Skip to main content
ControlFrame
Regulatory change tracker

Every dated change across the framework registry, in one list.

A version superseded, a coexistence window closing, an enforcement date arriving, a draft the authority has signalled but not yet dated — every entry below is generated from the same 84-regime registry that powers the framework library, not a separately maintained list. Each row names what changed, who it affects, and links the primary source directly.

Subscribe via RSS

01Timeline

generated 2026-08-30
Framework family
When
65 dated events · 22 signalled, undated
  1. AheadOtherPermalink

    NERC CIP — NERC CIP: Effective dates are staggered per standard: CIP-003-9 took effect 2026-04-01, CIP-012-2 took effect 2026-07-01, and CIP-015-1 (internal network security monitoring, FERC-approved 2025-06-26) requires high- and medium-impact BES Cyber Systems with external routable connectivity to comply by 2028-10-01, with all other in-scope systems following by 2030-10-01.

    Teams in electric utilities should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    NERC Reliability Standards — CIP (opens in a new tab)
  2. AheadSecurityPermalink

    EU Cyber Resilience Act — EU Cyber Resilience Act: Phased. Notification-body provisions applied from 2026-06-11 and actively-exploited-vulnerability reporting from 2026-09-11. The main manufacturer obligations, CE marking, and SBOM requirements apply from 2027-12-11.

    Teams in hardware, software, IoT should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    European Commission — Cyber Resilience Act (opens in a new tab)
  3. AheadAIPermalink

    EU AI Act — EU AI Act: Regulation (EU) 2026/1744 (the 'Digital Omnibus on AI'), adopted 2026-07-08 and published in the OJ 2026-07-24, entered into force 2026-07-27, amending Regulation (EU) 2024/1689 (confirmed directly against the regulation's own EUR-Lex text). It defers Annex III high-risk obligations (Article 6(2) systems) to 2027-12-02 and Annex I embedded-product obligations (Article 6(1) systems) to 2028-08-02. Article 50 transparency duties began applying 2026-08-02, with a four-month transitional allowance for systems already placed on the market before that date. Treat the Omnibus as amending legislation, not a replacement framework.

    Teams in AI, technology, regulated industries should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    European Commission — AI Act (opens in a new tab)
  4. AheadGovernmentPermalink

    CJIS Security Policy — CJIS Security Policy: the coexistence window for 6.1 — Priority 2 through 4 modernized requirements (zero-cycle) (applying to Every agency and vendor covered by v6.1 — findings on these lower-priority requirements are recorded but not sanctioned during the zero-cycle) is scheduled to close.

    Every agency and vendor covered by v6.1 — findings on these lower-priority requirements are recorded but not sanctioned during the zero-cycle should move to 6.1 on or before this date; after it, 6.1 — Priority 2 through 4 modernized requirements (zero-cycle) is no longer a recognized alternative under CJIS Security Policy.

    FBI Criminal Justice Information Services (opens in a new tab)
  5. AheadGovernmentPermalink

    CJIS Security Policy — CJIS Security Policy: The FBI frames the transition not by version number but by a zero-cycle running 2024-10-01 to 2027-09-30 for lower-priority modernized requirements (Priority 2 through 4): findings are recorded but not yet sanctionable. Priority 1 controls have been sanctionable since 2024-10-01. A state's own audit program may still cite an older baseline against its own timeline (for example, Texas DPS audits have historically referenced v5.9.5) — that is a state-sourced fact, not an FBI one, and should be verified per state before quoting an enforced version.

    Teams in law enforcement, public safety, government should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    FBI Criminal Justice Information Services (opens in a new tab)
  6. AheadGovernmentPermalink

    FedRAMP (Rev. 5 baselines) — FedRAMP (Rev. 5 baselines): FedRAMP 20x is the forward program path, while Rev. 5 remains available during transition. FedRAMP Ready submissions under Rev. 5 stopped being accepted 2026-07-28. FedRAMP will stop accepting applications for new Rev. 5 Certifications on 2027-06-11. Existing Rev. 5 authorizations remain valid through at least 2028-12-31; FedRAMP has not stated a final retirement date for all of them.

    Teams in federal cloud should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    FedRAMP (opens in a new tab)
  7. AheadPrivacyPermalink

    GDPR — GDPR: Regulation (EU) 2025/2518, adopted 2025-11-26 and published 2025-12-12, lays down additional procedural rules for cross-border GDPR enforcement; its main chapters apply 15 months after entry into force (2027-04-02). Confirmed directly against the regulation's own EUR-Lex text. Separately, the Commission's Digital Omnibus (Data track), proposed 2025-11-19, would amend Art. 5(1)(b), add a new Art. 33a single-entry-point breach notification, and add Art. 88a — it remains under Council/Parliament negotiation and is not enacted law at this check.

