CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Compliance

Regulatory and compliance calendar

Upcoming compliance deadlines: regulatory dates added by hand after checking the primary source, and CISA directive deadlines taken from the directives list. Near-term product End of Support and End of Life dates from endoflife.date are an optional layer, off by default so the compliance signal stays clear; use the toggle below to show them. Every row names its source.

Regulatory entries last reviewed against their sources: . Directive and product-lifecycle dates are derived from cisa.gov and endoflife.date at each export.

Next 30 days

  • OpenJDK (Oracle builds) 26: End of LifeMilestone
  • FreeBSD 15.0: End of LifeMilestone
  • Fortinet FortiOS 7.2: End of LifeMilestone
  • Python 3.13: End of SupportMilestone

Upcoming

September 2026

  • in 6 days

    OpenJDK (Oracle builds) 26: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    OpenJDK (Oracle builds) 26 reaches End of Life on 2026-09-18 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 18 days

    FreeBSD 15.0: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    FreeBSD 15.0 reaches End of Life on 2026-09-30 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 18 days

    Fortinet FortiOS 7.2: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Fortinet FortiOS 7.2 reaches End of Life on 2026-09-30 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

October 2026

  • in 19 days

    Python 3.13: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Python 3.13 reaches End of Support on 2026-10-01 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 31 days

    Windows 11 24h2 w: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 11 24h2 w reaches End of Life on 2026-10-13 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 31 days

    Windows 11 24h2 w: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 11 24h2 w reaches End of Support on 2026-10-13 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 31 days

    Windows 10 1607 e lts: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 10 1607 e lts reaches End of Life on 2026-10-13 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 31 days

    Windows Server 2022: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Windows Server 2022 reaches End of Support on 2026-10-13 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 35 days

    NIS2 Directive two-year application milestone

    MilestoneNIS2EU

    Two years after the 2024-10-17 transposition deadline, national supervisory and enforcement regimes for essential and important entities are expected to be fully operational across member states.

    Source: ECSO NIS2 Transposition Tracker

  • in 38 days

    Node.js 24: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Node.js 24 reaches End of Support on 2026-10-20 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 40 days

    OpenSSL 3.4: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    OpenSSL 3.4 reaches End of Life on 2026-10-22 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 45 days

    Kubernetes 1.34: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Kubernetes 1.34 reaches End of Life on 2026-10-27 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 47 days

    Citrix Virtual Apps and Desktops 2503: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Citrix Virtual Apps and Desktops 2503 reaches End of Life on 2026-10-29 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 48 days

    Citrix Virtual Apps and Desktops 2603: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Citrix Virtual Apps and Desktops 2603 reaches End of Support on 2026-10-30 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 49 days

    Python 3.10: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Python 3.10 reaches End of Life on 2026-10-31 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

November 2026

  • in 50 days

    Alpine Linux 3.21: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Alpine Linux 3.21 reaches End of Life on 2026-11-01 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 50 days

    OpenSSL 3.6: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    OpenSSL 3.6 reaches End of Life on 2026-11-01 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 59 days

    CMMC Phase 2 begins, Level 2 third-party certification required

    ObligationCMMCUS

    Defense contractors handling Controlled Unclassified Information (CUI) face the Level 2 certification assessment requirement in applicable solicitations as a condition of contract award. The assessment must be performed by an authorized CMMC Third-Party Assessment Organization (C3PAO), and the Department of Defense may delay the requirement to an option period at its discretion. Contractors without Conditional or Final Level 2 status will be ineligible for affected awards.

    Source: eCFR, 32 CFR 170.3(e)(2), one calendar year after the verified 2025-11-10 Phase 1 start

  • in 59 days

    Windows 11 23h2 e: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 11 23h2 e reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 59 days

    Windows 11 23h2 e: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 11 23h2 e reaches End of Support on 2026-11-10 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 59 days

    .NET 9: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    .NET 9 reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 59 days

    .NET 8: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    .NET 8 reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 61 days

    PostgreSQL 14: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    PostgreSQL 14 reaches End of Life on 2026-11-12 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

December 2026

  • in 81 days

    EU AI Act watermarking obligations for AI-generated content

    ObligationEU AI ActEU

    Providers must have machine-readable marking and transparency solutions for synthetic content in place. The 2026 omnibus set this deadline after cutting the proposed grace period from six months to three.

    Source: European Parliament press release, 2026 AI simplification deal

  • in 86 days

    BOD 26-04: Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance)

    ObligationCISA directiveUS

    Prioritizing Security Updates Based on Risk. Compliance deadline from CISA BOD 26-04.

    Date computed from the directive's issued date; not a date CISA published.

