Regulatory Radar
Track regulatory changes, framework updates, and compliance deadlines. Filtered to what matters for your organization.
Obligations With a Published Date
Compliance obligations that carry a published date, in date order with the soonest first. Each one opens a full entry with the primary regulator source, an impact analysis, and a remediation effort estimate. The list narrows to what is still ahead and the days remaining are worked out in your browser, so both are right for the day you are reading rather than the day this page was published.
CMMC Phase 2 Suspended; RFI Due Aug 14
CMMCNIST 800-171EU CRA Article 14 Reporting Duties Apply
EU CRACISA 2015 Liability Protections Sunset Sept 30
CISA 2015NIST CSFCIRCIAEU AI Act Article 50 Marking Transition Ends
EU AI ActCCPA ADMT Compliance Deadline Arrives
CCPAEU AI Act: Annex III High-Risk Duties Apply
EU AI ActEU CRA Becomes Fully Applicable
EU CRACCPA Risk Assessments Due for Legacy Processing
CCPAState PrivacyCCPA First Cyber Audit and Filing Deadline
CCPAState PrivacyEU AI Act: Annex I Embedded High-Risk Duties
EU AI ActCCPA Cyber Audit Due: Mid-Market Revenue Tier
CCPAState PrivacyCCPA Cyber Audit Due: Smaller Revenue Tier
CCPAState Privacy
Awaiting a Published Date
Obligations that are real and moving but carry no published date. They are listed rather than estimated, because a guessed regulatory deadline is worse than an acknowledged gap.
- No date publishedCMMCNIST 800-171
CMMC Phases 2 to 4: third-party certification requirements
Where it stands: The Department of War suspended CMMC Phase 2 on 13 July 2026, ahead of its scheduled 10 November 2026 start, and stood up a CMMC Reform Task Force to review the programme. Phase 1 is untouched: Level 1 and Level 2 self-assessments, SPRS scores, and annual affirmations under DFARS 252.204-7021 remain in force, as do the DFARS 252.204-7012 safeguarding and incident reporting clauses.
Why there is no date: No replacement date has been announced for Phase 2 or for the phases that followed it. The task force was asked for recommendations, not for a schedule, and until those recommendations are acted on there is no published date to plan against. Treat the suspension as a pause pending review rather than a repeal.
- No date publishedCIRCIA
CIRCIA: 72-hour incident and 24-hour ransom payment reporting
Where it stands: The Cyber Incident Reporting for Critical Infrastructure Act obligations do not bind anyone until CISA issues the final rule adding 6 CFR Part 226. The statutory deadline of 4 October 2025 passed without one, and the Unified Agenda target has since moved twice.
Why there is no date: A Unified Agenda target is a projection of when an agency expects to act, not a compliance date, and this one has already slipped. The 72-hour incident and 24-hour ransom payment clocks are fixed by statute and will start when the final rule takes effect, so the reporting duty is certain even though its start date is not.
- No date publishedHIPAA
HIPAA Security Rule modernization: encryption, MFA, and 72-hour restoration
Where it stands: HHS published the Security Rule modernization proposal on 6 January 2025 and the comment period closed on 7 March 2025. No final rule has issued, and the rulemaking has since moved to the Unified Agenda's Long-Term Actions list.
Why there is no date: Nothing in the proposal binds a covered entity until a final rule issues, and a projected final action date on a long-term agenda is neither a compliance date nor a commitment. The existing Security Rule continues to apply unchanged in the meantime.
- No date publishedDORA
DORA: the next round of critical ICT third-party provider designations
Where it stands: The European Supervisory Authorities published the first list of designated critical ICT third-party service providers on 18 November 2025. Designation runs off the registers of information that financial entities file with their competent authorities, so it repeats as those registers are refreshed.
Why there is no date: The ESAs have not published a date for the next designation round. A provider learns it is in scope when it is notified, which is why the planning question for a technology vendor is the DORA contractual and register obligations its financial-sector customers already carry, not the designation calendar.
- No date publishedNIS2
NIS2 in Ireland: national transposition still pending
Where it stands: Ireland's National Cyber Security Centre states on its own NIS2 page that the transposition deadline of 17 October 2024 has not been met, that Ireland continues to work through the directive's transposition requirements, and that the Heads of the General Scheme of the implementing Bill were published by the Department of the Environment, Climate and Communications in September 2024. The NCSC also states that NIS1 remains in full effect in the meantime, so Irish operators of essential services are regulated today under the earlier regime rather than being unregulated.
Why there is no date: No enactment or commencement date has been published. A General Scheme is a pre-drafting outline of a Bill, not a Bill before the Oireachtas, and neither a scheme nor the European Commission's referral of Ireland to the Court of Justice fixes a date that anyone can plan against. The direction is not in doubt and the timing is not knowable, which is why the honest planning basis is the directive's own Article 21 risk management measures and Article 23 reporting duties: whatever the Irish law says, those are what it has to give effect to.
Every Development We Track
The complete record, newest first, including everything already in effect. Filter by framework, industry, severity, or type, or switch to the calendar view to see how the dates cluster.
Every entry is checked against its primary source. Last verified: August 24, 2026. This page is for general informational and educational purposes only. It does not constitute legal, regulatory, or professional compliance advice. Details may be incomplete or outdated. Always verify compliance obligations with official sources and qualified legal counsel. See our Terms of Service.
California CCPA: Cybersecurity Audit Deadline for Businesses Under 50 Million Dollars in Revenue
The final phase-in wave of California cybersecurity audits falls due. Under section 7121(a)(3) of the California Privacy Protection Agency regulations, a business whose annual gross revenue for 2028 was less than 50 million dollars must complete its first cybersecurity audit report by April 1, 2030, covering January 1, 2029 through January 1, 2030. From this point the regulations settle into an annual cycle: under section 7121(b), a business that meets the section 7120 criteria on 1 January of any year audits the following twelve months and files its report by 1 April of the year after that.
California CCPA: Cybersecurity Audit Deadline for the 50 to 100 Million Dollar Revenue Tier
The second wave of California cybersecurity audits falls due. Under section 7121(a)(2) of the California Privacy Protection Agency regulations, a business whose annual gross revenue for 2027 was between 50 million and 100 million dollars as of January 1, 2028 must complete its first cybersecurity audit report by April 1, 2029, covering the period from January 1, 2028 through January 1, 2029. The written certification of completion required by section 7124 is filed with the Agency by the same date. A third wave follows on April 1, 2030 for businesses whose 2028 annual gross revenue was under 50 million dollars.
EU AI Act: High-Risk Obligations Apply to AI Embedded in Annex I Regulated Products
The final deferred EU AI Act deadline arrives. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the Chapter III obligations for AI systems classified as high-risk under Article 6(1) and Annex I, meaning AI that functions as a safety component of, or is itself, a product covered by existing EU product legislation such as the medical devices, in vitro diagnostic, machinery, and radio equipment regimes. Those obligations apply from August 2, 2028. Stand-alone Annex III high-risk systems ran to the earlier deferred date of December 2, 2027.