    Teams in all sectors should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    European Commission — EU data-protection legal framework (opens in a new tab)
  8. AheadAIPermalink

    Colorado AI Act — Colorado AI Act: SB 26-189 (signed 2026-05-14) repeals and reenacts SB 24-205 rather than amending it: the risk management programme, the annual impact assessment, and the duty of reasonable care against algorithmic discrimination are all gone, replaced by notice and disclosure duties on automated decision-making technology. It takes effect 2027-01-01 and leaves implementation detail to AG rulemaking. Nothing is in force today. Do not describe Colorado as a high-risk-AI regime.

    Teams in AI, employment, lending should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    Colorado General Assembly — SB 26-189 (opens in a new tab)
  9. AheadGovernmentPermalink

    FedRAMP 20x — FedRAMP 20x: CR26 took effect 2026-07-04 (optional) and becomes mandatory 2027-01-01. The Class A application pipeline opened 2026-08-03. Class B and C application pipelines opened 2026-08-31. Class D has not yet opened (targeted FY27 Q1-Q2).

    Teams in federal cloud should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    FedRAMP 20x (opens in a new tab)
  10. AheadSecurityPermalink

    TISAX — TISAX: ENX has published ISA2027, which becomes the basis for TISAX assessments ordered from 2027-01-01. Assessments ordered before then may remain on ISA 6, and March 2027 is the final date to open an initial ISA 6 assessment.

    Teams in automotive, manufacturing, supply chain should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    ENX Association (opens in a new tab)
  11. AheadFinancialPermalink

    Sarbanes-Oxley ICFR — Sarbanes-Oxley ICFR: PCAOB and SEC-approved amendments to AS 2201 paragraph .09 and new paragraph .99 become effective on 2026-12-15. They affect the auditor standard, not the statutory text of SOX.

    Teams in public companies, financial reporting, audit firms should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    U.S. Securities and Exchange Commission — Release 33-8238 (opens in a new tab)
  12. AheadSecurityPermalink

    PCI Contactless Payments on COTS (CPoC) — PCI Contactless Payments on COTS (CPoC): the coexistence window for PCI MPoC v1.1 (designated successor) (applying to New solutions and any CPoC solution being migrated ahead of the sunset) is scheduled to close.

    New solutions and any CPoC solution being migrated ahead of the sunset should move to v1.0 on or before this date; after it, PCI MPoC v1.1 (designated successor) is no longer a recognized alternative under PCI Contactless Payments on COTS (CPoC).

    PCI Security Standards Council — CPoC (opens in a new tab)
  13. AheadSecurityPermalink

    PCI Contactless Payments on COTS (CPoC) — PCI Contactless Payments on COTS (CPoC): PCI SSC announced the formal sunset period for CPoC from 2026-05-01 to 2026-10-31, the same window as SPoC. PCI MPoC v1.1 is the standard's designated successor.

    Teams in payments, mobile point-of-sale should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    PCI Security Standards Council — CPoC (opens in a new tab)
  14. AheadSecurityPermalink

    PCI Mobile Payments on COTS (MPoC) — PCI Mobile Payments on COTS (MPoC): MPoC is the designated successor absorbing PCI SPoC and CPoC, which are both in their formal sunset window (2026-05-01 to 2026-10-31).

    Teams in payments, mobile point-of-sale should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    PCI Security Standards Council — MPoC (opens in a new tab)
  15. AheadSecurityPermalink

    PCI Software-based PIN Entry on COTS (SPoC) — PCI Software-based PIN Entry on COTS (SPoC): the coexistence window for PCI MPoC v1.1 (designated successor) (applying to New solutions and any SPoC solution being migrated ahead of the sunset) is scheduled to close.

    New solutions and any SPoC solution being migrated ahead of the sunset should move to v1.1 on or before this date; after it, PCI MPoC v1.1 (designated successor) is no longer a recognized alternative under PCI Software-based PIN Entry on COTS (SPoC).

    PCI Security Standards Council — SPoC (opens in a new tab)
  16. AheadSecurityPermalink

    PCI Software-based PIN Entry on COTS (SPoC) — PCI Software-based PIN Entry on COTS (SPoC): PCI SSC announced the formal sunset period for SPoC from 2026-05-01 to 2026-10-31. PCI MPoC v1.1 is the standard's designated successor for organizations moving off SPoC.

