CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Compliance

Regulatory and compliance calendar

Upcoming compliance deadlines: curated regulatory dates and CISA directive deadlines. Near-term product End of Support and End of Life dates from endoflife.date are an optional layer, off by default so the compliance signal stays clear; use the toggle below to show them. Curated regulatory candidates are reviewed by an operator before they appear, and the directive and lifecycle dates are derived automatically from their published sources.

Upcoming
  • 2026-07-29in 2d

    Cisco IOS XE 17.9: End of Life

    Product lifecycle

    Cisco IOS XE 17.9 reaches End of Life on 2026-07-29 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-08-02in 6d

    EU AI Act general application date

    EU AI ActEU

    The baseline application date of Regulation (EU) 2024/1689. After the 2026 simplification omnibus, obligations for high-risk systems do not start on this date; they were deferred to 2027-12-02 and 2028-08-02. The remaining framework, including transparency and governance provisions, becomes applicable.

  • 2026-08-06in 10d

    F5 BIG-IP 21.0: End of Life

    Product lifecycle

    F5 BIG-IP 21.0 reaches End of Life on 2026-08-06 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-08-06in 10d

    F5 BIG-IP 21.0: End of Support

    Product lifecycle

    F5 BIG-IP 21.0 reaches End of Support on 2026-08-06 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-08-09in 13d

    BOD 26-04: Update vulnerability remediation processes to the risk-based tiered model (within 60 days of issuance)

    CISA directiveUS

    Prioritizing Security Updates Based on Risk. Compliance deadline from CISA BOD 26-04.

    CISA BOD 26-04
  • 2026-08-27in 31d

    Kubernetes 1.34: End of Support

    Product lifecycle

    Kubernetes 1.34 reaches End of Support on 2026-08-27 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-09-07in 42d

    OpenSSL 3.0: End of Life

    Product lifecycle

    OpenSSL 3.0 reaches End of Life on 2026-09-07 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-09-11in 46d

    EU Cyber Resilience Act reporting obligations apply

    CRAEU

    Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform (early warning within 24 hours, full notification within 72 hours). Main obligations follow on 2027-12-11.

  • 2026-09-18in 53d

    OpenJDK (Oracle builds) 26: End of Life

    Product lifecycle

    OpenJDK (Oracle builds) 26 reaches End of Life on 2026-09-18 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-09-30in 2mo

    FreeBSD 15.0: End of Life

    Product lifecycle

    FreeBSD 15.0 reaches End of Life on 2026-09-30 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-09-30in 2mo

    Fortinet FortiOS 7.2: End of Life

    Product lifecycle

    Fortinet FortiOS 7.2 reaches End of Life on 2026-09-30 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-10-01in 2mo

    Python 3.13: End of Support

    Product lifecycle

    Python 3.13 reaches End of Support on 2026-10-01 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-10-13in 3mo

    Windows 11-24h2-w: End of Life

    Product lifecycle

    Windows 11-24h2-w reaches End of Life on 2026-10-13 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-10-13in 3mo

    Windows 11-24h2-w: End of Support

    Product lifecycle

    Windows 11-24h2-w reaches End of Support on 2026-10-13 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-10-13in 3mo

    Windows 10-1607-e-lts: End of Life

    Product lifecycle

    Windows 10-1607-e-lts reaches End of Life on 2026-10-13 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-10-13in 3mo

    Windows Server 2022: End of Support

    Product lifecycle

    Windows Server 2022 reaches End of Support on 2026-10-13 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-10-17in 3mo

    NIS2 Directive two-year application milestone

    NIS2EU

    Two years after the 2024-10-17 transposition deadline, national supervisory and enforcement regimes for essential and important entities are expected to be fully operational across member states.

  • 2026-10-20in 3mo

    Node.js 24: End of Support

    Product lifecycle

    Node.js 24 reaches End of Support on 2026-10-20 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-10-22in 3mo

    OpenSSL 3.4: End of Life

    Product lifecycle

    OpenSSL 3.4 reaches End of Life on 2026-10-22 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-10-27in 3mo

    Kubernetes 1.34: End of Life

    Product lifecycle

    Kubernetes 1.34 reaches End of Life on 2026-10-27 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-10-29in 3mo

    Citrix Virtual Apps and Desktops 2503: End of Life

    Product lifecycle

    Citrix Virtual Apps and Desktops 2503 reaches End of Life on 2026-10-29 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-10-30in 3mo

