Security Act (ransomware reporting): Smart device s
 ecurity standard applies
DESCRIPTION:Part 2 and Schedule 1 of the Cyber Security (Security Standards
  for Smart Devices) Rules 2025 commence. Manufacturers and suppliers of re
 levant connectable products must meet the security standard.\n\nCyber Secu
 rity Act 2024 (Cth) and Cyber Security (Ransomware Payment Reporting) Rule
 s 2025 (Australia)\n\nSource: https://www.legislation.gov.au/F2025L00276/a
 smade\n\nhttps://regulations.fru.dev/regulations/au-cyber-security-act
URL:https://regulations.fru.dev/regulations/au-cyber-security-act
CATEGORIES:Australia,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6994@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260401
DTEND;VALUE=DATE:20260402
SUMMARY:Japan Active Cyber Defense Act: Supervisory Commission provisions i
 n force
DESCRIPTION:Provisions setting up the Cyber Communications Information Supe
 rvisory Commission take effect\, per the e-Gov revision history.\n\nAct on
  the Prevention of Damage from Unauthorized Acts against Important Compute
 rs (Act No. 42 of 2025) (Japan)\n\nSource: https://laws.e-gov.go.jp/api/2/
 law_revisions/507AC0000000042?response_format=json\n\nhttps://regulations.
 fru.dev/regulations/jp-active-cyber-defense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-277@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260415
DTEND;VALUE=DATE:20260416
SUMMARY:NYDFS Cybersecurity Regulation (Part 500): Annual compliance notifi
 cation
DESCRIPTION:Annual certification or acknowledgment covering calendar year 2
 025 due.\n\nNew York DFS Cybersecurity Requirements for Financial Services
  Companies (23 NYCRR Part 500)\, Second Amendment (New York)\n\nSource: ht
 tps://www.dfs.ny.gov/cybersecurity/23-NYCRR-Part-500\n\nhttps://regulation
 s.fru.dev/regulations/us-ny-dfs-500
URL:https://regulations.fru.dev/regulations/us-ny-dfs-500
CATEGORIES:New York,cybersecurity,breach-notification,financial
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-297@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260603
DTEND;VALUE=DATE:20260604
SUMMARY:SEC Regulation S-P: Smaller entities must comply
DESCRIPTION:Smaller covered institutions (24 months after Federal Register 
 publication) must comply with the amended Regulation S-P.\n\nRegulation S-
 P: Privacy of Consumer Financial Information and Safeguarding Customer Inf
 ormation (2024 amendments) (United States (Federal))\n\nSource: https://ww
 w.federalregister.gov/documents/2024/06/03/2024-11116/regulation-s-p-priva
 cy-of-consumer-financial-information-and-safeguarding-customer-information
 \n\nhttps://regulations.fru.dev/regulations/us-sec-reg-sp
URL:https://regulations.fru.dev/regulations/us-sec-reg-sp
CATEGORIES:United States (Federal),financial,privacy,cybersecurity,breach-n
 otification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-49@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260611
DTEND;VALUE=DATE:20260612
SUMMARY:Cyber Resilience Act: Conformity assessment body provisions apply
DESCRIPTION:Chapter IV (Arts 35-51\, notification of conformity assessment 
 bodies) applies (Art 71(2)).\n\nRegulation (EU) 2024/2847 on horizontal cy
 bersecurity requirements for products with digital elements (Cyber Resilie
 nce Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/202
 4/2847/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-17@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260615
DTEND;VALUE=DATE:20260616
SUMMARY:Canada Bill C-8 / CCSPA: Royal Assent
DESCRIPTION:Bill C-8 receives Royal Assent (S.C. 2026\, c. 9)\; Telecommuni
 cations Act amendments take effect.\n\nCritical Cyber Systems Protection A
 ct (enacted by Bill C-8\, An Act respecting cyber security) (Canada)\n\nSo
 urce: https://www.parl.ca/legisinfo/en/bill/45-1/c-8\n\nhttps://regulation
 s.fru.dev/regulations/ca-ccspa
URL:https://regulations.fru.dev/regulations/ca-ccspa
CATEGORIES:Canada,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-146@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260616
DTEND;VALUE=DATE:20260617
SUMMARY:UK Cyber Security and Resilience Bill: Passes House of Commons
DESCRIPTION:Report stage and third reading completed in the Commons after c
 arry-over into the new session.\n\nCyber Security and Resilience (Network 
 and Information Systems) Bill (United Kingdom)\n\nSource: https://bills.pa
 rliament.uk/bills/4035\n\nhttps://regulations.fru.dev/regulations/uk-csr-b
 ill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6885@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260630
DTEND;VALUE=DATE:20260701
SUMMARY:CFPB Open Banking Rule (Section 1033): First compliance date (staye
 d\, enjoined)
DESCRIPTION:Largest data providers (banks with $250B or more in assets\; no
 ndepositories with $10B or more in receipts). Originally 2026-04-01\, move