    Teams in payments, mobile point-of-sale should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    PCI Security Standards Council — SPoC (opens in a new tab)
  17. AheadAIPermalink

    AIUC-1 — AIUC-1: AIUC states that it updates the standard quarterly; the next scheduled release is 2026-10-15.

    Teams in AI, technology, SaaS should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    AIUC-1 (opens in a new tab)
  18. AheadGovernmentPermalink

    GAO FISCAM — GAO FISCAM: The June 2026 revision is already effective for fiscal-year and calendar-year 2026 federal financial statement audits; it becomes effective for attestation and performance-audit engagements beginning on or after 2026-10-01.

    Teams in federal, government audit, public sector should track this date against their own assessment or renewal calendar; the authority has signalled the change but has not yet made it effective.

    US Government Accountability Office and CIGIE (opens in a new tab)
  19. Already happenedAIPermalink

    OWASP GenAI LLM Top 10 — OWASP GenAI LLM Top 10 2026 supersedes 2025 and is the current edition.

    Teams in AI, technology, SaaS under OWASP GenAI LLM Top 10 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2026.

    OWASP GenAI Security Project (opens in a new tab)
  20. Already happenedSecurityPermalink

    ISO/IEC 27017 — ISO/IEC 27017 2026 supersedes 2015 and is the current edition.

    Teams in cloud services, SaaS, technology under ISO/IEC 27017 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2026.

    ISO/IEC 27017:2026 (opens in a new tab)
  21. Already happenedAIPermalink

    AIUC-1 — AIUC-1 Q3 2026 (2026-07-15 release) supersedes Q2 2026 (2026-04-15 release) and is the current edition.

    Teams in AI, technology, SaaS under AIUC-1 should confirm which edition their engagement, contract, or assessment cycle requires before relying on Q3 2026 (2026-07-15 release).

    AIUC-1 (opens in a new tab)
  22. Already happenedGovernmentPermalink

    CMS Acceptable Risk Safeguards — CMS Acceptable Risk Safeguards ARS 5.2 supersedes ARS 5.1 and is the current edition.

    Teams in federal healthcare, CMS contractors under CMS Acceptable Risk Safeguards should confirm which edition their engagement, contract, or assessment cycle requires before relying on ARS 5.2.

    CMS Information Security and Privacy Program (opens in a new tab)
  23. Already happenedGovernmentPermalink

    GAO FISCAM — GAO FISCAM June 2026 (GAO-26-108633) supersedes September 2024 (GAO-24-107026) and is the current edition.

    Teams in federal, government audit, public sector under GAO FISCAM should confirm which edition their engagement, contract, or assessment cycle requires before relying on June 2026 (GAO-26-108633).

    US Government Accountability Office and CIGIE (opens in a new tab)
  24. Already happenedGovernmentPermalink

    CJIS Security Policy — CJIS Security Policy 6.1 supersedes 6.0 and is the current edition.

    Teams in law enforcement, public safety, government under CJIS Security Policy should confirm which edition their engagement, contract, or assessment cycle requires before relying on 6.1.

    FBI Criminal Justice Information Services (opens in a new tab)
  25. Already happenedAIPermalink

    CSA AI Controls Matrix — CSA AI Controls Matrix v1.1 supersedes v1.0 and is the current edition.

    Teams in AI, cloud services, SaaS under CSA AI Controls Matrix should confirm which edition their engagement, contract, or assessment cycle requires before relying on v1.1.

    Cloud Security Alliance (opens in a new tab)
  26. Already happenedAIPermalink

    Colorado AI Act — Colorado AI Act SB 26-189 supersedes SB 24-205 (as enacted 2024) and is the current edition.

    Teams in AI, employment, lending under Colorado AI Act should confirm which edition their engagement, contract, or assessment cycle requires before relying on SB 26-189.

    Colorado General Assembly — SB 26-189 (opens in a new tab)
  27. Already happenedGovernmentPermalink

    NIST SP 800-172 — NIST SP 800-172 Rev. 3 supersedes 2021 and is the current edition.

    Teams in defense industrial base, federal contractors, critical programs under NIST SP 800-172 should confirm which edition their engagement, contract, or assessment cycle requires before relying on Rev. 3.

    National Institute of Standards and Technology (opens in a new tab)
  28. Already happenedSecurityPermalink

    HITRUST CSF — HITRUST CSF v11.8.0 supersedes v11.7.0 and is the current edition.

    Teams in healthcare, technology, financial services under HITRUST CSF should confirm which edition their engagement, contract, or assessment cycle requires before relying on v11.8.0.

    HITRUST Alliance (opens in a new tab)
  29. Already happenedFinancialPermalink

    APRA CPS 230 — APRA CPS 230 2026 determination (effective 2026-07-01) supersedes 2023 determination (effective 2025-07-01) and is the current edition.

