Regulatory and compliance calendar
Upcoming compliance deadlines: regulatory dates added by hand after checking the primary source, and CISA directive deadlines taken from the directives list. Near-term product End of Support and End of Life dates from endoflife.date are an optional layer, off by default so the compliance signal stays clear; use the toggle below to show them. Every row names its source.
Regulatory entries last reviewed against their sources: . Directive and product-lifecycle dates are derived from cisa.gov and endoflife.date at each export.
Upcoming
September 2026
in 6 days
OpenJDK (Oracle builds) 26: End of Life
OpenJDK (Oracle builds) 26 reaches End of Life on 2026-09-18 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 18 days
FreeBSD 15.0: End of Life
FreeBSD 15.0 reaches End of Life on 2026-09-30 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 18 days
Fortinet FortiOS 7.2: End of Life
Fortinet FortiOS 7.2 reaches End of Life on 2026-09-30 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
October 2026
in 19 days
Python 3.13: End of Support
Python 3.13 reaches End of Support on 2026-10-01 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 31 days
Windows 11 24h2 w: End of Life
Windows 11 24h2 w reaches End of Life on 2026-10-13 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 31 days
Windows 11 24h2 w: End of Support
Windows 11 24h2 w reaches End of Support on 2026-10-13 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 31 days
Windows 10 1607 e lts: End of Life
Windows 10 1607 e lts reaches End of Life on 2026-10-13 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 31 days
Windows Server 2022: End of Support
Windows Server 2022 reaches End of Support on 2026-10-13 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 35 days
NIS2 Directive two-year application milestone
Two years after the 2024-10-17 transposition deadline, national supervisory and enforcement regimes for essential and important entities are expected to be fully operational across member states.
Source: ECSO NIS2 Transposition Tracker
in 38 days
Node.js 24: End of Support
Node.js 24 reaches End of Support on 2026-10-20 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 40 days
OpenSSL 3.4: End of Life
OpenSSL 3.4 reaches End of Life on 2026-10-22 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 45 days
Kubernetes 1.34: End of Life
Kubernetes 1.34 reaches End of Life on 2026-10-27 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 47 days
Citrix Virtual Apps and Desktops 2503: End of Life
Citrix Virtual Apps and Desktops 2503 reaches End of Life on 2026-10-29 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 48 days
Citrix Virtual Apps and Desktops 2603: End of Support
Citrix Virtual Apps and Desktops 2603 reaches End of Support on 2026-10-30 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 49 days
Python 3.10: End of Life
Python 3.10 reaches End of Life on 2026-10-31 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
November 2026
in 50 days
Alpine Linux 3.21: End of Life
Alpine Linux 3.21 reaches End of Life on 2026-11-01 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 50 days
OpenSSL 3.6: End of Life
OpenSSL 3.6 reaches End of Life on 2026-11-01 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 59 days
CMMC Phase 2 begins, Level 2 third-party certification required
Defense contractors handling Controlled Unclassified Information (CUI) face the Level 2 certification assessment requirement in applicable solicitations as a condition of contract award. The assessment must be performed by an authorized CMMC Third-Party Assessment Organization (C3PAO), and the Department of Defense may delay the requirement to an option period at its discretion. Contractors without Conditional or Final Level 2 status will be ineligible for affected awards.
Source: eCFR, 32 CFR 170.3(e)(2), one calendar year after the verified 2025-11-10 Phase 1 start
in 59 days
Windows 11 23h2 e: End of Life
Windows 11 23h2 e reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 59 days
Windows 11 23h2 e: End of Support
Windows 11 23h2 e reaches End of Support on 2026-11-10 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 59 days
.NET 9: End of Life
.NET 9 reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 59 days
.NET 8: End of Life
.NET 8 reaches End of Life on 2026-11-10 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 61 days
PostgreSQL 14: End of Life
PostgreSQL 14 reaches End of Life on 2026-11-12 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
December 2026
in 81 days
EU AI Act watermarking obligations for AI-generated content
Providers must have machine-readable marking and transparency solutions for synthetic content in place. The 2026 omnibus set this deadline after cutting the proposed grace period from six months to three.
Source: European Parliament press release, 2026 AI simplification deal
in 86 days
BOD 26-04: Meet the full BOD 26-04 remediation timelines in Table 1 (within 180 days of issuance)
Prioritizing Security Updates Based on Risk. Compliance deadline from CISA BOD 26-04.