 d 90 days by court stay. Not enforceable while the injunction stands.\n\nT
 entative: depends on a proposal not yet adopted.\n\nRequired Rulemaking on
  Personal Financial Data Rights (12 CFR Part 1033) (United States)\n\nSour
 ce: https://www.federalregister.gov/documents/2025/08/22/2025-16139/person
 al-financial-data-rights-reconsideration\n\nhttps://regulations.fru.dev/re
 gulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7019@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260701
DTEND;VALUE=DATE:20260702
SUMMARY:Vietnam Cybersecurity Law 2025: Cybersecurity Law 2025 takes effect
DESCRIPTION:The new law takes effect. Law 86/2015/QH13 and Law 24/2018/QH14
  cease to have effect.\n\nCybersecurity Law 2025 (Law No. 116/2025/QH15) (
 Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&docid=216499\
 n\nhttps://regulations.fru.dev/regulations/vn-cybersecurity-law
URL:https://regulations.fru.dev/regulations/vn-cybersecurity-law
CATEGORIES:Vietnam,cybersecurity,data-residency,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6988@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260820
DTEND;VALUE=DATE:20260821
SUMMARY:China Data Security Risk Assessment Measures: Risk assessment measu
 res take effect
DESCRIPTION:Annual risk assessment and reporting duties for important data 
 handlers apply.\n\nMeasures for Network Data Security Risk Assessment (Chi
 na)\n\nSource: https://www.cac.gov.cn/2026-06/18/c_1783525609815499.htm\n\
 nhttps://regulations.fru.dev/regulations/cn-data-risk-assessment
URL:https://regulations.fru.dev/regulations/cn-data-risk-assessment
CATEGORIES:China,cybersecurity,privacy
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-50@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: Vulnerability and incident reporting obligati
 ons apply
DESCRIPTION:Art 14: manufacturers must report actively exploited vulnerabil
 ities and severe incidents (24-hour early warning\, 72-hour notification) 
 via the single reporting platform. Also covers products placed on the mark
 et before 11 Dec 2027 (Art 69(3)).\n\nRegulation (EU) 2024/2847 on horizon
 tal cybersecurity requirements for products with digital elements (Cyber R
 esilience Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2024/2847/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7022@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20260916
DTEND;VALUE=DATE:20260917
SUMMARY:Thailand Cybersecurity Act: Website Security Standard B.E. 2568 enf
 orced
DESCRIPTION:The website security standard announced on 16 September 2025 be
 comes enforceable for government agencies\, regulators and CII organisatio
 ns.\n\nCybersecurity Act B.E. 2562 (2019) (Thailand)\n\nSource: https://ww
 w.ncsa.or.th/news/3a613ca26532320a0b000264\n\nhttps://regulations.fru.dev/
 regulations/th-cybersecurity-act
URL:https://regulations.fru.dev/regulations/th-cybersecurity-act
CATEGORIES:Thailand,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6995@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20261001
DTEND;VALUE=DATE:20261002
SUMMARY:Japan Active Cyber Defense Act: Registration and incident reporting
  duties start
DESCRIPTION:Main provisions take effect\, including Chapter 2 duties for sp
 ecial social infrastructure operators to register important computers and 
 report specified intrusion incidents.\n\nAct on the Prevention of Damage f
 rom Unauthorized Acts against Important Computers (Act No. 42 of 2025) (Ja
 pan)\n\nSource: https://laws.e-gov.go.jp/api/2/law_revisions/507AC00000000
 42?response_format=json\n\nhttps://regulations.fru.dev/regulations/jp-acti
 ve-cyber-defense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-147@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20261026
DTEND;VALUE=DATE:20261027
SUMMARY:UK Cyber Security and Resilience Bill: Lords report stage scheduled
DESCRIPTION:House of Lords report stage scheduled (committee stage sat 1\, 
 3 and 7 Sept 2026).\n\nTentative: depends on a proposal not yet adopted.\n
 \nCyber Security and Resilience (Network and Information Systems) Bill (Un
 ited Kingdom)\n\nSource: https://bills.parliament.uk/bills/4035\n\nhttps:/
 /regulations.fru.dev/regulations/uk-csr-bill
URL:https://regulations.fru.dev/regulations/uk-csr-bill
CATEGORIES:United Kingdom,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-196@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20261110
DTEND;VALUE=DATE:20261111
SUMMARY:CMMC 2.0: Phase 2: Level 2 C3PAO certification
DESCRIPTION:Phase 2 begins one calendar year after Phase 1\; applicable sol
 icitations require CMMC Level 2 third-party (C3PAO) certification (32 CFR 
 170.3(e)(2)).\n\nCybersecurity Maturity Model Certification (CMMC) Program
  (32 CFR Part 170) and DFARS acquisition rule (48 CFR Parts 204\, 212\, 21
 7\, 252) (United States (Federal))\n\nSource: https://www.federalregister.
 gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certifica
 tion-cmmc-program\n\nhttps://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-107@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20261209
DTEND;VALUE=DATE:20261210
SUMMARY:Product Liability Directive: Transposition deadline\; old PLD repea
 led
DESCRIPTION:Member States must transpose by 9 Dec 2026 (Art 22). Directive 
 85/374/EEC is repealed from that date but still applies to products placed
  on the market before it (Art 21).\n\nDirective (EU) 2024/2853 on liabilit
 y for defective products (new Product Liability Directive) (European Union
 )\n\nSource: https://eur-lex.europa.eu/eli/dir/2024/2853/oj\n\nhttps://reg
 ulations.fru.dev/regulations/eu-pld
URL:https://regulations.fru.dev/regulations/eu-pld
CATEGORIES:European Union,ai,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-169@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: ADMT requirements compliance date
DESCRIPTION:Businesses using ADMT for significant decisions must comply wit
 h Article 11 (pre-use notice\, opt-out\, access rights) by this date (11 C
 CR 7200(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by th
 e California Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) 
 and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)
 \n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_ad
 mt_appr_text.pdf\n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-170@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:CCPA / CPRA: Browsers must support opt-out preference signal (AB 56
 6)
DESCRIPTION:Businesses that develop or maintain a browser must include cons
 umer-configurable functionality to send an opt-out preference signal (Civ.
  Code 1798.136\, operative Jan 1\, 2027).\n\nCalifornia Consumer Privacy A
 ct of 2018\, as amended by the California Privacy Rights Act of 2020 (Cal.
  Civ. Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11
 \, 7000 et seq.) (California)\n\nSource: https://leginfo.legislature.ca.go
 v/faces/billStatusClient.xhtml?bill_id=202520260AB566\n\nhttps://regulatio
 ns.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6859@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20270205
DTEND;VALUE=DATE:20270206
SUMMARY:EU Cyber Solidarity Act: First Commission evaluation
DESCRIPTION:Commission evaluates the Regulation and reports to Parliament a
 nd Council\, then every 4 years (Article 25).\n\nRegulation (EU) 2025/38 l
 aying down measures to strengthen solidarity and capacities in the Union t
 o detect\, prepare for and respond to cyber threats and incidents (Cyber S
 olidarity Act) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/r
 eg/2025/38/oj/eng\n\nhttps://regulations.fru.dev/regulations/eu-cyber-soli
 darity-act
URL:https://regulations.fru.dev/regulations/eu-cyber-solidarity-act
CATEGORIES:European Union,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6886@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20270401
DTEND;VALUE=DATE:20270402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 2 compliance date (orig
 inal)
DESCRIPTION:Banks with $10B to $250B in assets and smaller nondepositories.
