REGULATION / DEADLINE TRACKER

Regulatory Deadline Tracker

Target dates for cryptographic inventories, post-quantum migration, cybersecurity and AI rules around the world, and how much time is left to meet each one.

Each entry is checked against its primary source at least every 90 days. Most recent check: .

  1. In effect

    Qatar · Qatar Central Bank Supervisory

    The guideline enters into force, including the AI register disclosed to QCB annually, QCB approval before launching a new AI system as provider or signing a high-risk AI purchase, licensing or outsourcing agreement, human oversight protocols and customer notification.

    Artificial Intelligence Guideline (Regulating the Use of Artificial Intelligence by QCB Licensed Entities). Applies to entities regulated by the Qatar Central Bank that develop, buy or outsource AI. Source · Explainer · Verified 7 Oct 2026

  2. In effect

    European Union · European Commission Binding

    Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.

    Delegated Regulation (EU) 2024/1774 (DORA ICT risk RTS), Articles 6 and 7. Applies to EU financial entities under the full DORA ICT risk framework. Source · Verified 7 Oct 2026

  3. In effect

    European Union · European Parliament and Council Binding

    Prohibited AI practices in Article 5 apply, together with the AI literacy duty in Article 4.

    Regulation (EU) 2024/1689 (AI Act), Article 113(a). Applies to providers and deployers of AI systems in or affecting the EU. Source · Explainer · Verified 7 Oct 2026

  4. In effect

    Global payments · PCI Security Standards Council Binding

    Keep documentation of the cryptographic cipher suites and protocols in use, with a current inventory of what each does and where it runs, active tracking of whether each remains safe and a plan for reacting to foreseeable cryptographic weaknesses, and review it at least once every 12 months. Treated as a best practice until this date and required since.

    PCI DSS v4.0.1, requirement 12.3.3. Applies to entities in scope of PCI DSS (contractual standard), for all cipher suites and protocols used to meet PCI DSS requirements. Source · Verified 7 Oct 2026

  5. In effect

    Bahrain · Information and eGovernment Authority (approved by the Ministerial Committee for Information and Communication Technology) Binding

    Government entities must comply with the rules, requirements and guiding principles of the policy from the date of its approval.

    General Policy for the Use of Artificial Intelligence, version 1.0. Applies to government entities in Bahrain only (a government policy, not a law). Source · Explainer · Verified 7 Oct 2026

  6. In effect

    Australia · Australian Prudential Regulation Authority Binding

    Operational risk management and business continuity standard commences.

    Prudential Standard CPS 230 Operational Risk Management. Applies to APRA-regulated entities. Source · Explainer · Verified 7 Oct 2026

  7. In effect

    European Union · European Parliament and Council Binding

    Obligations for providers of general-purpose AI models (Chapter V) apply.

    Regulation (EU) 2024/1689 (AI Act), Article 113(b). Applies to providers of general-purpose AI models placed on the EU market. Source · Explainer · Verified 7 Oct 2026

  8. In effect

    Japan · Government of Japan (Cabinet Office) Binding

    The AI Promotion Act is fully in force, including the AI Strategy Headquarters.

    Act on the Promotion of Research, Development and Utilisation of AI-Related Technologies. Applies to AI research, development and use in Japan (a promotion law that mainly sets duties for government). Source · Explainer · Verified 7 Oct 2026

  9. In effect

    China · Cyberspace Administration of China with MIIT, MPS and NRTA Binding

    Labelling duties for AI-generated synthetic content take effect.

    Measures for Labelling AI-Generated Synthetic Content. Applies to internet information service providers that generate or distribute synthetic content in China. Source · Explainer · Verified 7 Oct 2026

  10. In effect

    United States (New York) · New York State Department of Financial Services Binding

    Maintain a complete, documented asset inventory, alongside the expanded multi-factor authentication duty in section 500.12.

    23 NYCRR Part 500 (Second Amendment), section 500.13(a). Applies to NYDFS-regulated covered entities. Source · Explainer · Verified 7 Oct 2026

  11. In effect

    United States (Texas) · Texas Legislature Binding

    The Texas AI governance act takes effect.

    Texas Responsible Artificial Intelligence Governance Act (HB 149). Applies to developers and deployers of AI systems in Texas, as defined in the Act. Source · Explainer · Verified 7 Oct 2026

  12. In effect

    South Korea · National Assembly of Korea Binding

    The AI Framework Act takes effect.

    Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust (Act No. 20676). Applies to AI businesses covered by the Act. Source · Explainer · Verified 7 Oct 2026

  13. In effect

    United Arab Emirates (ADGM) · ADGM Financial Services Regulatory Authority Binding

    Maintain an incident response plan, which GEN section 3.5.16 requires from this date.

    General Rulebook (GEN) section 3.5.16, as noted in FSRA Notice FSRA/FCCP/146/2025 (17 October 2025). Applies to FSRA Authorised Persons and Recognised Bodies in ADGM. Source · Explainer · Verified 7 Oct 2026

  14. In effect

    India · Ministry of Electronics and Information Technology Binding

    Due diligence and labelling duties for synthetically generated information, meaning realistic AI-made or altered audio, visual or audiovisual content, take effect.

    IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E)). Applies to intermediaries whose services enable the creation or sharing of such content, with extra duties for significant social media intermediaries. Source · Explainer · Verified 7 Oct 2026

  15. In effect

    United States · US Securities and Exchange Commission Binding

    Smaller covered institutions must run an incident response programme. After learning of actual or probable unauthorised access to customer information, they must tell the people whose sensitive information is, or probably is, affected as quickly as they can and within 30 days at most, subject to limited exceptions.