    Teams in banking, insurance, superannuation under APRA CPS 230 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2026 determination (effective 2026-07-01).

    Australian Prudential Regulation Authority (opens in a new tab)
  30. Already happenedOtherPermalink

    OSCAL — OSCAL 1.2.2 supersedes 1.2.0 and is the current edition.

    Teams in all sectors under OSCAL should confirm which edition their engagement, contract, or assessment cycle requires before relying on 1.2.2.

    NIST OSCAL (opens in a new tab)
  31. Already happenedSecurityPermalink

    UK Cyber Essentials — UK Cyber Essentials Requirements for IT infrastructure v3.3 supersedes Requirements for IT infrastructure v3.2 and is the current edition.

    Teams in all sectors, government suppliers, small and medium businesses under UK Cyber Essentials should confirm which edition their engagement, contract, or assessment cycle requires before relying on Requirements for IT infrastructure v3.3.

    UK National Cyber Security Centre (opens in a new tab)
  32. Already happenedGovernmentPermalink

    CMS Enhanced Direct Enrollment — CMS Enhanced Direct Enrollment Year 9 (PY 2026–PY 2027) supersedes Year 8 and is the current edition.

    Teams in healthcare, insurance under CMS Enhanced Direct Enrollment should confirm which edition their engagement, contract, or assessment cycle requires before relying on Year 9 (PY 2026–PY 2027).

    CMS — Direct Enrollment Partners (opens in a new tab)
  33. Already happenedPrivacyPermalink

    UK GDPR — UK GDPR UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82) supersedes UK GDPR + DPA 2018 and is the current edition.

    Teams in all sectors under UK GDPR should confirm which edition their engagement, contract, or assessment cycle requires before relying on UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82).

    UK Information Commissioner's Office (opens in a new tab)
  34. Already happenedSecurityPermalink

    CSA CCM and CAIQ — CSA CCM and CAIQ v4.1 supersedes v4.0 and is the current edition.

    Teams in cloud services, SaaS, technology under CSA CCM and CAIQ should confirm which edition their engagement, contract, or assessment cycle requires before relying on v4.1.

    Cloud Security Alliance (opens in a new tab)
  35. Already happenedPrivacyPermalink

    ISO/IEC 27701 — ISO/IEC 27701 2025 supersedes 2019 and is the current edition.

    Teams in all sectors under ISO/IEC 27701 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2025.

    ISO/IEC 27701:2025 (opens in a new tab)
  36. Already happenedPrivacyPermalink

    CCPA/CPRA + US state privacy — CCPA/CPRA + US state privacy CCPA/CPRA with 2026 CPPA regulations supersedes CCPA/CPRA (2020 regulations) and is the current edition.

    Teams in all sectors under CCPA/CPRA + US state privacy should confirm which edition their engagement, contract, or assessment cycle requires before relying on CCPA/CPRA with 2026 CPPA regulations.

    California Privacy Protection Agency (opens in a new tab)
  37. Already happenedGovernmentPermalink

    CMMC — CMMC 32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025) supersedes 1.0 and is the current edition.

    Teams in defense industrial base under CMMC should confirm which edition their engagement, contract, or assessment cycle requires before relying on 32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025).

    DoD CMMC Program (opens in a new tab)
  38. Already happenedSecurityPermalink

    NIST SP 800-53 — NIST SP 800-53 Rev. 5, Release 5.2.0 supersedes Rev. 5, Release 5.1.1 and is the current edition.

    Teams in federal, critical infrastructure, technology under NIST SP 800-53 should confirm which edition their engagement, contract, or assessment cycle requires before relying on Rev. 5, Release 5.2.0.

    NIST Computer Security Resource Center (opens in a new tab)
  39. Already happenedPrivacyPermalink

    ISO/IEC 27018 — ISO/IEC 27018 2025 supersedes 2019 and is the current edition.

    Teams in cloud services, SaaS, technology under ISO/IEC 27018 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2025.

    ISO/IEC 27018:2025 (opens in a new tab)
  40. Already happenedGovernmentPermalink

    GAO Green Book — GAO Green Book 2025 Revision supersedes 2014 Revision and is the current edition.

    Teams in federal, government audit, public sector under GAO Green Book should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2025 Revision.

    US Government Accountability Office (opens in a new tab)
  41. Already happenedGovernmentPermalink

    ARC-AMPE — ARC-AMPE v1.02 supersedes MARS-E 2.2 and is the current edition.

    Teams in healthcare, insurance, federal under ARC-AMPE should confirm which edition their engagement, contract, or assessment cycle requires before relying on v1.02.