Date computed from the directive's issued date; not a date CISA published.
Source: CISA BOD 26-04
in 88 days
Fedora 43: End of Life
Fedora 43 reaches End of Life on 2026-12-09 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 107 days
Kubernetes 1.35: End of Support
Kubernetes 1.35 reaches End of Support on 2026-12-28 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 110 days
PCI DSS v4.0.1 full assessment year close
All 51 future-dated PCI DSS v4.x requirements have been effective since 2025-03-31; organizations completing annual QSA assessments in 2026 must demonstrate compliance with the full v4.0.1 requirement set.
in 110 days
FreeBSD 14.4: End of Life
FreeBSD 14.4 reaches End of Life on 2026-12-31 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
January 2027
in 111 days
Oklahoma consumer data privacy law takes effect
Applies to businesses processing personal data of 100,000 or more Oklahoma consumers, or 25,000 or more where a majority of revenue comes from selling data. Grants access, correction, deletion, and opt-out rights, and requires consent before processing sensitive personal data.
Source: Oklahoma House of Representatives, SB 546 news, signed 2026-03-20
in 111 days
California automated decisionmaking rules, compliance begins
Businesses using automated decisionmaking technology (ADMT) for significant decisions about consumers, such as employment, lending, or housing, must provide pre-use notices, opt-outs, and access rights under the California Consumer Privacy Act (CCPA) regulations adopted in 2025.
Source: California Privacy Protection Agency, CCPA updates page
in 122 days
Windows 10 21h2 iot lts: End of Support
Windows 10 21h2 iot lts reaches End of Support on 2027-01-12 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 122 days
Windows 10 21h2 e lts: End of Life
Windows 10 21h2 e lts reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 122 days
Windows 10 21h2 e lts: End of Support
Windows 10 21h2 e lts reaches End of Support on 2027-01-12 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 122 days
Windows Server 2016: End of Life
Windows Server 2016 reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 122 days
Microsoft .NET Framework 4.6.2: End of Life
Microsoft .NET Framework 4.6.2 reaches End of Life on 2027-01-12 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
in 127 days
DORA second anniversary and oversight ramp
Two years into DORA application (effective 2025-01-17), oversight of critical ICT third-party providers by the European Supervisory Authorities continues to mature; financial entities should have completed threat-led penetration testing cycles.
in 130 days
EU Machinery Regulation applies
Regulation (EU) 2023/1230 on machinery products begins to apply, including its cybersecurity and safety requirements for connected and digitally controlled machinery.
Source: EU cybersecurity regulatory update for 2026 and beyond, Reed Smith
February 2027
in 146 days
BOD 26-02: Decommission listed EOS edge devices with an EOS date on or before this milestone, report the decommissions, and inventory devices reaching EOS within the next twelve months (within 12 months of issuance)
Mitigating Risk From End-of-Support Edge Devices. Compliance deadline from CISA BOD 26-02.
Date computed from the directive's issued date; not a date CISA published.
Source: CISA BOD 26-02
in 150 days
Cisco IOS XE 17.15: End of Support
Cisco IOS XE 17.15 reaches End of Support on 2027-02-09 (active support ends, though security patches usually continue). Lifecycle data from endoflife.date.
Source: endoflife.date
in 169 days
Kubernetes 1.35: End of Life
Kubernetes 1.35 reaches End of Life on 2027-02-28 (security patches stop). Lifecycle data from endoflife.date.
Source: endoflife.date
March 2027
in 200 days
DORA registers of information, annual transmission deadline
Financial entities' registers of information on ICT third-party arrangements, reference date 2026-12-31, are transmitted by national competent authorities to the European Supervisory Authorities by 31 March. Entity-level filing deadlines fall earlier in the first quarter and are set nationally.
Source: EBA, DORA register of information reporting FAQ (2025-03-28)
April 2027
in 218 days
Belgium NIS2, essential entities must hold CyFun certification
Essential entities on the CyberFundamentals (CyFun) route whose risk assessment lands at assurance level Essential must have obtained CyFun Essential certification from an accredited conformity assessment body, or full ISO/IEC 27001 certification on that pathway, and must report compliance progress to the Centre for Cybersecurity Belgium.