  Original date in 12 CFR 1033.121\; subject to the 90-day stay\, planned e
 xtension and injunction.\n\nTentative: depends on a proposal not yet adopt
 ed.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR Part 
 1033) (United States)\n\nSource: https://www.federalregister.gov/documents
 /2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-righ
 ts\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-104@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20270417
DTEND;VALUE=DATE:20270418
SUMMARY:NIS2: Next biennial entity notification
DESCRIPTION:Competent authorities notify the Commission and Cooperation Gro
 up of the number of essential and important entities\, repeated every two 
 years after 17 Apr 2025 (Art 3(5)).\n\nDirective (EU) 2022/2555 on measure
 s for a high common level of cybersecurity across the Union (NIS2 Directiv
 e) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/dir/2022/2555
 /oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-7020@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20270701
DTEND;VALUE=DATE:20270702
SUMMARY:Vietnam Cybersecurity Law 2025: Transition ends for existing system
 s and products
DESCRIPTION:Information systems classified under the 2015 law\, and securit
 y products already in use\, must meet the new law's conditions within 12 m
 onths of its effective date.\n\nCybersecurity Law 2025 (Law No. 116/2025/Q
 H15) (Vietnam)\n\nSource: https://vanban.chinhphu.vn/?pageid=27160&docid=2
 16499\n\nhttps://regulations.fru.dev/regulations/vn-cybersecurity-law
URL:https://regulations.fru.dev/regulations/vn-cybersecurity-law
CATEGORIES:Vietnam,cybersecurity,data-residency,online-safety
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-105@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20271017
DTEND;VALUE=DATE:20271018
SUMMARY:NIS2: Commission review of NIS2
DESCRIPTION:Commission must review the functioning of NIS2 and report to Pa
 rliament and Council\, then every 36 months (Art 40).\n\nDirective (EU) 20
 22/2555 on measures for a high common level of cybersecurity across the Un
 ion (NIS2 Directive) (European Union)\n\nSource: https://eur-lex.europa.eu
 /eli/dir/2022/2555/oj\n\nhttps://regulations.fru.dev/regulations/eu-nis2
URL:https://regulations.fru.dev/regulations/eu-nis2
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-197@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20271110
DTEND;VALUE=DATE:20271111
SUMMARY:CMMC 2.0: Phase 3: Level 3 certification
DESCRIPTION:Phase 3 begins one year after Phase 2\; Level 3 (DIBCAC) requir
 ements added to applicable solicitations (32 CFR 170.3(e)(3)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6996@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20271122
DTEND;VALUE=DATE:20271123
SUMMARY:Japan Active Cyber Defense Act: Communications data measures in for
 ce (latest date)
DESCRIPTION:Chapters 3 to 7 on agreements with operators and collection of 
 communications data take effect by Cabinet Order within 2 years and 6 mont
 hs of promulgation. e-Gov lists 22 Nov 2027 as the outer limit\, not a fix
 ed date.\n\nTentative: depends on a proposal not yet adopted.\n\nAct on th
 e Prevention of Damage from Unauthorized Acts against Important Computers 
 (Act No. 42 of 2025) (Japan)\n\nSource: https://laws.e-gov.go.jp/api/2/law
 _revisions/507AC0000000042?response_format=json\n\nhttps://regulations.fru
 .dev/regulations/jp-active-cyber-defense
URL:https://regulations.fru.dev/regulations/jp-active-cyber-defense
CATEGORIES:Japan,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-51@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:Cyber Resilience Act: CRA fully applies
DESCRIPTION:All remaining obligations\, including essential cybersecurity r
 equirements\, conformity assessment and CE marking\, apply (Art 71(2)). Pr
 oducts placed on the market earlier are covered only if substantially modi
 fied (Art 69(2)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity
  requirements for products with digital elements (Cyber Resilience Act) (E
 uropean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n
 \nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-171@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:CCPA / CPRA: Risk assessments for pre-existing processing due
DESCRIPTION:Risk assessments must be completed and documented for high-risk
  processing that began before Jan 1\, 2026 and continues after (11 CCR 715
 5(b)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Cali
 fornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CP
 PA regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSo
 urce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_app
 r_text.pdf\n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-172@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: First risk assessment submission to CPPA
DESCRIPTION:Businesses must submit required risk assessment information and
  attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)
 )\; annually by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 
 2018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. 
 Code 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 700
 0 et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccp
 a_updates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/reg
 ulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-173@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue over $100M
DESCRIPTION:First cybersecurity audit report (covering Jan 1\, 2027 - Jan 1
 \, 2028) and certification due for businesses with 2026 annual gross reven
 ue over $100M (11 CCR 7121(a)(1)).\n\nCalifornia Consumer Privacy Act of 2
 018\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. C
 ode 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000
  et seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa
 _updates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/regu