    CMS — Direct Enrollment Entity Resources (opens in a new tab)
  42. Already happenedGovernmentPermalink

    CJIS Security Policy — CJIS Security Policy 6.0 supersedes 5.9.5.

    Teams in law enforcement, public safety, government under CJIS Security Policy should confirm which edition their engagement, contract, or assessment cycle requires before relying on 6.0.

    FBI Criminal Justice Information Services (opens in a new tab)
  43. Already happenedOtherPermalink

    OSCAL — OSCAL 1.2.0 supersedes 1.1.3.

    Teams in all sectors under OSCAL should confirm which edition their engagement, contract, or assessment cycle requires before relying on 1.2.0.

    NIST OSCAL (opens in a new tab)
  44. Already happenedSecurityPermalink

    PCI Mobile Payments on COTS (MPoC) — PCI Mobile Payments on COTS (MPoC) v1.1 supersedes v1.0 and is the current edition.

    Teams in payments, mobile point-of-sale under PCI Mobile Payments on COTS (MPoC) should confirm which edition their engagement, contract, or assessment cycle requires before relying on v1.1.

    PCI Security Standards Council — MPoC (opens in a new tab)
  45. Already happenedGovernmentPermalink

    GovRAMP (formerly StateRAMP) — GovRAMP (formerly StateRAMP) Rev. 5 baselines supersedes Rev. 4 baselines and is the current edition.

    Teams in cloud services, SaaS, state and local government under GovRAMP (formerly StateRAMP) should confirm which edition their engagement, contract, or assessment cycle requires before relying on Rev. 5 baselines.

    GovRAMP (opens in a new tab)
  46. Already happenedSecurityPermalink

    CIS Critical Security Controls — CIS Critical Security Controls v8.1 supersedes v8 and is the current edition.

    Teams in all sectors under CIS Critical Security Controls should confirm which edition their engagement, contract, or assessment cycle requires before relying on v8.1.

    Center for Internet Security (opens in a new tab)
  47. Already happenedSecurityPermalink

    PCI DSS — PCI DSS v4.0.1 supersedes v4.0 and is the current edition.

    Teams in payments, retail, SaaS under PCI DSS should confirm which edition their engagement, contract, or assessment cycle requires before relying on v4.0.1.

    PCI Security Standards Council (opens in a new tab)
  48. Already happenedFinancialPermalink

    SOC 1 — SOC 1 AT-C section 320, as amended by SSAE No. 23 (2025-12-15) supersedes SSAE No. 18 (AT-C section 320) and is the current edition.

    Teams in service organizations, payroll, financial services under SOC 1 should confirm which edition their engagement, contract, or assessment cycle requires before relying on AT-C section 320, as amended by SSAE No. 23 (2025-12-15).

    AICPA — SOC 1 (opens in a new tab)
  49. Already happenedGovernmentPermalink

    NIST SP 800-171 — NIST SP 800-171 Rev. 3 supersedes Rev. 2 and is the current edition.

    Teams in defense industrial base, federal contractors under NIST SP 800-171 should confirm which edition their engagement, contract, or assessment cycle requires before relying on Rev. 3.

    NIST Computer Security Resource Center (opens in a new tab)
  50. Already happenedSecurityPermalink

    TISAX — TISAX ISA 6.0.3 supersedes ISA 5.1.0 and is the current edition.

    Teams in automotive, manufacturing, supply chain under TISAX should confirm which edition their engagement, contract, or assessment cycle requires before relying on ISA 6.0.3.

    ENX Association (opens in a new tab)
  51. Already happenedSecurityPermalink

    NIST Cybersecurity Framework — NIST Cybersecurity Framework 2.0 supersedes 1.1 and is the current edition.

    Teams in all sectors under NIST Cybersecurity Framework should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2.0.

    NIST Cybersecurity Framework (opens in a new tab)
  52. Already happenedOtherPermalink

    ISO 22301 — ISO 22301 2019 (Amd 1:2024) supersedes 2012 and is the current edition.

    Teams in all sectors, critical infrastructure, financial services under ISO 22301 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2019 (Amd 1:2024).

    ISO 22301:2019 (opens in a new tab)
  53. Already happenedPrivacyPermalink

    42 CFR Part 2 — 42 CFR Part 2 2024 final rule supersedes Pre-2024 Part 2 and is the current edition.

    Teams in healthcare, behavioral health under 42 CFR Part 2 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2024 final rule.

    HHS — Confidentiality of Substance Use Disorder Patient Records (opens in a new tab)
  54. Already happenedGovernmentPermalink

    GAO Yellow Book (GAGAS) — GAO Yellow Book (GAGAS) 2024 Revision supersedes 2018 Revision (2021 technical update) and is the current edition.