California CCPA: First Cybersecurity Audit Reports, Certifications, and Risk Assessment Filings Due
Three California Privacy Protection Agency obligations converge on April 1, 2028. Under section 7121(a)(1), a business whose annual gross revenue for 2026 exceeded 100 million dollars as of January 1, 2027 must complete its first cybersecurity audit report by this date, covering January 1, 2027 through January 1, 2028. Under section 7124, a member of executive management directly responsible for audit compliance must submit a written certification of completion to the Agency through its website by the same date. Under section 7157(a)(1), a business that conducted risk assessments in 2026 or 2027 must submit the section 7157(b) risk assessment information by the same date: its name and point of contact, the period covered, the number of assessments conducted or updated in total and per section 7150(b) activity, which Civil Code section 1798.140 categories of personal information were involved, and an executive attestation under penalty of perjury. The assessment reports themselves are not filed on this date; under section 7157(e) the Agency or the Attorney General may require them at any time, and a business then has 30 calendar days to produce them.
California CCPA: Risk Assessments Due for Processing Activities Already Underway
Section 7155(b) of the California Privacy Protection Agency regulations sets December 31, 2027 as the date by which a business must have conducted and documented a risk assessment for any processing activity listed in section 7150(b) that it started before the regulations took effect and continued afterwards. The triggering activities include selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for a significant decision, and using personal information to train certain automated systems. Section 7155(b) then directs the business to the section 7157(a)(1) submission rule, which asks for the section 7157(b) risk assessment information (a count of the assessments conducted, the categories of personal information involved, and an executive attestation under penalty of perjury) rather than for the assessments themselves.
EU Cyber Resilience Act Becomes Fully Applicable: Essential Requirements and CE Marking
The EU Cyber Resilience Act, Regulation (EU) 2024/2847, becomes fully applicable on December 11, 2027, three years after it entered into force on December 10, 2024. From this date every product with digital elements placed on the Union market must meet the Annex I essential cybersecurity requirements, be covered by a conformity assessment appropriate to its risk class, carry CE marking, ship with technical documentation and an EU declaration of conformity, and be supported with security updates for a declared support period. The Act phased in ahead of this date: Chapter IV, covering notification of conformity assessment bodies, applied from June 11, 2026, and the Article 14 vulnerability and incident reporting duties from September 11, 2026.
EU AI Act: Annex III High-Risk System Obligations Apply
The deferred compliance deadline for standalone high-risk AI systems under Annex III of the EU AI Act arrives. Regulation (EU) 2026/1744, the Digital Omnibus on AI that entered into force on July 27, 2026, moved the obligations of Chapter III Sections 1, 2 and 3 from August 2, 2026 to this date. Providers of standalone Annex III high-risk systems must by now have completed conformity assessments, established quality management systems, prepared technical documentation, and put post-market monitoring in place. AI embedded in Annex I regulated products follows separately on August 2, 2028.
CCPA Automated Decision-Making Technology Compliance Deadline
Businesses using automated decision-making technology (ADMT) to make significant decisions about consumers must be in compliance with the California Privacy Protection Agency's ADMT regulations as of this date. The regulations, adopted by the CPPA board on July 24, 2025 and approved by the Office of Administrative Law on September 22, 2025, took effect January 1, 2026, with the ADMT obligations themselves phased to January 1, 2027. Covered businesses must provide pre-use notices, honor consumer opt-out rights, and provide access to information about how the technology is used.
EU AI Act: Article 50 Marking Transition Closes for Generative Systems Already on the Market
The four-month transitional period for Article 50(2) content marking closes. The Digital Omnibus on AI, Regulation (EU) 2026/1744, gave providers whose generative AI systems were already placed on the market before August 2, 2026 an extra four months to mark synthetic audio, image, video and text in a machine-readable format detectable as artificially generated. From December 2, 2026 those systems carry the same marking duty as anything launched on or after August 2, 2026. This transition sits outside the Digital Omnibus deferral of the Chapter III high-risk obligations, which moved separately to December 2, 2027 and August 2, 2028.
Cybersecurity Information Sharing Act of 2015 Liability Protections Sunset Again on September 30, 2026
The Cybersecurity Information Sharing Act of 2015 is scheduled to lapse on September 30, 2026. The statute was enacted with a ten-year sunset that ran out on September 30, 2025; Congress then passed a series of short-term extensions before reauthorizing it through September 30, 2026 in the spending bill signed on February 3, 2026. While in force it gives organizations that share qualifying cyber threat indicators and defensive measures a set of legal protections: exemption from Freedom of Information Act disclosure, limits on liability arising from the sharing itself, and protection against waiver of legal privilege.
EU Cyber Resilience Act: 24-Hour Vulnerability and Incident Reporting Duties Apply
On September 11, 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) begins to apply, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents affecting product security. Reports follow a staged timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days for exploited vulnerabilities or one month for severe incidents. Notifications go to the CSIRT designated as coordinator in the relevant Member State and are made available simultaneously to ENISA through a single reporting platform.
Netherlands Cyberbeveiligingswet Enters Into Force, Closing One of the Four Transposition Gaps
The Cyberbeveiligingswet, the Dutch law implementing NIS2, entered into force on 15 August 2026. Organisations in scope are legally required to register in the entiteitenregister, which in the Netherlands is held by the Nationaal Cyber Security Centrum, and the registration duty applies from the date the law took effect.
DoD Suspends CMMC Phase 2; Reform Task Force RFI Responses Due August 14
On July 13, 2026, the Department of War (formerly DoD) CIO suspended CMMC Phase 2 requirements, which had been scheduled to take effect November 10, 2026, and stood up a CMMC Reform Task Force to deliver reform recommendations within roughly 60 days. A companion Request for Information posted to SAM.gov seeks defense industrial base input on compliance cost drivers, control effectiveness, self-attestation, and commercial cybersecurity capabilities, with responses due by email no later than 12:00 pm ET on Friday, August 14, 2026. Phase 1 obligations, the Level 1 and Level 2 self-assessment and affirmation requirements flowing through DFARS 252.204-7021 since November 10, 2025, remain in effect.
EU AI Act Applies Generally; High-Risk Obligations Deferred by Digital Omnibus
The EU AI Act reaches its general application date, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, published 24 July 2026 and in force 27 July 2026) deferred the high-risk system obligations of Chapter III Sections 1, 2 and 3. Stand-alone high-risk systems under Annex III must now comply by 2 December 2027, and high-risk AI embedded in Annex I regulated products by 2 August 2028. What does apply from 2 August 2026 includes the Article 50 transparency obligations for AI that interacts with people or generates synthetic content, alongside the Act's other generally applicable provisions; a four-month transitional period covers Article 50(2) marking for generative systems already on the market before this date.
California Delete Act: Data Brokers Must Process Deletion Requests Through DROP
From August 1, 2026, data brokers registered in California must access the Delete Request and Opt-Out Platform (DROP) and act on the consumer deletion requests it holds. DROP is the accessible deletion mechanism required by the Delete Act (SB 362, signed October 2023) and built by the California Privacy Protection Agency, which had to stand it up for consumer use by January 1, 2026. A single verified consumer request now reaches every registered broker at once. Brokers must check the mechanism at least once every 45 days, delete a requesting consumer's personal information within 45 days, and keep deleting any newly acquired information about that consumer on the same 45-day cycle.