    Source: CISA BOD 26-04

  • in 88 days

    Fedora 43: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Fedora 43 reaches End of Life on 2026-12-09 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 107 days

    Kubernetes 1.35: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Kubernetes 1.35 reaches End of Support on 2026-12-28 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 110 days

    PCI DSS v4.0.1 full assessment year close

    ObligationPCI DSSGlobal

    All 51 future-dated PCI DSS v4.x requirements have been effective since 2025-03-31; organizations completing annual QSA assessments in 2026 must demonstrate compliance with the full v4.0.1 requirement set.

    Source: PCI SSC blog, future-dated requirements guidance

  • in 110 days

    FreeBSD 14.4: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    FreeBSD 14.4 reaches End of Life on 2026-12-31 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

January 2027

  • in 111 days

    Oklahoma consumer data privacy law takes effect

    ObligationOklahoma SB 546US

    Applies to businesses processing personal data of 100,000 or more Oklahoma consumers, or 25,000 or more where a majority of revenue comes from selling data. Grants access, correction, deletion, and opt-out rights, and requires consent before processing sensitive personal data.

    Source: Oklahoma House of Representatives, SB 546 news, signed 2026-03-20

  • in 111 days

    California automated decisionmaking rules, compliance begins

    ObligationCCPAUS

    Businesses using automated decisionmaking technology (ADMT) for significant decisions about consumers, such as employment, lending, or housing, must provide pre-use notices, opt-outs, and access rights under the California Consumer Privacy Act (CCPA) regulations adopted in 2025.

    Source: California Privacy Protection Agency, CCPA updates page

  • in 122 days

    Windows 10 21h2 iot lts: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 10 21h2 iot lts reaches End of Support on 2027-01-12 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 122 days

    Windows 10 21h2 e lts: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 10 21h2 e lts reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 122 days

    Windows 10 21h2 e lts: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Windows 10 21h2 e lts reaches End of Support on 2027-01-12 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 122 days

    Windows Server 2016: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Windows Server 2016 reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 122 days

    Microsoft .NET Framework 4.6.2: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Microsoft .NET Framework 4.6.2 reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 127 days

    DORA second anniversary and oversight ramp

    MilestoneDORAEU

    Two years into DORA application (effective 2025-01-17), oversight of critical ICT third-party providers by the European Supervisory Authorities continues to mature; financial entities should have completed threat-led penetration testing cycles.

    Source: EIOPA, Digital Operational Resilience Act page

  • in 130 days

    EU Machinery Regulation applies

    ObligationMachinery RegulationEU

    Regulation (EU) 2023/1230 on machinery products begins to apply, including its cybersecurity and safety requirements for connected and digitally controlled machinery.

    Source: EU cybersecurity regulatory update for 2026 and beyond, Reed Smith

February 2027

  • in 146 days

    BOD 26-02: Decommission listed EOS edge devices with an EOS date on or before this milestone, report the decommissions, and inventory devices reaching EOS within the next twelve months (within 12 months of issuance)

    ObligationCISA directiveUS

    Mitigating Risk From End-of-Support Edge Devices. Compliance deadline from CISA BOD 26-02.

    Date computed from the directive's issued date; not a date CISA published.

    Source: CISA BOD 26-02

  • in 150 days

    Cisco IOS XE 17.15: End of Support

    MilestoneProduct lifecycleJurisdiction not reported

    Cisco IOS XE 17.15 reaches End of Support on 2027-02-09 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.

    Source: endoflife.date

  • in 169 days

    Kubernetes 1.35: End of Life

    MilestoneProduct lifecycleJurisdiction not reported

    Kubernetes 1.35 reaches End of Life on 2027-02-28 (security patches stop). Lifecycle data from endoflife.date.

    Source: endoflife.date

March 2027

  • in 200 days

    DORA registers of information, annual transmission deadline

    ObligationDORAEU

    Financial entities' registers of information on ICT third-party arrangements, reference date 2026-12-31, are transmitted by national competent authorities to the European Supervisory Authorities by 31 March. Entity-level filing deadlines fall earlier in the first quarter and are set nationally.

    Source: EBA, DORA register of information reporting FAQ (2025-03-28)

April 2027

  • in 218 days

    Belgium NIS2, essential entities must hold CyFun certification

    ObligationNIS2Belgium

    Essential entities on the CyberFundamentals (CyFun) route whose risk assessment lands at assurance level Essential must have obtained CyFun Essential certification from an accredited conformity assessment body, or full ISO/IEC 27001 certification on that pathway, and must report compliance progress to the Centre for Cybersecurity Belgium.

    Source: Centre for Cybersecurity Belgium

August 2027

  • in 324 days

    EU AI Act compliance deadline for legacy GPAI models

    ObligationEU AI ActEU

    Providers of general-purpose artificial intelligence (GPAI) models placed on the market before 2025-08-02 must have completed the steps needed to comply with the regulation's GPAI obligations.

    Source: EUR-Lex, Regulation (EU) 2024/1689, Article 111(3)

  • in 327 days

    BOD 26-02: Decommission all identified EOS edge devices and report the decommissions to CISA (within 18 months of issuance)

    ObligationCISA directiveUS

    Mitigating Risk From End-of-Support Edge Devices. Compliance deadline from CISA BOD 26-02.