    Teams in government audit, public sector, government award recipients under GAO Yellow Book (GAGAS) should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2024 Revision.

    US Government Accountability Office (opens in a new tab)
  55. Already happenedOtherPermalink

    IIA Global Internal Audit Standards — IIA Global Internal Audit Standards 2024 IPPF (effective 2025-01-09) supersedes 2017 IPPF and is the current edition.

    Teams in internal audit, professional services, all sectors under IIA Global Internal Audit Standards should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2024 IPPF (effective 2025-01-09).

    The Institute of Internal Auditors (opens in a new tab)
  56. Already happenedFinancialPermalink

    GLBA Safeguards Rule — GLBA Safeguards Rule 16 CFR Part 314 (amended 2023) supersedes 16 CFR Part 314 (2021 amendments) and is the current edition.

    Teams in financial services, lending, tax preparation under GLBA Safeguards Rule should confirm which edition their engagement, contract, or assessment cycle requires before relying on 16 CFR Part 314 (amended 2023).

    Federal Trade Commission (opens in a new tab)
  57. Already happenedFinancialPermalink

    NYDFS 23 NYCRR 500 — NYDFS 23 NYCRR 500 23 NYCRR 500 (2023 amendments) supersedes 23 NYCRR 500 (2017) and is the current edition.

    Teams in financial services, insurance under NYDFS 23 NYCRR 500 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 23 NYCRR 500 (2023 amendments).

    NYDFS Cybersecurity Resource Center (opens in a new tab)
  58. Already happenedGovernmentPermalink

    FedRAMP (Rev. 5 baselines) — FedRAMP (Rev. 5 baselines) Rev. 5 supersedes Rev. 4 and is the current edition.

    Teams in federal cloud under FedRAMP (Rev. 5 baselines) should confirm which edition their engagement, contract, or assessment cycle requires before relying on Rev. 5.

    FedRAMP (opens in a new tab)
  59. Already happenedSecurityPermalink

    NIS2 Directive — NIS2 Directive Directive (EU) 2022/2555 supersedes Directive (EU) 2016/1148 (NIS1) and is the current edition.

    Teams in critical sectors under NIS2 Directive should confirm which edition their engagement, contract, or assessment cycle requires before relying on Directive (EU) 2022/2555.

    European Commission — NIS2 (opens in a new tab)
  60. Already happenedSecurityPermalink

    ISO/IEC 27001 — ISO/IEC 27001 2022 (Amd 1:2024) supersedes 2013 and is the current edition.

    Teams in all sectors under ISO/IEC 27001 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2022 (Amd 1:2024).

    ISO/IEC 27001:2022 (opens in a new tab)
  61. Already happenedSecurityPermalink

    PCI DSS — PCI DSS v4.0 supersedes v3.2.1.

    Teams in payments, retail, SaaS under PCI DSS should confirm which edition their engagement, contract, or assessment cycle requires before relying on v4.0.

    PCI Security Standards Council (opens in a new tab)
  62. Already happenedSecurityPermalink

    ISO/IEC 27002 — ISO/IEC 27002 2022 supersedes 2013 and is the current edition.

    Teams in all sectors, SaaS, technology under ISO/IEC 27002 should confirm which edition their engagement, contract, or assessment cycle requires before relying on 2022.

    ISO/IEC 27002:2022 (opens in a new tab)
  63. Already happenedSecurityPermalink

    NIST SSDF — NIST SSDF v1.1 supersedes v1.0 and is the current edition.

    Teams in technology, federal contractors, SaaS under NIST SSDF should confirm which edition their engagement, contract, or assessment cycle requires before relying on v1.1.

    NIST — Secure Software Development Framework (opens in a new tab)
  64. Already happenedSecurityPermalink

    PCI PIN Security Requirements — PCI PIN Security Requirements v3.1 supersedes v3.0 and is the current edition.

    Teams in payments under PCI PIN Security Requirements should confirm which edition their engagement, contract, or assessment cycle requires before relying on v3.1.

    PCI Security Standards Council — PIN Security (opens in a new tab)
  65. Already happenedGovernmentPermalink

    FISMA — FISMA Federal Information Security Modernization Act of 2014 supersedes Federal Information Security Management Act of 2002 and is the current edition.

    Teams in federal, federal contractors under FISMA should confirm which edition their engagement, contract, or assessment cycle requires before relying on Federal Information Security Modernization Act of 2014.