CIRCIA Incident Reporting Final Rule Slips Again: CISA Now Targets September 2026
CISA has again pushed back the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which will add 6 CFR Part 226. The statutory deadline of October 4, 2025 (18 months after the April 2024 proposed rule) passed without a final rule, and the regulatory agenda target moved first to May 2026 and now, as of the current Unified Agenda entry, to September 2026. Once final, the rule will require covered critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
EU Digital Omnibus on AI Defers High-Risk AI Act Obligations to 2027 and 2028
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on July 27, 2026, three days after publication in the Official Journal. First proposed by the European Commission on November 19, 2025, it amends the AI Act to defer high-risk system obligations: standalone Annex III systems must now comply by December 2, 2027, and AI embedded in Annex I regulated products by August 2, 2028. Other obligations still apply from August 2, 2026 as originally scheduled, including Article 50 transparency duties, with a limited transition to December 2, 2026 for generative AI systems already on the market.
UK Cyber Security and Resilience Bill Advances in Lords, Expanding NIS Rules to MSPs
The Cyber Security and Resilience (Network and Information Systems) Bill, introduced in the House of Commons on 12 November 2025, passed its House of Lords second reading on 14 July 2026, with Lords committee stage scheduled for September 2026. The bill amends the NIS Regulations 2018 to bring medium and large managed service providers and data centres at or above 1 megawatt rated IT load into regulation for the first time. It also introduces two-stage incident reporting: an initial notification within 24 hours of becoming aware of an incident and a full report within 72 hours, with the NCSC informed at the same time as the regulator.
EU Commission Refers Four Member States to CJEU Over NIS2 Transposition Failures
The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to notify complete transposition of the NIS2 Directive (Directive (EU) 2022/2555), which member states were required to implement by 17 October 2024. The Commission asked the Court to impose a lump sum and daily penalties on each country until it notifies full transposition. According to the Commission, most member states have complied, meaning 23 of 27 have notified full national implementing measures, and the referrals follow letters of formal notice in November 2024 and reasoned opinions in May 2025.
FAR Council Proposes Government-Wide CUI Rule Adopting NIST SP 800-171 Rev 3
As part of the Revolutionary FAR Overhaul, the FAR Council issued a revised proposed rule (FAR Case 2026-001, 91 FR 37550) that consolidates Controlled Unclassified Information safeguarding into a reorganized FAR Part 40, Information Security and Supply Chain Security. The proposal would require contractor systems handling CUI identified on a new standard form to implement NIST SP 800-171 Revision 3, with DoD-published Organization-Defined Parameter values, and to report CUI incidents within 72 hours of discovery. It replaces the January 2025 FAR Case 2017-016 proposal; the comment period closed July 23, 2026, and the rule is not final as of August 2026.
Executive Order 14412 Sets Binding Federal PQC Migration Deadlines for 2030 and 2031
President signed Executive Order 14412, 'Securing the Nation Against Advanced Cryptographic Attacks,' on June 22, 2026, establishing the first binding government-wide deadlines for post-quantum cryptography migration. Federal agencies must transition all high value assets and high impact systems (excluding National Security Systems) to PQC for key establishment by December 31, 2030, and to PQC for digital signatures by December 31, 2031. The order also directs the FAR Council to publish a proposed rule within 180 days requiring covered federal contractors to comply with NIST's FIPS incorporating PQC algorithms, including FIPS 203, by the end of 2030.
HITRUST CSF v11.8.0 Adds AI and Compliance Mappings and Consolidates Requirement Statements
HITRUST announced CSF version 11.8.0 on May 7, 2026, with the framework available in MyCSF and as a download from May 8, 2026. The release continues the consolidation of requirement statements to reduce overlap within the CSF, adjusts the e1 and i1 baselines, and adds authoritative source mappings including the OWASP Top 10 for Large Language Model Applications 2025 and the Commonwealth of Virginia IT Resource Management Standard SEC530. New e1, i1 and rapid assessment objects created in MyCSF must use v11.8.0, while assessments already created under v11.7.0 may still be submitted.
SEC Regulation S-K Reform Review Puts 2023 Cybersecurity Disclosure Rules Up for Comment
SEC Chairman Paul Atkins announced a comprehensive review of Regulation S-K on January 13, 2026, requesting public comment (File No. CLL-15) on amending the disclosure regime to focus on material information, with comments due April 13, 2026. Because Item 106 cybersecurity disclosures sit within Regulation S-K, the review opened the 2023 cyber rules to reconsideration, and industry commenters, including Business Roundtable, urged the Commission to eliminate Item 106 and rescind the Item 1.05 Form 8-K incident disclosure requirement. No amendment has been proposed or adopted, and both requirements remain in effect as of August 2026.
Indiana, Kentucky, and Rhode Island Privacy Laws Take Effect
Comprehensive privacy laws in Indiana (Consumer Data Protection Act), Kentucky (Consumer Data Protection Act), and Rhode Island (Data Transparency and Privacy Protection Act) all became effective on January 1, 2026, bringing the number of states with operative comprehensive privacy laws to roughly twenty as of August 2026. Indiana and Kentucky follow the familiar Virginia model with exclusive attorney general enforcement, a 30-day cure period, and civil penalties up to $7,500 per violation; Kentucky's Attorney General has established a dedicated Office of Data Privacy to handle enforcement and consumer complaints. Rhode Island diverges in important ways: a lower applicability threshold of 35,000 customers, no cure period, and treatment of violations as deceptive trade practices carrying penalties up to $10,000 per violation.
Germany Transposes NIS2: New BSI Act in Force With a Rolling Three-Month Registration Clock
Germany's NIS2 implementing act was signed on 2 December 2025, published as BGBl. 2025 I Nr. 301 on 5 December 2025, and took effect on 6 December 2025. It replaces the old BSI-Gesetz with a new BSIG that carries the directive's duties directly, including a registration duty in Section 33 and incident reporting duties in Section 32.
European Supervisory Authorities Designate the First Critical ICT Third-Party Providers Under DORA
On November 18, 2025, the three European Supervisory Authorities (the EBA, EIOPA and ESMA) published their first list of critical ICT third-party service providers designated under the Digital Operational Resilience Act, Regulation (EU) 2022/2554. The designated providers span core infrastructure, business and data services supplied to financial entities across the EU, and they now come under direct oversight by the ESAs rather than being supervised only indirectly through their financial-sector customers. DORA itself has applied since January 17, 2025 under Article 64.
India Notifies Final DPDP Rules 2025 With Phased Deadlines Through May 2027
India's Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), operationalizing the DPDP Act, 2023 after a public consultation that drew 6,915 inputs on the January 2025 draft. The rules commence in phases: provisions establishing the Data Protection Board of India took effect on publication, consent manager registration follows after twelve months, and the core obligations covering consent notices, breach notification, children's data, and data principal rights apply eighteen months after publication, in May 2027.