Source: Centre for Cybersecurity Belgium
August 2027
in 324 days
EU AI Act compliance deadline for legacy GPAI models
Providers of general-purpose artificial intelligence (GPAI) models placed on the market before 2025-08-02 must have completed the steps needed to comply with the regulation's GPAI obligations.
in 327 days
BOD 26-02: Decommission all identified EOS edge devices and report the decommissions to CISA (within 18 months of issuance)
Mitigating Risk From End-of-Support Edge Devices. Compliance deadline from CISA BOD 26-02.
Date computed from the directive's issued date; not a date CISA published.
Source: CISA BOD 26-02
November 2027
in 424 days
CMMC Phase 3 begins, Level 3 government assessments required
Applicable solicitations add the Level 3 requirement, assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), as a condition of award. Level 2 third-party certification requirements also extend to option-period exercises on previously awarded contracts.
Source: eCFR, 32 CFR 170.3(e)(3), one calendar year after Phase 2
December 2027
in 446 days
EU AI Act high-risk obligations apply to stand-alone systems
The full high-risk regime (risk management, data governance, technical documentation, human oversight, and conformity assessment) applies to stand-alone high-risk systems under Annex III. Deferred from 2026-08-02 by the 2026 omnibus.
in 455 days
EU Cyber Resilience Act main obligations apply
Secure-by-design requirements, conformity assessment, technical documentation, CE marking, software bill of materials (SBOM), and vulnerability handling obligations take full effect for products with digital elements placed on the EU market.
Source: European Commission, Cyber Resilience Act policy page
February 2028
in 511 days
BOD 26-02: Establish continuous discovery of EOS edge devices and decommission each on or before its EOS date (within 24 months of issuance)
Mitigating Risk From End-of-Support Edge Devices. Compliance deadline from CISA BOD 26-02.
Date computed from the directive's issued date; not a date CISA published.
Source: CISA BOD 26-02
August 2028
in 690 days
EU AI Act high-risk obligations for AI embedded in products
High-risk obligations apply to systems that are safety components of, or are themselves, products covered by Annex I harmonisation legislation. Deferred from 2027-08-02 by the 2026 omnibus.
November 2028
in 790 days
CMMC Phase 4, full implementation across DoD contracting
CMMC program requirements appear in all applicable Department of Defense solicitations and contracts, including option periods on contracts awarded before Phase 4. This completes the three-year phase-in that began 2025-11-10.
Source: eCFR, 32 CFR 170.3(e)(4), one calendar year after Phase 3
Recent and passed
1 day ago
EU Cyber Resilience Act reporting obligations apply
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform (early warning within 24 hours, full notification within 72 hours). Main obligations follow on 2027-12-11.
Source: European Commission, Cyber Resilience Act reporting page
41 days ago
EU AI Act general application date
The baseline application date of Regulation (EU) 2024/1689. After the 2026 simplification omnibus, obligations for high-risk systems do not start on this date; they were deferred to 2027-12-02 and 2028-08-02. The remaining framework, including transparency and governance provisions, becomes applicable.
Source: EUR-Lex, Regulation (EU) 2024/1689, Article 113, and the Consilium AI Act timeline
73 days ago
Arkansas Children and Teens' Online Privacy Protection Act
State law modeled on the federal Children's Online Privacy Protection Act (COPPA) takes effect, adding consent, data minimization, and operator duties for children's and teens' online data.
Source: Arkansas General Assembly, Act 952 of 2025 (HB 1717)
73 days ago
Connecticut Data Privacy Act amendments effective
Public Act 25-113 lowers applicability thresholds so all sensitive data processing and all personal data sales are covered regardless of volume, expands consumer access rights, and strengthens protections for minors.
74 days ago
NIS2 first compliance audit reference date (passed, tracking)
Reference date cited by practitioners for the first NIS2 compliance audit cycle in early-transposing member states, retained for historical context.
306 days ago
CMMC Phase 1 began, self-assessments required in DoD contracts
The Cybersecurity Maturity Model Certification (CMMC) acquisition rule took effect and contracting officers began inserting DFARS clause 252.204-7021 in applicable solicitations. Phase 1 requires Level 1 or Level 2 self-assessments with affirmations in the Supplier Performance Risk System (SPRS) as a condition of award. Kept as the anchor for the phased schedule below.
Source: Federal Register, DFARS Case 2019-D041 final rule, effective 2025-11-10, and DoD CIO CMMC