    Cybersecurity and Infrastructure Security Agency (opens in a new tab)
Signalled — no fixed date yet
  1. In force and enforcedPrivacy

    42 CFR Part 2 — 42 CFR Part 2: Compliance was required by 2026-02-16. OCR announced its civil enforcement program 2026-02-13 and began accepting complaints, breach notifications, and resolving noncompliance findings (resolution agreements, settlements, corrective actions, civil monetary penalties) starting 2026-02-16. This is now enforced, not upcoming. hhs.gov blocks automated fetch (403); corroborated via independent legal-industry sources.

    Teams in healthcare, behavioral health should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    HHS — Confidentiality of Substance Use Disorder Patient Records (opens in a new tab)
  2. Phased through 2030Privacy

    CCPA/CPRA + US state privacy — CCPA/CPRA + US state privacy: The regulations took effect 2026-01-01, confirmed directly against cppa.ca.gov, but most substantive obligations phase in later — ADMT obligations begin 2027-01-01, risk assessments for processing already underway must be documented by 2027-12-31, and cybersecurity-audit certifications follow a staged schedule by revenue tier through 2030.

    Teams in all sectors should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    California Privacy Protection Agency (opens in a new tab)
  3. Phase II timing unannounced; program review in progressGovernment

    CMMC — CMMC: On 2026-07-13 the Department suspended Phase II and all pending and future CMMC implementation milestones while a reform review proceeds. Phase I self-assessment requirements remain in place, and the Department states that interim enforcement uses NIST SP 800-171 Rev. 2 self-assessments plus selected government-led assessments.

    Teams in defense industrial base should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    DoD CMMC Program (opens in a new tab)
  4. UnannouncedGovernment

    CMS Enhanced Direct Enrollment — CMS Enhanced Direct Enrollment: The Year 9 audit submission window closed 2026-07-01. CMS has said it intends to publish updated guidelines for calendar-year 2026 audit submissions (Year 10); no Year 10 document was found at this check.

    Teams in healthcare, insurance should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    CMS — Direct Enrollment Partners (opens in a new tab)
  5. Later in 2026Financial

    COBIT 2019 (SOX ITGC reference) — COBIT 2019 (SOX ITGC reference): ISACA states that a COBIT update is planned later in 2026. COBIT 2019 remains the current framework until a successor is published; planned timing is not a released edition.

    Teams in public companies, financial reporting should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    ISACA — COBIT (opens in a new tab)
  6. No pending legislation identifiedGovernment

    FISMA — FISMA: No modernization bill has passed since 2014. A 2023 reform bill advanced through Senate committee markup but did not become law; no equivalent bill has been tracked in the current Congress as of this check.

    Teams in federal, federal contractors should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    Cybersecurity and Infrastructure Security Agency (opens in a new tab)
  7. July 2027 (anticipated final action in the HHS Unified Agenda)Security

    HIPAA Security Rule — HIPAA Security Rule: OCR's January 2025 proposal (RIN 0945-AA22) is not final, so the existing Security Rule remains in force. HHS's Unified Agenda lists July 2027 as an anticipated final-action date, not a guaranteed effective date.

    Teams in healthcare should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    HHS Office for Civil Rights (opens in a new tab)
  8. Submission deadline not yet announced (≥90 days' notice promised)Security

    HITRUST CSF — HITRUST CSF: New e1, i1, and rapid assessment objects can no longer be created on CSF v11.7.0 as of 2026-05-07 — all new assessments must be created on v11.8.0. Assessment objects already created on v11.7.0 may still be submitted; this is a wind-down, not a hard cutoff, and HITRUST has committed to announcing the v11.7.0 submission deadline at least 90 days in advance.

    Teams in healthcare, technology, financial services should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    HITRUST Alliance (opens in a new tab)
  9. Draft not yet finalizedGovernment

    IRS Publication 1075 — IRS Publication 1075: A successor, Rev. 12-2026, exists only as a draft on the IRS's draft-forms page (marked 'DRAFT — NOT FOR FILING'); Rev. 11-2021 remains the current, effective version.

    Teams in government, CMS contractors, state and local government should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    Internal Revenue Service (opens in a new tab)
  10. Publication date unannouncedOther

    ISO 22301 — ISO 22301: ISO has opened development of the third edition as ISO/CD 22301. The 2019 edition with Amendment 1:2024 remains the published standard.

    Teams in all sectors, critical infrastructure, financial services should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    ISO 22301:2019 (opens in a new tab)
  11. 2026 amendment draft not yet finalizedFinancial

    NAIC Insurance Data Security Model Law — NAIC Insurance Data Security Model Law: Roughly 25-28 states had adopted a version of Model #668 as of 2026. A 2026 amendment draft addresses AI and third-party data; it has not been finalized.