CMMC Phase 1 Begins as DFARS Final Rule Takes Effect
The DFARS final rule for CMMC (DFARS Case 2019-D041, published September 10, 2025) took effect on November 10, 2025, starting Phase 1 of the CMMC phased implementation. From this date, DoD includes clause DFARS 252.204-7021 in applicable solicitations and contracts, requiring CMMC Level 1 (self-assessment) or Level 2 (self-assessment) as a condition of award, with program offices holding discretion to require Level 2 certification assessments in some procurements. Phase 1 is intentionally limited in scope to allow the assessment ecosystem to scale, but it establishes the contractual mechanism for mandatory cybersecurity certification in defense procurement.
NYDFS Part 500 Second Amendment Final Phase: Universal MFA and Asset Inventory in Effect
On November 1, 2025, the final transitional period of the Second Amendment to the New York Department of Financial Services cybersecurity regulation (23 NYCRR Part 500) expired under section 500.22(d)(4). Covered entities must now use multi-factor authentication for any individual accessing any of their information systems under section 500.12, with a narrower scope only for entities qualifying for the limited exemption. Section 500.13(a) simultaneously took effect, requiring written policies and procedures that produce and maintain a complete, accurate, and documented asset inventory tracking owner, location, classification, support expiration date, and recovery time objectives.
ISO 27001:2013 to 2022 Transition Deadline
The three-year transition period for migrating from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 ended on this date under IAF MD 26:2023, which required certification bodies to complete all client transitions within 36 months of the 2022 edition's October 2022 publication. Per the IAF mandatory document, all certifications based on ISO/IEC 27001:2013 expired or were withdrawn at the end of the transition period regardless of their stated expiry date. Any organization that did not complete a transition audit by the deadline no longer holds a valid ISO 27001 certification and must pursue a new initial certification to the 2022 edition.
Maryland Online Data Privacy Act Takes Effect
The Maryland Online Data Privacy Act (MODPA) became effective, introducing one of the most restrictive state privacy laws in the United States. Unlike most other state privacy laws that allow opt-out rights for data sales and targeted advertising, Maryland's law prohibits the sale of sensitive personal data entirely, a ban that consumer consent cannot override, and restricts the collection of personal data to what is reasonably necessary and proportionate to provide the requested service. The law also includes strong protections for minors' data and restricts targeted advertising directed at consumers under 18. By its terms MODPA did not apply to processing activities occurring before April 1, 2026; that transition window has closed and the law now applies in full.
DOJ Data Security Program Reaches Full Enforcement for Bulk Data Transfers
The Department of Justice's Data Security Program (DSP), codified at 28 CFR Part 202 and implementing Executive Order 14117, took effect on April 8, 2025 and reached full enforcement on July 8, 2025 when DOJ's 90-day good-faith compliance policy expired. The program prohibits or restricts transactions that give countries of concern (China, Cuba, Iran, North Korea, Russia, and Venezuela) or covered persons access to government-related data or bulk US sensitive personal data, including genomic, biometric, geolocation, health, and financial data. Additional affirmative obligations for restricted transactions, including due diligence, audits, and reporting, took effect on October 6, 2025.
Tennessee and Minnesota Privacy Laws Take Effect
The Tennessee Information Protection Act (TIPA) took effect July 1, 2025, and the Minnesota Consumer Data Privacy Act became effective on July 31, 2025, adding two more states to the growing roster of comprehensive privacy jurisdictions. Tennessee's law follows the Virginia model and includes a notable affirmative defense provision for organizations that maintain and comply with a written privacy program conforming to NIST privacy framework standards. Minnesota's law includes broader protections and notably requires data protection assessments for certain processing activities.
SEC Withdraws 2022 Cybersecurity Rule Proposals for Investment Advisers and Funds
The SEC formally withdrew 14 pending rule proposals via a notice dated June 12, 2025 and published in the Federal Register on June 17, 2025 (Release No. 33-11377). The withdrawn items include the March 2022 cybersecurity risk management proposal for registered investment advisers, registered investment companies, and business development companies, along with the April 2023 companion proposal covering broker-dealers, clearing agencies, transfer agents, and other market entities. The Commission stated it does not intend to issue final rules on these proposals and will publish a new proposed rule if it pursues future action in any of these areas.
PCI DSS v4.0 Future-Dated Requirements Now Mandatory
All 51 future-dated requirements in PCI DSS v4.0 transitioned from best practice to mandatory, completing the full v4.0 implementation cycle. Key requirements now enforceable include targeted risk analysis for flexible control frequencies, automated detection and response to payment page script modifications, enhanced authentication for all access to the cardholder data environment, and inventory-based management of custom and third-party software. Assessors must now validate compliance with every v4.0 requirement without exception.
PCI DSS v4.0.1 Future-Dated Testing Requirements Now Mandatory
PCI DSS v4.0.1 future-dated requirements became mandatory on 31 March 2025, including Requirement 11.4.7 (multi-tenant service providers must support customer external penetration testing), Requirement 11.3.1.2 (authenticated internal vulnerability scanning), and Requirement 6.4.2 (an automated technical solution that continually detects and prevents web-based attacks on public-facing web applications).
EU AI Act: Prohibited Practices Provisions Apply
The EU AI Act's provisions on prohibited AI practices became applicable, banning categories of AI systems deemed to pose an unacceptable risk to fundamental rights. Prohibited practices under Article 5 include AI systems that deploy subliminal or manipulative techniques causing significant harm, exploit vulnerabilities of specific groups, perform social scoring by public or private actors, conduct certain forms of predictive policing based solely on profiling, infer emotions in workplaces and educational institutions, build facial recognition databases through untargeted scraping, use biometric categorization to infer sensitive attributes, and use real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions). AI literacy obligations under Article 4 became applicable on the same date. General-purpose AI (GPAI) model provider obligations followed separately on 2 August 2025.
CISA Known Exploited Vulnerabilities Catalog Exceeds 1,200 Entries
The CISA KEV catalog surpassed 1,200 actively exploited vulnerabilities in early 2025 and had grown to more than 1,650 entries as of August 2026. Federal civilian agencies must remediate KEV-listed vulnerabilities within timelines mandated by Binding Operational Directive 22-01, and private sector organizations are strongly urged to prioritize these vulnerabilities in their vulnerability management and testing programs.
HIPAA Security Rule NPRM Published in Federal Register
HHS published the Notice of Proposed Rulemaking (NPRM) to modernize the HIPAA Security Rule, the first major update since the 2013 Omnibus Rule. The proposal eliminates the distinction between addressable and required implementation specifications, mandates encryption of ePHI at rest and in transit with limited exceptions, requires multi-factor authentication, and establishes 72-hour system restoration requirements, alongside annual compliance audits and network segmentation. The comment period closed March 7, 2025 with nearly 5,000 comments, and no final rule has issued; the 2026 Unified Agenda moved the rulemaking to the Long-Term Actions agenda with final action now projected for July 2027, slipping from a prior May 2026 target.
Five State Privacy Laws Take Effect: Iowa, Delaware, Nebraska, New Hampshire, New Jersey
Privacy laws in Iowa, Delaware, Nebraska, and New Hampshire became effective on January 1, 2025, with New Jersey's law following on January 15, 2025, marking the largest single-month expansion of state privacy coverage in the United States. While these laws largely follow the Virginia/Connecticut model, there are notable variations: Delaware's law has a lower applicability threshold of 35,000 consumers, and New Jersey's law classifies financial information as sensitive data requiring consent. With these additions, nineteen US states had enacted comprehensive privacy legislation, with more taking effect through 2025 and 2026.