    Citrix Virtual Apps and Desktops 2603: End of Support

    Product lifecycle

    Citrix Virtual Apps and Desktops 2603 reaches End of Support on 2026-10-30 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-10-31in 3mo

    Python 3.10: End of Life

    Product lifecycle

    Python 3.10 reaches End of Life on 2026-10-31 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-11-01in 3mo

    Alpine Linux 3.21: End of Life

    Product lifecycle

    Alpine Linux 3.21 reaches End of Life on 2026-11-01 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-11-01in 3mo

    OpenSSL 3.6: End of Life

    Product lifecycle

    OpenSSL 3.6 reaches End of Life on 2026-11-01 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-11-10in 4mo

    CMMC Phase 2 begins, Level 2 third-party certification required

    CMMCUS

    Defense contractors handling Controlled Unclassified Information (CUI) face the Level 2 certification assessment requirement in applicable solicitations as a condition of contract award. The assessment must be performed by an authorized CMMC Third-Party Assessment Organization (C3PAO), and the Department of Defense may delay the requirement to an option period at its discretion. Contractors without Conditional or Final Level 2 status will be ineligible for affected awards.

  • 2026-11-10in 4mo

    Windows 11-23h2-e: End of Life

    Product lifecycle

    Windows 11-23h2-e reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-11-10in 4mo

    Windows 11-23h2-e: End of Support

    Product lifecycle

    Windows 11-23h2-e reaches End of Support on 2026-11-10 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-11-10in 4mo

    .NET 9: End of Life

    Product lifecycle

    .NET 9 reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-11-10in 4mo

    .NET 8: End of Life

    Product lifecycle

    .NET 8 reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-11-12in 4mo

    PostgreSQL 14: End of Life

    Product lifecycle

    PostgreSQL 14 reaches End of Life on 2026-11-12 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-12-02in 4mo

    EU AI Act watermarking obligations for AI-generated content

    EU AI ActEU

    Providers must have machine-readable marking and transparency solutions for synthetic content in place. The 2026 omnibus set this deadline after cutting the proposed grace period from six months to three.

  • 2026-12-07in 4mo

    BOD 26-04: Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance)

    CISA directiveUS

    Prioritizing Security Updates Based on Risk. Compliance deadline from CISA BOD 26-04.

    CISA BOD 26-04
  • 2026-12-09in 5mo

    Fedora 43: End of Life

    Product lifecycle

    Fedora 43 reaches End of Life on 2026-12-09 (security patches stop). Lifecycle data from endoflife.date.

  • 2026-12-28in 5mo

    Kubernetes 1.35: End of Support

    Product lifecycle

    Kubernetes 1.35 reaches End of Support on 2026-12-28 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2026-12-31in 5mo

    PCI DSS v4.0.1 full assessment year close

    PCI DSSGlobal

    All 51 future-dated PCI DSS v4.x requirements have been effective since 2025-03-31; organizations completing annual QSA assessments in 2026 must demonstrate compliance with the full v4.0.1 requirement set.

  • 2026-12-31in 5mo

    FreeBSD 14.4: End of Life

    Product lifecycle

    FreeBSD 14.4 reaches End of Life on 2026-12-31 (security patches stop). Lifecycle data from endoflife.date.

  • 2027-01-01in 5mo

    Oklahoma consumer data privacy law takes effect

    Oklahoma SB 546US

    Applies to businesses processing personal data of 100,000 or more Oklahoma consumers, or 25,000 or more where a majority of revenue comes from selling data. Grants access, correction, deletion, and opt-out rights, and requires consent before processing sensitive personal data.

  • 2027-01-01in 5mo

    California automated decisionmaking rules, compliance begins

    CCPAUS

    Businesses using automated decisionmaking technology (ADMT) for significant decisions about consumers, such as employment, lending, or housing, must provide pre-use notices, opt-outs, and access rights under the California Consumer Privacy Act (CCPA) regulations adopted in 2025.

  • 2027-01-12in 6mo

    Windows 10-21h2-iot-lts: End of Support

    Product lifecycle

    Windows 10-21h2-iot-lts reaches End of Support on 2027-01-12 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2027-01-12in 6mo

    Windows 10-21h2-e-lts: End of Life

    Product lifecycle

    Windows 10-21h2-e-lts reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.

  • 2027-01-12in 6mo

    Windows 10-21h2-e-lts: End of Support

    Product lifecycle

    Windows 10-21h2-e-lts reaches End of Support on 2027-01-12 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

  • 2027-01-12in 6mo

    Windows Server 2016: End of Life

    Product lifecycle

    Windows Server 2016 reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.