    Date computed from the directive's issued date; not a date CISA published.

    Source: CISA BOD 26-02

November 2027

  • in 424 days

    CMMC Phase 3 begins, Level 3 government assessments required

    ObligationCMMCUS

    Applicable solicitations add the Level 3 requirement, assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), as a condition of award. Level 2 third-party certification requirements also extend to option-period exercises on previously awarded contracts.

    Source: eCFR, 32 CFR 170.3(e)(3), one calendar year after Phase 2

December 2027

  • in 446 days

    EU AI Act high-risk obligations apply to stand-alone systems

    ObligationEU AI ActEU

    The full high-risk regime (risk management, data governance, technical documentation, human oversight, and conformity assessment) applies to stand-alone high-risk systems under Annex III. Deferred from 2026-08-02 by the 2026 omnibus.

    Source: Consilium press release, final approval 2026-06-29

  • in 455 days

    EU Cyber Resilience Act main obligations apply

    ObligationCRAEU

    Secure-by-design requirements, conformity assessment, technical documentation, CE marking, software bill of materials (SBOM), and vulnerability handling obligations take full effect for products with digital elements placed on the EU market.

    Source: European Commission, Cyber Resilience Act policy page

February 2028

  • in 511 days

    BOD 26-02: Establish continuous discovery of EOS edge devices and decommission each on or before its EOS date (within 24 months of issuance)

    ObligationCISA directiveUS

    Mitigating Risk From End-of-Support Edge Devices. Compliance deadline from CISA BOD 26-02.

    Date computed from the directive's issued date; not a date CISA published.

    Source: CISA BOD 26-02

August 2028

  • in 690 days

    EU AI Act high-risk obligations for AI embedded in products

    ObligationEU AI ActEU

    High-risk obligations apply to systems that are safety components of, or are themselves, products covered by Annex I harmonisation legislation. Deferred from 2027-08-02 by the 2026 omnibus.

    Source: Consilium press release, final approval 2026-06-29

November 2028

  • in 790 days

    CMMC Phase 4, full implementation across DoD contracting

    ObligationCMMCUS

    CMMC program requirements appear in all applicable Department of Defense solicitations and contracts, including option periods on contracts awarded before Phase 4. This completes the three-year phase-in that began 2025-11-10.

    Source: eCFR, 32 CFR 170.3(e)(4), one calendar year after Phase 3

Recent and passed

  • 1 day ago

    EU Cyber Resilience Act reporting obligations apply

    ObligationCRAEU

    Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform (early warning within 24 hours, full notification within 72 hours). Main obligations follow on 2027-12-11.

    Source: European Commission, Cyber Resilience Act reporting page

  • 41 days ago

    EU AI Act general application date

    ObligationEU AI ActEU

    The baseline application date of Regulation (EU) 2024/1689. After the 2026 simplification omnibus, obligations for high-risk systems do not start on this date; they were deferred to 2027-12-02 and 2028-08-02. The remaining framework, including transparency and governance provisions, becomes applicable.

    Source: EUR-Lex, Regulation (EU) 2024/1689, Article 113, and the Consilium AI Act timeline

  • 73 days ago

    Arkansas Children and Teens' Online Privacy Protection Act

    ObligationArkansas Act 952US

    State law modeled on the federal Children's Online Privacy Protection Act (COPPA) takes effect, adding consent, data minimization, and operator duties for children's and teens' online data.

    Source: Arkansas General Assembly, Act 952 of 2025 (HB 1717)

  • 73 days ago

    Connecticut Data Privacy Act amendments effective

    ObligationCTDPAUS

    Public Act 25-113 lowers applicability thresholds so all sensitive data processing and all personal data sales are covered regardless of volume, expands consumer access rights, and strengthens protections for minors.

    Source: Connecticut General Assembly, Public Act No. 25-113

  • 74 days ago

    NIS2 first compliance audit reference date (passed, tracking)

    MilestoneNIS2EU

    Reference date cited by practitioners for the first NIS2 compliance audit cycle in early-transposing member states, retained for historical context.

    Source: AIGovHub, NIS2 and DORA 2026 compliance guide

  • 306 days ago

    CMMC Phase 1 began, self-assessments required in DoD contracts

    ObligationCMMCUS

    The Cybersecurity Maturity Model Certification (CMMC) acquisition rule took effect and contracting officers began inserting DFARS clause 252.204-7021 in applicable solicitations. Phase 1 requires Level 1 or Level 2 self-assessments with affirmations in the Supplier Performance Risk System (SPRS) as a condition of award. Kept as the anchor for the phased schedule below.

    Source: Federal Register, DFARS Case 2019-D041 final rule, effective 2025-11-10, and DoD CIO CMMC

Glossary