CMMC 2.0 Final Rule Effective Date
The CMMC Program final rule (32 CFR Part 170) became effective, formally establishing CMMC as enforceable regulation for the defense industrial base. The program rule defines the three CMMC levels, the assessment and certification requirements for each, and the roles of contractors, C3PAOs, and DoD in the certification ecosystem. Contractual enforcement arrived separately through the 48 CFR acquisition rule revising DFARS 252.204-7021, published September 10, 2025 and effective November 10, 2025, which started the four-phase rollout: Phase 1 (Level 1 and Level 2 self-assessments in new solicitations) began on that date. Phase 2 third-party assessment requirements were originally scheduled for November 10, 2026, but DoD suspended Phase 2 on July 13, 2026 pending its CMMC Reform Task Force review.
CPPA Finalizes Automated Decision-Making, Risk Assessment, and Cyber Audit Rules
The California Privacy Protection Agency published proposed regulations on automated decision-making technology (ADMT), risk assessments, and cybersecurity audits on November 22, 2024, opening the formal comment period. The board adopted the final package on July 24, 2025, and the Office of Administrative Law approved it on September 22, 2025. The regulations took effect January 1, 2026. Businesses using ADMT to make significant decisions about consumers must provide pre-use notices, honor opt-out rights, and provide access to information about how the technology is used, with compliance required by January 1, 2027.
CMMC 2.0 Final Rule Published
The Department of Defense published the CMMC 2.0 final rule (32 CFR Part 170) in the Federal Register, completing the regulatory process that began with the December 2023 proposed rule. The final rule establishes the definitive certification requirements, assessment processes, and phased implementation timeline for the defense industrial base. Key provisions include the three certification levels, C3PAO assessment methodology, POA&M requirements (limited, conditional, with 180-day closeout), and affirmation requirements for senior officials of defense contractors.
EU AI Act Enters Into Force
The EU AI Act (Regulation (EU) 2024/1689) officially entered into force, starting the clock on its phased compliance deadlines. The first obligations, covering AI literacy requirements and prohibited AI practices, became applicable six months later on 2 February 2025, with general-purpose AI model obligations following on 2 August 2025. The high-risk system timeline was later extended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026): obligations for Annex III high-risk systems now apply from 2 December 2027, and obligations for high-risk AI embedded in regulated products under Annex I apply from 2 August 2028.
FTC Amended Health Breach Notification Rule Takes Effect
The FTC's amended Health Breach Notification Rule became effective on July 29, 2024 (final rule published May 30, 2024, 89 FR 47028), expanding the definition of personal health record (PHR) to cover health apps, fitness trackers, and other direct-to-consumer digital health tools not covered by HIPAA. The amendments clarify that unauthorized sharing of health data with third parties (not just traditional security breaches) constitutes a reportable breach. Entities must notify affected individuals and the FTC without unreasonable delay and no later than 60 days after discovering a breach, with FTC notice for breaches affecting 500 or more individuals due at the same time as individual notice, and media notice required in some cases.
NIST AI RMF Generative AI Profile Published
NIST published the Generative AI Profile (NIST AI 600-1), a companion resource to the AI RMF 1.0 that addresses risks unique to generative AI systems including large language models, image generators, and code synthesis tools. The profile identifies 12 risks specific to generative AI, including confabulation, data privacy in training corpora, information integrity, harmful content generation, and environmental impact. For each risk, the profile maps relevant AI RMF subcategories and provides suggested actions across the Govern, Map, Measure, and Manage functions.
Oregon OCPA and Texas TDPSA Take Effect
The Oregon Consumer Privacy Act (OCPA) and Texas Data Privacy and Security Act (TDPSA) became effective, continuing the expansion of state-level privacy regulation. Oregon's law is notable for having no revenue threshold, applying to any entity processing 100,000 Oregon consumers' data or 25,000 consumers' data when deriving 25% of revenue from data sales. Texas's TDPSA is significant due to the state's large population and economy, substantially expanding the number of consumers covered by comprehensive privacy laws.
SEC Cybersecurity Rules Effective for Smaller Reporting Companies
The SEC cybersecurity incident disclosure rules on Form 8-K became effective for smaller reporting companies on June 15, 2024, extending the four-business-day material incident reporting requirement to all SEC registrants. The 180-day deferral granted to smaller filers beyond the December 18, 2023 compliance date for other registrants has now expired. Annual cybersecurity risk management and governance disclosures under Regulation S-K Item 106 already applied to smaller reporting companies, with no deferral, beginning with fiscal years ending on or after December 15, 2023.
PCI DSS v4.0.1 Released with Clarifications
The PCI Security Standards Council released PCI DSS v4.0.1 on June 11, 2024 as a limited revision correcting formatting and typographical errors and clarifying the focus and intent of certain requirements. No requirements were added or removed. Notable clarifications include a note that multi-factor authentication does not apply to accounts using phishing-resistant authentication factors, narrowed applicability guidance for payment page script requirements, and reverted patch management language limiting mandatory timelines to critical vulnerabilities. PCI DSS v4.0 was retired on December 31, 2024, making v4.0.1 the only active version of the standard.
Australian ISM June 2024 Update Released
The Australian Signals Directorate (ASD) released the June 2024 update to the Information Security Manual (ISM), the security control framework underpinning IRAP assessments for Australian government systems. The update split the GOVERN cyber security principles into separate GOVERN and IDENTIFY sets, extended CISO governance responsibilities to operational technology alongside IT, added controls addressing generative AI and large language model security, tightened multi-factor authentication requirements including disabling authentication protocols that do not support MFA, and adopted OWASP mobile application security standards. The ISM is updated quarterly, and this release restructured the manual's principles more substantially than a typical quarterly revision.
NIST SP 800-171 Revision 3 Published
NIST published SP 800-171 Revision 3, significantly restructuring the standard for protecting Controlled Unclassified Information (CUI) in non-federal systems. Rev 3 reorganizes requirements into 17 control families (aligned with SP 800-53 Rev 5), consolidates the 110 Rev 2 requirements into 97 while the companion assessment guide expands to 422 determination statements, introduces Organization-Defined Parameters (ODPs) that allow tailoring of specific thresholds, and removes the distinction between basic and derived requirements. The revision represents the most substantial change to 800-171 since its original publication.
PCI DSS v3.2.1 Officially Retired
PCI DSS v3.2.1 was officially retired on March 31, 2024 after a two-year transition period, making v4.0 the sole active version at that time. Assessments initiated after this date could no longer use v3.2.1. The standard has since evolved further: PCI SSC published a limited revision, v4.0.1, in June 2024 and retired v4.0 on December 31, 2024, and the future-dated v4.0 requirements became mandatory on March 31, 2025. All assessments now validate against v4.0.1 with the full requirement set in force.
EU AI Act Adopted by European Parliament
The European Parliament adopted the EU Artificial Intelligence Act, the world's first comprehensive legal framework for AI regulation. The regulation establishes a risk-based classification system with four tiers: unacceptable risk (banned), high risk (strict compliance obligations), limited risk (transparency requirements), and minimal risk (voluntary codes of conduct). The Act applies to providers, deployers, importers, and distributors of AI systems placed on the EU market or whose output is used within the EU.