  • 2027-01-12in 6mo

    Microsoft .NET Framework 4.6.2: End of Life

    Product lifecycle

    Microsoft .NET Framework 4.6.2 reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.

  • 2027-01-17in 6mo

    DORA second anniversary and oversight ramp

    DORAEU

    Two years into DORA application (effective 2025-01-17), oversight of critical ICT third-party providers by the European Supervisory Authorities continues to mature; financial entities should have completed threat-led penetration testing cycles.

  • 2027-01-20in 6mo

    EU Machinery Regulation applies

    Machinery RegulationEU

    Regulation (EU) 2023/1230 on machinery products begins to apply, including its cybersecurity and safety requirements for connected and digitally controlled machinery.

  • 2027-03-31in 8mo

    DORA registers of information, annual transmission deadline

    DORAEU

    Financial entities' registers of information on ICT third-party arrangements, reference date 2026-12-31, are transmitted by national competent authorities to the European Supervisory Authorities by 31 March. Entity-level filing deadlines fall earlier in the first quarter and are set nationally.

  • 2027-04-18in 9mo

    Belgium NIS2, essential entities must hold CyFun certification

    NIS2Belgium

    Essential entities on the CyberFundamentals (CyFun) route whose risk assessment lands at assurance level Essential must have obtained CyFun Essential certification from an accredited conformity assessment body, or full ISO/IEC 27001 certification on that pathway, and must report compliance progress to the Centre for Cybersecurity Belgium.

  • 2027-08-02in 12mo

    EU AI Act compliance deadline for legacy GPAI models

    EU AI ActEU

    Providers of general-purpose artificial intelligence (GPAI) models placed on the market before 2025-08-02 must have completed the steps needed to comply with the regulation's GPAI obligations.

  • 2027-11-10in 16mo

    CMMC Phase 3 begins, Level 3 government assessments required

    CMMCUS

    Applicable solicitations add the Level 3 requirement, assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), as a condition of award. Level 2 third-party certification requirements also extend to option-period exercises on previously awarded contracts.

  • 2027-12-02in 16mo

    EU AI Act high-risk obligations apply to stand-alone systems

    EU AI ActEU

    The full high-risk regime (risk management, data governance, technical documentation, human oversight, and conformity assessment) applies to stand-alone high-risk systems under Annex III. Deferred from 2026-08-02 by the 2026 omnibus.

  • 2027-12-11in 17mo

    EU Cyber Resilience Act main obligations apply

    CRAEU

    Secure-by-design requirements, conformity assessment, technical documentation, CE marking, software bill of materials (SBOM), and vulnerability handling obligations take full effect for products with digital elements placed on the EU market.

  • 2028-08-02in 25mo

    EU AI Act high-risk obligations for AI embedded in products

    EU AI ActEU

    High-risk obligations apply to systems that are safety components of, or are themselves, products covered by Annex I harmonisation legislation. Deferred from 2027-08-02 by the 2026 omnibus.

  • 2028-11-10in 28mo

    CMMC Phase 4, full implementation across DoD contracting

    CMMCUS

    CMMC program requirements appear in all applicable Department of Defense solicitations and contracts, including option periods on contracts awarded before Phase 4. This completes the three-year phase-in that began 2025-11-10.

Recent and passed
  • 2026-07-0126d ago

    Arkansas Children and Teens' Online Privacy Protection Act

    Arkansas Act 952US

    State law modeled on the federal Children's Online Privacy Protection Act (COPPA) takes effect, adding consent, data minimization, and operator duties for children's and teens' online data.

  • 2026-07-0126d ago

    Connecticut Data Privacy Act amendments effective

    CTDPAUS

    Public Act 25-113 lowers applicability thresholds so all sensitive data processing and all personal data sales are covered regardless of volume, expands consumer access rights, and strengthens protections for minors.

  • 2026-06-3027d ago

    NIS2 first compliance audit reference date (passed, tracking)

    NIS2EU

    Reference date cited by practitioners for the first NIS2 compliance audit cycle in early-transposing member states, retained for historical context.

  • 2025-11-10259d ago

    CMMC Phase 1 began, self-assessments required in DoD contracts

    CMMCUS

    The Cybersecurity Maturity Model Certification (CMMC) acquisition rule took effect and contracting officers began inserting DFARS clause 252.204-7021 in applicable solicitations. Phase 1 requires Level 1 or Level 2 self-assessments with affirmations in the Supplier Performance Risk System (SPRS) as a condition of award. Kept as the anchor for the phased schedule below.