March 2026 Compliance Calendar - 7 deadlines across PCI-DSS, SOC2, GDPR, NIST, ISO27001, FedRAMP.
Sun
Mon
Tue
Wed
Thu
Fri
Sat
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Printed calendars coming soon
All Deadlines for March 2026
1
Mar
China Cross-Border Data Transfer Certification Rules
Updated national standards governing cross-border data transfers take effect on March 1, 2026. Data processors in China must satisfy at least one compliance pathway: passing CAC security assessment or obtaining personal information protection certification.
2
Mar
SEC Annual 10-K Cybersecurity Disclosure (FY2025)
Large accelerated filers with December 31, 2025 fiscal year-end must file Form 10-K including mandatory cybersecurity disclosures under Item 106 of Regulation S-K. Must include cybersecurity risk management processes, board oversight description, management role in cybersecurity, and whether risks have materially affected the company.
31
Mar
PCI DSS 4.0.1 Full Enforcement
All PCI DSS 4.0.1 requirements become mandatory. Organizations must be fully compliant with all new requirements that were previously best practices.
31
Mar
PCI DSS Quarterly ASV Scan - Q1
Quarterly external vulnerability scan by an Approved Scanning Vendor (ASV) required for PCI DSS compliance.
31
Mar
SOC 2 Quarterly Access Review - Q1
Quarterly user access review for SOC 2 compliance.
31
Mar
GDPR Annual Privacy Notice Review
Annual review and update of privacy notices to ensure they accurately reflect current data processing activities.
31
Mar
NIST Quarterly Vulnerability Scanning Q1
Q1 quarterly vulnerability scanning as recommended by NIST SP 800-53 RA-5.
31
Mar
ISO 27001 Internal Audit
Annual internal audit of the Information Security Management System required under ISO 27001 Clause 9.2.
31
Mar
FedRAMP Quarterly Vulnerability Scan
Q1 quarterly authenticated vulnerability scanning for all FedRAMP systems.
31
Mar
DORA Register of Information Annual Submission
Financial entities must submit their Register of Information (RoI) detailing all contractual arrangements with ICT third-party service providers to their national competent authority by March 31, 2026. Data must reflect status as of December 31, 2025. Submissions must be in xBRL-CSV format.
31
Mar
FedRAMP 20x Phase 2 Pilot Completion
FedRAMP 20x Phase 2 pilot expected to conclude by Q2 FY26 (March 31, 2026). The pilot tests the new cloud-native authorization framework emphasizing machine-readable packages, continuous evidence, and automated monitoring. After this phase, FedRAMP plans to stop accepting new Rev5-based agency authorizations.