NIST Cybersecurity Framework 2.0 Released
NIST released version 2.0 of the Cybersecurity Framework, the first major revision since the framework's original publication in 2014. CSF 2.0 introduces a sixth core function, Govern, which elevates cybersecurity governance, risk management strategy, and supply chain risk management to a top-level concern alongside Identify, Protect, Detect, Respond, and Recover. The update also expands the framework's applicability beyond critical infrastructure to all organizations, adds extensive implementation examples, and introduces Community Profiles for sector-specific guidance.
CMMC 2.0 Proposed Rule Published in Federal Register
The Department of Defense published the CMMC 2.0 proposed rule (32 CFR Part 170) in the Federal Register, initiating a 60-day public comment period that closed February 26, 2024. The proposed rule formalized the three-tiered model: Level 1 (annual self-assessment, 15 security requirements from FAR 52.204-21), Level 2 (self-assessment or third-party C3PAO certification depending on contract, 110 requirements from NIST 800-171 Rev 2), and Level 3 (government-led assessment, adding 24 selected NIST 800-172 requirements on top of the Level 2 baseline). The rule established the C3PAO ecosystem, assessment methodology, and Plans of Action and Milestones (POA&M) closeout requirements.
SEC Cybersecurity Incident Disclosure Rules Take Effect for Most Filers
The SEC cybersecurity disclosure rules reached their first compliance date: all registrants other than smaller reporting companies must report material cybersecurity incidents on Form 8-K Item 1.05 within four business days of a materiality determination as of December 18, 2023, with smaller reporting companies following on June 15, 2024. Annual cybersecurity risk management, strategy, and governance disclosures under Regulation S-K Item 106 apply to annual reports for fiscal years ending on or after December 15, 2023. The rules remain in effect as of 2026, though industry groups have petitioned the SEC to rescind the Item 1.05 incident reporting requirement.
ISO/IEC 42001:2023 Published -- AI Management Systems
ISO published ISO/IEC 42001:2023, the world's first certifiable international standard for Artificial Intelligence Management Systems (AIMS). The standard provides a structured framework for organizations that develop, provide, or use AI systems to establish, implement, maintain, and continually improve a responsible AI management system. ISO 42001 follows the familiar ISO management system structure (Harmonized Structure) and addresses AI-specific concerns including bias, transparency, data governance, and human oversight, with Annex A providing a set of AI-specific controls and Annex B offering implementation guidance.
Australian Essential Eight Maturity Model Updated
The Australian Signals Directorate's Australian Cyber Security Centre (ACSC) released an updated Essential Eight Maturity Model, refining maturity level definitions and tightening requirements across all eight mitigation strategies. Key changes include a 48-hour patching timeline for vulnerabilities in internet-facing services across Maturity Levels 1 through 3 when a vendor assesses the vulnerability as critical or a working exploit exists, weekly rather than fortnightly vulnerability scanning for critical vulnerabilities, strengthened and phishing-resistant multi-factor authentication requirements, and annual application control ruleset reviews incorporating Microsoft's recommended block rules. The Essential Eight remains the baseline security standard referenced by IRAP assessments for Australian government cloud services.
SEC Enforcement on SolarWinds: Precedent for CISO Accountability and Supply Chain Disclosures
On October 30, 2023, the SEC filed a complaint against SolarWinds and its CISO Timothy Brown in the aftermath of the 2020 SolarWinds Orion supply chain compromise (discovered December 2020), alleging they misled investors about the company's cybersecurity posture. A federal judge dismissed most claims in July 2024, leaving securities fraud claims tied to pre-incident statements about security practices. After the parties reached a settlement in principle in July 2025, the SEC voluntarily dismissed the remaining claims with prejudice on November 20, 2025, ending the case without penalties. The action nonetheless demonstrated that materially misleading cybersecurity disclosures can draw securities fraud charges, and the SEC's 2023 cybersecurity disclosure rules (in effect since December 2023) requiring disclosure of material cybersecurity incidents within four business days of a materiality determination remain in force.
HITRUST CSF v11.2 Released with AI Risk Management Sources
HITRUST released CSF v11.2.0 on October 10, 2023, adding NIST AI RMF v1.0, ISO/IEC 23894, and ISO 31000 as authoritative sources together with a new selectable Artificial Intelligence Risk Management compliance factor. The release also added ISO 27001:2022 and ISO 27002:2022, the Ontario Personal Health Information Protection Act, and VA Directive 6500 as sources, refreshed mappings for 23 NYCRR 500, the FTC Red Flags Rule, and Nevada Title 52 603A, and began an initial wave of requirement statement consolidation to reduce overlap within the CSF.
HITRUST Releases Industry's First AI Assurance Program
HITRUST released its AI Assurance Program, the industry's first certifiable approach to managing AI-related risks in regulated industries. Built on the HITRUST CSF (v11.2 at release) and aligned with ISO and NIST AI risk management guidance, the program allows organizations to integrate AI risk management dimensions into existing e1, i1, and r2 assurance reports, supports shared responsibility and inheritance models for AI service providers, and announced a forthcoming standalone AI security certification for deployed AI systems.
CISA Known Exploited Vulnerabilities Catalog Surpasses 1,000 Entries
CISA's Known Exploited Vulnerabilities (KEV) catalog, established in November 2021 via BOD 22-01, surpassed 1,000 entries, a milestone CISA marked in a September 18, 2023 blog post. The catalog, which requires federal civilian agencies to remediate listed vulnerabilities within defined timelines, has become a de facto standard for vulnerability prioritization across the private sector. CISA enriches each entry with metadata including known ransomware campaign use, required remediation actions, due dates, and vendor advisory notes. The catalog's adoption by SOC 2 auditors, HITRUST assessors, and cyber insurance underwriters as a minimum patching standard solidified its role beyond federal compliance.
TikTok Fined EUR 345 Million for Children's Privacy Violations
The Irish DPC fined TikTok Technology Limited EUR 345 million for multiple GDPR violations related to the processing of children's personal data on the TikTok platform. Key findings included that child users' accounts were set to public by default, the paired accounts (Family Pairing) feature had verification weaknesses, and the platform's use of dark patterns nudged children toward less private settings. The decision also found transparency failures in how information was communicated to child users.
SEC Adopts Cybersecurity Disclosure Rules
The SEC adopted final rules requiring public companies to disclose material cybersecurity incidents within four business days on Form 8-K and to provide annual disclosures of cybersecurity risk management, strategy, and governance on Form 10-K. The rules apply to all SEC registrants and mandate that companies describe board oversight of cybersecurity risk, management's role in assessing and managing risk, and the processes used to identify and manage threats. This represented the most significant federal cybersecurity disclosure mandate for public companies to date.
EU-US Data Privacy Framework Adequacy Decision Adopted
The European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF), restoring a legal mechanism for transferring personal data from the EU to certified US organizations. The framework introduced new safeguards including binding limitations on US intelligence access to EU data, a Data Protection Review Court, and enhanced oversight mechanisms. US organizations must self-certify through the Department of Commerce to rely on the DPF as a transfer mechanism.
