Calendar View
June 2026
Upcoming Deadlines
View all deadlines →SEC Regulation S-P - Smaller Entity Compliance
SEC CyberSmaller financial institutions must comply with amendments to SEC Regulation S-P. Requirements include: written policies for detecting, responding to, and recovering from unauthorized access; customer notification within 30 days of breach discovery; service provider oversight with 72-hour breach notification clauses; incident response program; and enhanced recordkeeping.
EU CRA - Conformity Assessment Body Designation
EU CRARules on notifying and appointing conformity assessment bodies become applicable to EU Member States. Member States must have notified bodies in place to assess products with digital elements for cybersecurity compliance.
UK DUAA - Complaint Response Requirements
GDPRNew right to complain comes into force under the UK DUAA. Controllers must acknowledge complaints within 30 days and provide full response without undue delay. This formalizes complaint handling procedures under UK data protection law for the first time.
PCI DSS Quarterly ASV Scan - Q2
PCI DSSQ2 quarterly external vulnerability scan by an Approved Scanning Vendor.
HIPAA Business Associate Agreement Review
HIPAAAnnual review of Business Associate Agreements to ensure all vendors handling PHI have current BAAs in place.
SOC 2 Quarterly Access Review - Q2
SOC 2Q2 quarterly user access review for SOC 2 compliance.
GDPR Annual DPA Review
GDPRAnnual review of Data Processing Agreements with all third-party processors.
GDPR Records of Processing Review
GDPRSemi-annual review of Records of Processing Activities (ROPA) required under Article 30 GDPR.
NIST Quarterly Vulnerability Scanning Q2
NIST CSFQ2 quarterly vulnerability scanning per NIST SP 800-53 RA-5.
ISO 27001 Surveillance Audit
ISO 27001Annual surveillance audit by certification body to maintain ISO 27001 certification.
CCPA Consumer Request Process Review
CCPA/CPRASemi-annual review of consumer request handling processes for CCPA compliance.
Cyber Insurance Renewal Preparation
NIST CSFPrepare for annual cyber insurance renewal. Insurers increasingly require evidence of compliance frameworks, MFA, EDR, and incident response plans.
Business Continuity Plan Review
ISO 27001Annual review and testing of Business Continuity Plan including disaster recovery procedures.
NIS2 First Compliance Audit Deadline
NIS2 DirectiveThe deadline for companies to complete their first audit verifying NIS2 compliance was extended from December 31, 2025, to June 30, 2026. Organizations must demonstrate implementation of cybersecurity risk management measures, incident response capabilities, and supply chain security.
EDPB 2026 Coordinated Enforcement - Transparency
GDPRThe European Data Protection Board's 2026 coordinated enforcement action focuses on transparency and information obligations under GDPR Articles 12-14. Data protection authorities across EU member states will conduct investigations and potentially issue enforcement actions focused on how organizations explain their data collection, use, and sharing practices.
Colorado AI Anti-Discrimination Law Takes Effect
EU AI ActColorado SB24-205 Consumer Protections for AI takes effect (delayed from February 1, 2026). Developers must exercise reasonable care to prevent algorithmic discrimination, publish documentation on high-risk AI systems, and disclose known discrimination risks. Deployers must adopt risk management policies, conduct initial and annual impact assessments, and provide pre-decision and adverse-decision consumer notices.
Netherlands NIS2 Implementation Expected
NIS2 DirectiveThe Netherlands' cybersecurity bill implementing NIS2 is expected to enter into force in Q2 2026. Essential and important entities will need to register, implement risk management measures, and establish incident reporting procedures.
DORA ICT Risk Management Framework Review
DORAFinancial entities must review and update their ICT risk management frameworks at least annually. The 2026 mid-year review cycle is a critical checkpoint for demonstrating ongoing compliance. Entities must maintain and update ICT risk policies, business continuity plans, ICT incident management procedures, and digital operational resilience testing programs.
Connecticut Data Privacy Act Amendments - Expanded Scope
State PrivacySignificant amendments to Connecticut's Data Privacy Act take effect. Applicability threshold lowered from 100,000 to 35,000 consumers. Sensitive data definition expanded to include neural data, disability-related treatment, nonbinary status, financial account information, and government-issued ID data. New prohibition on sale of sensitive data without consent.
Utah Digital Choice Act - Data Portability Requirements
State PrivacyUtah's Digital Choice Act takes effect, requiring social media companies to implement data portability and interoperability tools. This is the first US state law explicitly requiring social media platforms to build tools allowing users to transfer personal data (friends, connections, photos, likes, social graph) to other services.
HIPAA Security Rule Modernization - Final Rule
HIPAAThe HIPAA Security Rule modernization is scheduled to be finalized around May 2026, with the rule likely effective July/August 2026. Major changes: elimination of addressable vs required distinction (all become required), mandatory MFA, mandatory encryption, 12-month risk assessment cycle, 24-hour business associate breach notification, and enhanced workforce training requirements.