    Teams in insurance, healthcare should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    National Association of Insurance Commissioners (opens in a new tab)
  12. No successor publication date announcedAI

    NIST AI Risk Management Framework — NIST AI Risk Management Framework: NIST states that AI RMF 1.0 is being revised. The July 2025 White House 'America's AI Action Plan' directs NIST to revise the RMF to remove references to misinformation, Diversity, Equity, and Inclusion, and climate change — that directive, not an independent NIST initiative, is the revision's driver. NIST AI 600-1, the Generative AI Profile published 2024-07-26, remains a companion profile rather than a successor version.

    Teams in AI, technology, federal should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    NIST AI Risk Management Framework (opens in a new tab)
  13. Final version 1.1 pendingPrivacy

    NIST Privacy Framework — NIST Privacy Framework: NIST Privacy Framework 1.1 remains an Initial Public Draft; NIST lists the final version as coming soon. Version 1.0 remains the current final framework.

    Teams in all sectors, healthcare, technology should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    National Institute of Standards and Technology (opens in a new tab)
  14. DFARS transition not expected before late 2026 to 2027 at the earliestGovernment

    NIST SP 800-171 — NIST SP 800-171: Rev. 3 is the current NIST publication, but DoD contracts still enforce Rev. 2 through a DFARS class deviation, reinforced by the 2026-07-13 CMMC Phase II suspension, which pins interim enforcement to Rev. 2 self-assessment. Do not tell a defense contractor Rev. 3 is their contractual baseline without checking their clause.

    Teams in defense industrial base, federal contractors should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    NIST Computer Security Resource Center (opens in a new tab)
  15. SP 800-218r1 in draft; comment period closed 2026-01-30Security

    NIST SSDF — NIST SSDF: SP 800-218A, the community profile for generative AI and dual-use foundation models, extends the SSDF to AI model development. NIST published the initial public draft of SP 800-218r1 (SSDF v1.2) on 2025-12-17, per Executive Order 14306; the comment period closed 2026-01-30 with no finalization date announced.

    Teams in technology, federal contractors, SaaS should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    NIST — Secure Software Development Framework (opens in a new tab)
  16. UnannouncedSecurity

    PCI 3DS Core Security Standard — PCI 3DS Core Security Standard: A v2.0 revision has been under discussion for years with no publication date announced; v1.0 remains the current, effective standard.

    Teams in payments should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    PCI Security Standards Council — 3DS Core (opens in a new tab)
  17. v3.0.1 draft not yet finalizedSecurity

    PCI Card Production and Provisioning — PCI Card Production and Provisioning: A combined v3.0.1 draft was in RFC from 2026-02-13 to 2026-03-16; it has not yet been finalized or published.

    Teams in payments, card issuers should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    PCI Security Standards Council — Card Production and Provisioning (opens in a new tab)
  18. UnannouncedSecurity

    PCI DSS — PCI DSS: PCI SSC completed a request-for-comments on the currently published v4.0.1 on 2026-07-20. No successor version has been announced.

    Teams in payments, retail, SaaS should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    PCI Security Standards Council (opens in a new tab)
  19. v4.0 in development; unannouncedSecurity

    PCI Point-to-Point Encryption — PCI Point-to-Point Encryption: PCI SSC closed v3.1 solution submissions 2026-03-31. A v4.0 revision is in development; no publication date has been announced.

    Teams in payments should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    PCI Security Standards Council — P2PE (opens in a new tab)
  20. In forcePrivacy

    Texas Data Privacy and Security Act — Texas Data Privacy and Security Act: The Act took effect 2024-07-01; the universal opt-out signal requirement took effect 2025-01-01. Texas HB 149 (TRAIGA) separately amends the Act with AI-specific processor duties.

    Teams in all sectors should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    Texas Legislature — HB 4 (88th R.S.) (opens in a new tab)
  21. In forceAI

    Texas Responsible AI Governance Act — Texas Responsible AI Governance Act: In force since 2026-01-01.

    Teams in AI, technology, government should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    Texas Legislature — HB 149 (opens in a new tab)
  22. In forcePrivacy

    Washington My Health My Data Act — Washington My Health My Data Act: Staggered implementation: Section 10 (private right of action) took effect 2023-07-23; Sections 4-9 took effect 2024-03-31 for larger entities and 2024-06-30 for small businesses. All dates have passed — the Act is fully in force.

    Teams in consumer health, technology should watch for a fixed date; the authority has signalled this change but has not published an effective date.

    Washington State Office of the Attorney General (opens in a new tab)
Regulatory change tracker | ControlFrame