CPRA Enforcement Begins by California Privacy Protection Agency
The California Privacy Protection Agency (CPPA) gained authority to enforce the CPRA's statutory amendments to the CCPA on July 1, 2023, alongside the California Attorney General's existing enforcement authority. Enforcement of the agency's implementing regulations was briefly delayed: on June 30, 2023, the Sacramento County Superior Court stayed enforcement of the March 2023 regulations for one year, but on February 9, 2024 the Third District Court of Appeal reversed that ruling, restoring the CPPA's authority to enforce the regulations immediately. The CPPA can conduct investigations, issue subpoenas, bring administrative enforcement actions, and impose fines of up to $2,500 per violation or $7,500 per intentional violation.
Colorado CPA and Connecticut CTDPA Take Effect
The Colorado Privacy Act (CPA) and Connecticut Data Privacy Act (CTDPA) both became effective, bringing the total number of active comprehensive state privacy laws to four alongside California and Virginia. Colorado's law is notable for requiring businesses to recognize universal opt-out mechanisms by July 2024, while Connecticut's CTDPA closely mirrors the Virginia model but adds protections around consent for processing of minors' data. Both laws grant consumers rights to access, correct, delete, and port their data.
MOVEit Transfer Mass Exploitation (CVE-2023-34362): Supply Chain Compliance Fallout
The Cl0p ransomware group exploited a critical SQL injection zero-day (CVE-2023-34362) in Progress Software's MOVEit Transfer managed file transfer application, compromising over 2,600 organizations and exposing data of approximately 90 million individuals. Victims included major healthcare systems, financial institutions, government agencies, and their downstream service providers. The attack targeted the file transfer infrastructure itself rather than individual organizations, making it one of the largest supply chain breaches in history.
FedRAMP Releases Rev 5 Baselines and Transition Plan
FedRAMP released its Rev 5 baselines and CSP Transition Plan on May 30, 2023, replacing the Rev 4 baselines based on NIST SP 800-53 Rev 4. The updated baselines align with NIST SP 800-53 Rev 5 and SP 800-53B, incorporating new control families for supply chain risk management (SR) and personally identifiable information processing and transparency (PT), along with significant changes to existing families. Cloud service providers were placed into phase-based transition tracks; those in continuous monitoring had to develop transition schedules by September 1, 2023 and complete implementation in line with their annual assessment cycle. The transition window has since closed, and Rev 5 is now the operative baseline for all FedRAMP authorizations.
Meta Receives Record EUR 1.2 Billion GDPR Fine
The Irish DPC imposed a record EUR 1.2 billion fine on Meta Platforms Ireland for transferring EU users' personal data to the United States without adequate safeguards following the Schrems II ruling. The decision also ordered Meta to suspend transatlantic data transfers and bring its processing operations into compliance within specified deadlines. This remains the largest GDPR fine ever imposed and was issued following an EDPB binding decision.
CISA Launches Secure by Design Initiative via Joint International Guidance
CISA, together with the FBI, NSA, and international partners including the UK NCSC, Australian ACSC, and Canadian Cyber Centre, published Shifting the Balance of Cybersecurity Risk: Security-by-Design and -Default Principles, formally launching the Secure by Design initiative and calling on software manufacturers to take ownership of customer security outcomes. An expanded joint guide followed in October 2023. On May 8, 2024, CISA added a voluntary Secure by Design Pledge for enterprise software manufacturers, initially signed by 68 companies, committing to seven goals: increased MFA adoption, reduction of default passwords, reduction of entire classes of vulnerability, increased customer installation of security patches, published vulnerability disclosure policies, transparent CVE reporting, and giving customers evidence of intrusions. More than 370 companies have since signed.
Banner Health Pays $1.25M HIPAA Settlement
HHS OCR settled with Banner Health for $1.25 million following a 2016 cyberattack that compromised the electronic protected health information (ePHI) of approximately 2.81 million individuals. The investigation found that Banner Health failed to conduct an accurate and thorough risk analysis, lacked sufficient monitoring of health information system activity, and did not implement adequate authentication controls. The corrective action plan requires two years of OCR monitoring.
NIST AI Risk Management Framework 1.0 Released
NIST published the AI Risk Management Framework (AI RMF) 1.0, establishing a voluntary, rights-preserving framework for managing risks associated with artificial intelligence systems throughout their lifecycle. The framework is organized around four core functions (Govern, Map, Measure, and Manage), providing organizations with a structured approach to identifying, assessing, and mitigating AI-specific risks including bias, transparency, accountability, and safety. The AI RMF is designed to be technology-agnostic and sector-neutral, complementing existing risk management frameworks like the NIST Cybersecurity Framework.
HITRUST CSF v11 Released: Major Framework Restructuring
HITRUST released CSF version 11, redesigning the framework into a fully traversable assessment portfolio. The update introduced the new e1 (Essentials, 1-year) assessment with 44 core requirement statements and nested it inside the i1 (Implemented, 1-year, 182 requirements, launched in 2022) and the r2 (Risk-based, 2-year), so each assessment builds on the one below it. v11 added NIST SP 800-53 Rev 5 and Health Industry Cybersecurity Practices as authoritative sources and refreshed mappings to NIST SP 800-171, NIST CSF, and HIPAA, with HITRUST citing up to a 45 percent effort reduction for i1 certification over two years.
FTC Orders Drizly CEO to Implement Security Program
The FTC finalized its order against Drizly and its CEO James Cory Rellas personally for security failures that exposed the personal data of approximately 2.5 million consumers, after first announcing the action in October 2022. The order requires Rellas to implement an information security program for the next ten years at any company that collects data on more than 25,000 individuals where he serves as majority owner, CEO, or a senior officer with security responsibilities. This was a landmark action because it attached compliance obligations directly to an individual executive, not just the corporate entity.
California CPRA Amendments Take Effect
The California Privacy Rights Act (CPRA) amendments to the CCPA became operative, significantly expanding consumer privacy rights and business obligations. Key additions include the right to correct inaccurate personal information, the right to limit the use and disclosure of sensitive personal information, and new obligations around data minimization and purpose limitation. The CPRA also created the California Privacy Protection Agency (CPPA) as the first dedicated state privacy enforcement agency in the United States.
Virginia CDPA Becomes First Comprehensive State Privacy Law in Effect
The Virginia Consumer Data Protection Act (CDPA) became the first comprehensive state privacy law outside California to take effect, establishing consumer rights including access, correction, deletion, portability, and the right to opt out of targeted advertising, sale of personal data, and profiling. The law applies to entities that control or process personal data of at least 100,000 Virginia residents, or 25,000 residents if deriving over 50% of gross revenue from data sales. Enforcement is exclusively through the Virginia Attorney General.
FedRAMP Authorization Act Signed Into Law
The FedRAMP Authorization Act was signed into law as part of the FY2023 National Defense Authorization Act, codifying the Federal Risk and Authorization Management Program for the first time. The legislation established FedRAMP as the authoritative framework for federal cloud security assessments, mandated agency presumption of adequacy for existing FedRAMP authorizations, and required automated continuous monitoring. It formalized the program that had operated since 2011 under OMB memoranda alone.
