Skip to content

US federal data and cybersecurity rules

Federal statutes and agency rules: COPPA, HIPAA, GLBA, SEC cyber disclosure, the DOJ bulk data rule and more.

15 of 15 regulations

Upcoming deadlines

DateRegulation
in 6 weeksCMMC 2.0

Phase 2: Level 2 C3PAO certification

in 6 monthsSection 1033

Tier 2 compliance date (original)tentative

in 1 yearCMMC 2.0

Phase 3: Level 3 certification

in 1 yearSection 1033

Tier 3 compliance date (original)tentative

in 2 yearsCMMC 2.0

Phase 4: full implementation

in 2 yearsSection 1033

Tier 4 compliance date (original)tentative

in 3 yearsSection 1033

Tier 5 compliance date (original)tentative

Past deadlines

DateRegulation
8 weeks agoAI state-law preemption EO

FTC policy statement comments close

2 months agoAI state-law preemption EO

FTC proposes AI accuracy policy statement

2 months agoSection 1033

First compliance date (stayed, enjoined)tentative

3 months agoSEC Reg S-P

Smaller entities must comply

4 months agoTAKE IT DOWN Act

Platform notice-and-removal process required

5 months agoCOPPA Rule

Full compliance with amended COPPA Rule

6 months agoAI state-law preemption EO

Commerce state-law evaluation, BEAD notice and FTC statement due

7 months agoHIPAA

Notice of Privacy Practices updates (Part 2 alignment)

8 months agoAI state-law preemption EO

AI Litigation Task Force due

9 months agoAI state-law preemption EO

EO published in Federal Register

9 months agoSEC Reg S-P

Larger entities must comply

10 months agoCMMC 2.0

DFARS rule effective; Phase 1 begins

11 months agoSection 1033

Court enjoins enforcement

11 months agoSection 1033

Reconsideration comment period closes

11 months agoDOJ Bulk Data Rule

Due diligence, audit and reporting obligations apply

1 year agoSection 1033

Reconsideration ANPR published

1 year agoSection 1033

Court stays Forcht Bank litigation

1 year agoCOPPA Rule

Amended COPPA Rule takes effect

1 year agoTAKE IT DOWN Act

Criminal provisions effective on enactment

1 year agoDOJ Bulk Data Rule

Prohibitions and restrictions take effect

1 year agoNPRM

Comment period closes

1 year agoHIPAA

Security Rule NPRM comment period closed

1 year agoSection 1033

Final rule effective

1 year agoNPRM

NPRM published

1 year agoHIPAA

Reproductive health privacy compliance date (vacated)

1 year agoSEC Cyber Rules

Inline XBRL tagging of Item 1.05 disclosures

1 year agoCMMC 2.0

CMMC Program rule (32 CFR Part 170) effective

1 year agoSEC Cyber Rules

Inline XBRL tagging of annual cybersecurity disclosures

2 years agoSEC Reg S-P

Amendments effective

2 years agoFTC HBNR

2024 amendments effective

2 years agoCIRCIA

NPRM comment period closed

2 years agoHIPAA

Reproductive health care privacy rule effective (later vacated)

2 years agoPADFA

PADFA takes effect

2 years agoSEC Cyber Rules

Smaller reporting companies: Item 1.05 compliance

2 years agoGLBA Safeguards

FTC breach notification requirement effective

2 years agoFCC CPNI Rule

Order effective except revised notification rules

2 years agoSEC Cyber Rules

Form 8-K Item 1.05 incident disclosure begins

2 years agoSEC Cyber Rules

Annual cybersecurity disclosures begin (Item 106 / 16K)

3 years agoGLBA Safeguards

Compliance with expanded security program elements

4 years agoGLBA Safeguards

2021 Safeguards Rule amendments effective

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.