 lations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6887@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 3 compliance date (orig
 inal)
DESCRIPTION:Banks with $3B to $10B in assets. Original date\; subject to st
 ay\, extension and injunction.\n\nTentative: depends on a proposal not yet
  adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CFR
  Part 1033) (United States)\n\nSource: https://www.federalregister.gov/doc
 uments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-dat
 a-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-52@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20280611
DTEND;VALUE=DATE:20280612
SUMMARY:Cyber Resilience Act: Legacy type-examination certificates expire
DESCRIPTION:EU type-examination certificates and approval decisions on cybe
 rsecurity requirements under other harmonisation legislation remain valid 
 until this date unless they expire earlier (Art 69(1)).\n\nRegulation (EU)
  2024/2847 on horizontal cybersecurity requirements for products with digi
 tal elements (Cyber Resilience Act) (European Union)\n\nSource: https://eu
 r-lex.europa.eu/eli/reg/2024/2847/oj\n\nhttps://regulations.fru.dev/regula
 tions/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-53@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20280911
DTEND;VALUE=DATE:20280912
SUMMARY:Cyber Resilience Act: Report on single reporting platform
DESCRIPTION:Commission report assessing the single reporting platform's eff
 ectiveness (Art 70(2)).\n\nRegulation (EU) 2024/2847 on horizontal cyberse
 curity requirements for products with digital elements (Cyber Resilience A
 ct) (European Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/284
 7/oj\n\nhttps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-198@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20281110
DTEND;VALUE=DATE:20281111
SUMMARY:CMMC 2.0: Phase 4: full implementation
DESCRIPTION:CMMC requirements included in all applicable DoD solicitations 
 and contracts\, including option periods (32 CFR 170.3(e)(4)).\n\nCybersec
 urity Maturity Model Certification (CMMC) Program (32 CFR Part 170) and DF
 ARS acquisition rule (48 CFR Parts 204\, 212\, 217\, 252) (United States (
 Federal))\n\nSource: https://www.federalregister.gov/documents/2024/10/15/
 2024-22905/cybersecurity-maturity-model-certification-cmmc-program\n\nhttp
 s://regulations.fru.dev/regulations/us-cmmc
URL:https://regulations.fru.dev/regulations/us-cmmc
CATEGORIES:United States (Federal),cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-174@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue $50M-$100M
DESCRIPTION:First cybersecurity audit report (covering 2028) due for busine
 sses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)
 (2)).\n\nCalifornia Consumer Privacy Act of 2018\, as amended by the Calif
 ornia Privacy Rights Act of 2020 (Cal. Civ. Code 1798.100 et seq.) and CPP
 A regulations (Cal. Code Regs. tit. 11\, 7000 et seq.) (California)\n\nSou
 rce: https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr
 _text.pdf\n\nhttps://regulations.fru.dev/regulations/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6888@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20290401
DTEND;VALUE=DATE:20290402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 4 compliance date (orig
 inal)
DESCRIPTION:Banks with $1.5B to $3B in assets. Original date\; subject to s
 tay\, extension and injunction.\n\nTentative: depends on a proposal not ye
 t adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 CF
 R Part 1033) (United States)\n\nSource: https://www.federalregister.gov/do
 cuments/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-da
 ta-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-175@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CCPA / CPRA: Cybersecurity audit due: revenue under $50M
DESCRIPTION:First cybersecurity audit report (covering 2029) due for covere
 d businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3))
 \; annual by April 1 thereafter.\n\nCalifornia Consumer Privacy Act of 201
 8\, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Cod
 e 1798.100 et seq.) and CPPA regulations (Cal. Code Regs. tit. 11\, 7000 e
 t seq.) (California)\n\nSource: https://cppa.ca.gov/regulations/pdf/ccpa_u
 pdates_cyber_risk_admt_appr_text.pdf\n\nhttps://regulations.fru.dev/regula
 tions/us-ca-ccpa
URL:https://regulations.fru.dev/regulations/us-ca-ccpa
CATEGORIES:California,privacy,ai,cybersecurity,children
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-6889@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20300401
DTEND;VALUE=DATE:20300402
SUMMARY:CFPB Open Banking Rule (Section 1033): Tier 5 compliance date (orig
 inal)
DESCRIPTION:Banks with $850M to $1.5B in assets. Original date\; subject to
  stay\, extension and injunction.\n\nTentative: depends on a proposal not 
 yet adopted.\n\nRequired Rulemaking on Personal Financial Data Rights (12 
 CFR Part 1033) (United States)\n\nSource: https://www.federalregister.gov/
 documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-
 data-rights\n\nhttps://regulations.fru.dev/regulations/us-cfpb-1033
URL:https://regulations.fru.dev/regulations/us-cfpb-1033
CATEGORIES:United States,data-access,financial,privacy,cybersecurity
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:deadline-54@regulations.fru.dev
DTSTAMP:20260926T183124Z
DTSTART;VALUE=DATE:20301211
DTEND;VALUE=DATE:20301212
SUMMARY:Cyber Resilience Act: First CRA evaluation
DESCRIPTION:Commission evaluation and review report\, then every four years
  (Art 70(1)).\n\nRegulation (EU) 2024/2847 on horizontal cybersecurity req
 uirements for products with digital elements (Cyber Resilience Act) (Europ
 ean Union)\n\nSource: https://eur-lex.europa.eu/eli/reg/2024/2847/oj\n\nht
 tps://regulations.fru.dev/regulations/eu-cra
URL:https://regulations.fru.dev/regulations/eu-cra
CATEGORIES:European Union,cybersecurity,breach-notification
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