Japan Launches ISMAP-LIU (Low-Impact Use) Assessment Track
Japan's ISMAP (Information system Security Management and Assessment Program) expanded with the launch of ISMAP-LIU (ISMAP for Low-Impact Use), which began operation on November 1, 2022. ISMAP-LIU is a streamlined assessment track specifically for SaaS services used in government operations and information processing with low security risk (Confidentiality class-2 information). It reduces the assessment burden relative to the full ISMAP process while maintaining baseline security expectations, creating a more accessible pathway for SaaS vendors, including international providers, seeking to serve Japan's government market.
ISO/IEC 27001:2022 Published
ISO/IEC 27001:2022 was officially published, replacing the 2013 edition as the global standard for information security management systems (ISMS). The revision incorporates the restructured Annex A controls from ISO 27002:2022, updates clause language to align with the latest ISO Harmonized Structure, and adds explicit requirements for monitoring organizational context changes and stakeholder needs. A three-year transition period was established, requiring all certified organizations to migrate by October 31, 2025.
CISA Issues Binding Operational Directive 23-01: Vulnerability Scanning Requirements
CISA published Binding Operational Directive (BOD) 23-01, 'Improving Asset Visibility and Vulnerability Detection on Federal Networks,' requiring federal civilian executive branch (FCEB) agencies to perform automated asset discovery every 7 days and vulnerability enumeration on all discovered assets every 14 days. Agencies were required to initiate automated asset discovery by April 3, 2023, and begin reporting vulnerability enumeration results to CISA's Continuous Diagnostics and Mitigation (CDM) dashboard. While directly binding only on federal agencies, the directive set a de facto industry benchmark for vulnerability management programs.
Instagram Fined EUR 405 Million Over Children's Data
The Irish DPC fined Meta's Instagram EUR 405 million for violations related to the processing of children's personal data. The investigation focused on the public exposure of children's email addresses and phone numbers through Instagram's business account feature and the default public profile setting for minors. This was the second-largest GDPR fine at the time and the largest penalty specifically concerning children's data protection.
Spain Royal Decree 311/2022 Updates ENS Framework
Spain published Royal Decree 311/2022, replacing the previous Royal Decree 3/2010 that established the Esquema Nacional de Seguridad (ENS). The updated framework modernizes security requirements for Spain's public sector and any private organizations providing services to government entities. Key changes include alignment with the EU NIS Directive (2016/1148) as transposed into Spanish law, new specific compliance profiles, provisions for cloud services and supply chain security, and a 24-month transition period for pre-existing systems that ended May 5, 2024.
PCI DSS v4.0 Released
The PCI Security Standards Council published PCI DSS v4.0, the first major revision since v3.2.1 in 2018. The update introduced 64 new requirements, a customized approach for meeting security objectives, and expanded multi-factor authentication mandates. Organizations were given a two-year transition window, with v3.2.1 retiring on March 31, 2024. A limited revision, v4.0.1, was published in June 2024 and became the only supported version after v4.0 retired on December 31, 2024; all 51 future-dated requirements became mandatory on March 31, 2025.
ISO/IEC 27002:2022 Published with Restructured Controls
ISO/IEC 27002:2022 replaced the 2013 edition with a completely restructured control set, consolidating 114 controls into 93 controls organized under four themes: Organizational, People, Physical, and Technological. The update introduced 11 new controls addressing cloud security, threat intelligence, ICT readiness for business continuity, and data masking, among others. This restructuring directly reshaped Annex A of ISO 27001 and set the foundation for the ISO/IEC 27001:2022 revision published in October 2022.
Log4Shell (CVE-2021-44228) Zero-Day Disclosed, Compliance Impact Across All Frameworks
A critical remote code execution vulnerability in Apache Log4j 2 (versions 2.0-beta9 through 2.15.0, excluding security releases 2.12.2, 2.12.3, and 2.3.1) was publicly disclosed on December 9, 2021, receiving a CVSS score of 10.0. The flaw allowed unauthenticated remote code execution via crafted JNDI lookup strings in logged data. Due to Log4j's ubiquity in Java-based applications, the vulnerability affected hundreds of thousands of organizations worldwide, including healthcare systems, financial institutions, SaaS platforms, and defense contractors.
WhatsApp Fined EUR 225 Million for Transparency Violations
Ireland's Data Protection Commission (DPC) fined WhatsApp Ireland EUR 225 million for failing to provide transparent information to users and non-users about how their personal data was processed. The European Data Protection Board (EDPB) intervened with an Article 65 binding decision that required the DPC to increase the fine significantly from its original draft. The ruling found deficiencies in WhatsApp's privacy notices under Articles 12, 13, and 14 of GDPR. WhatsApp challenged the EDPB's binding decision, and on 10 February 2026 the Court of Justice of the EU held in Case C-97/23 P that EDPB binding decisions are directly reviewable by EU courts, sending the dispute back to the General Court on the merits.
HITRUST CSF v9.5 Released with HIPAA Breach Notification Updates
HITRUST released CSF v9.5 in September 2021, updating Control Category 11.0 (Information Security Incident Management) to strengthen HIPAA breach notification alignment. Control 11(a) added a requirement that breach notifications to affected individuals use plain language, and Control 11(c) defined incident discovery as the first day the security event is or would have been known to the organization through reasonable due diligence. v9.5.0 was also the first release under HITRUST's v[Major].[Minor].[Errata] versioning policy.
Amazon Receives Record EUR 746 Million GDPR Fine
Luxembourg's CNPD issued a EUR 746 million fine against Amazon Europe Core on July 15, 2021 for processing personal data for targeted advertising without a valid legal basis under GDPR. At issuance it was the largest GDPR fine ever imposed. The Luxembourg Administrative Tribunal upheld the decision in March 2025, but on March 12, 2026 the Administrative Court annulled the fine on procedural grounds, finding the CNPD had not analysed fault or negligence, while confirming the core finding that Amazon could not rely on legitimate interests for behavioral advertising. The case was returned to the CNPD.
FTC Settlement with Flo Health Over Health Data Sharing
The FTC finalized its order against Flo Health for sharing sensitive health data from its period-tracking app with third-party analytics firms including Facebook and Google, despite explicit privacy promises to users. The settlement requires Flo to obtain independent reviews of its privacy practices and obtain user consent before sharing health information. This case marked a turning point in FTC enforcement around health app data sharing outside HIPAA's traditional scope.
NIST SP 800-53 Rev 5 Errata Update and Supplemental Materials Released
NIST issued the first errata update (Update 1) to SP 800-53 Revision 5, correcting errors, omissions, and unclear language identified through internal review and stakeholder feedback, with corresponding errata applied to the SP 800-53B control baselines. No new controls were added and the technical requirements were unchanged. NIST simultaneously released supplemental materials, including an analysis of changes from Revision 4 to Revision 5, a mapping of Revision 4 Appendix J privacy controls to Revision 5, and crosswalks to the NIST Cybersecurity Framework and ISO 27001. The Rev 5 catalog has since been amended by Patch Release 5.1.1 (November 7, 2023), which added control IA-13 and three enhancements addressing identity assertion and access token protection, and by Release 5.2.0 (August 27, 2025), which added three controls covering secure software development and update integrity.