    Regulation S-P amendments (Release 34-100155, 89 FR 47688, 3 June 2024). Applies to smaller broker-dealers, investment companies, investment advisers and transfer agents (larger entities from 3 December 2025). Source · Explainer · Verified 7 Oct 2026

  16. In effect

    European Union · European Parliament and Council Binding

    General application date, including the Article 50 transparency duties for chatbots, deepfakes and emotion recognition.

    Regulation (EU) 2024/1689 (AI Act), Article 113. Applies to providers and deployers of the AI systems covered by Article 50. Source · Explainer · Verified 7 Oct 2026

  17. In effect

    Canada · Office of the Superintendent of Financial Institutions (OSFI) Supervisory

    Full adherence to the guideline, including identifying and mapping critical operations and setting tolerances for disruption.

    Guideline E-21 Operational Risk Management and Resilience. Applies to federally regulated financial institutions. Source · Explainer · Verified 7 Oct 2026

  18. In effect

    European Union · European Parliament and Council Binding

    Manufacturer reporting obligations in Article 14 apply.

    Cyber Resilience Act, Regulation (EU) 2024/2847, Article 71(2). Applies to manufacturers of products with digital elements on the EU market. Source · Explainer · Verified 7 Oct 2026

  19. Upcoming

    United States · Office of Management and Budget Binding

    Submit a post-quantum cryptography migration plan to OMB and the Office of the National Cyber Director, no later than 120 days after the memorandum. The date shown is calculated by us as 120 days after 24 June 2026; the memorandum gives only the number of days.

    OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography (24 June 2026). Applies to US federal civilian agencies (excluding national security systems). Source · Explainer · Verified 7 Oct 2026

  20. Upcoming

    European Union · European Parliament and Council Binding

    New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material apply.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 113(a). Applies to providers and deployers of AI systems in or affecting the EU. Source · Explainer · Verified 7 Oct 2026

  21. Upcoming

    European Union · European Parliament and Council Binding

    Machine-readable marking of synthetic content under Article 50(2) for generative systems already on the market before 2 August 2026.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 111(4). Applies to providers of generative AI systems placed on the market before 2 August 2026. Source · Explainer · Verified 7 Oct 2026

  22. Upcoming

    United States · The White House Binding

    The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, section 6(c). Applies to FAR Council; the contractor rule itself will be a proposal until finalised. Source · Explainer · Verified 7 Oct 2026

  23. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  24. Upcoming

    European Union · NIS Cooperation Group Guidance

    All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 1. Applies to EU Member States. Source · Verified 7 Oct 2026

  25. Upcoming

    United States (Colorado) · Colorado General Assembly Binding

    Main developer and deployer duties for automated decision-making technology in consequential decisions apply.

    SB 26-189, Automated Decision-Making Technology (replacing the provisions of SB 24-205). Applies to developers and deployers of automated decision-making technology used in consequential decisions in Colorado. Source · Explainer · Verified 7 Oct 2026

  26. Upcoming

    United States (New York) · New York State Legislature Binding

    Transparency and safety incident reporting duties for large frontier AI developers apply, overseen by an office within the Department of Financial Services.

    RAISE Act as amended by S8828 (Chapter 96 of 2026). Applies to large frontier AI model developers, as defined in the Act. Source · Explainer · Verified 7 Oct 2026

  27. Upcoming

    United States · The White House Binding

    CISA, in coordination with NIST, must release public guidance on the minimum elements of a cryptographic bill of materials within 270 days of the order. The date shown is calculated by us as 270 days after 22 June 2026.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, section 5(d). Applies to CISA and NIST (the resulting guidance is for public use). Source · Explainer · Verified 7 Oct 2026

  28. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    Submit a quantum-safe migration plan to CSA.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Verified 7 Oct 2026

  29. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  30. Upcoming

    Switzerland · FINMA Supervisory

    Draw up a post-quantum cryptography roadmap.

    FINMA Guidance 05/2026. Applies to FINMA-supervised institutions (recommendation). Source · Verified 7 Oct 2026

  31. Upcoming

    European Union · European Parliament and Council Binding

    General-purpose AI models placed on the market before 2 August 2025 must comply with the Chapter V obligations.

    Regulation (EU) 2024/1689 (AI Act), Article 111(3). Applies to providers of general-purpose AI models already on the market before 2 August 2025. Source · Explainer · Verified 7 Oct 2026

  32. Upcoming

    Canada · Office of the Superintendent of Financial Institutions (OSFI) Supervisory

    Complete scenario testing for all critical operations.

    Guideline E-21 Operational Risk Management and Resilience. Applies to federally regulated financial institutions. Source · Explainer · Verified 7 Oct 2026

  33. Upcoming

    Singapore · Monetary Authority of Singapore Supervisory

    Sections 3 and 4 of the AI risk management guidelines take effect.

    Guidelines on Artificial Intelligence Risk Management (7 October 2026). Applies to financial institutions regulated by MAS. Source · Explainer · Verified 7 Oct 2026

  34. Upcoming

    European Union · European Parliament and Council Binding

    High-risk requirements apply to the Annex III use cases, such as hiring, credit scoring, education and biometrics. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities, which must comply by 2 August 2030 (Article 111(2)).

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113(c)(i). Applies to providers and deployers of high-risk AI systems listed in Annex III. Source · Explainer · Verified 7 Oct 2026

  35. Upcoming

    European Union · European Parliament and Council Binding

    Main obligations apply, including the Annex I requirement to protect data confidentiality, for example by encrypting data at rest or in transit with state of the art mechanisms.

    Cyber Resilience Act, Regulation (EU) 2024/2847, Article 71(2) and Annex I. Applies to manufacturers, importers and distributors of products with digital elements on the EU market. Source · Explainer · Verified 7 Oct 2026

  36. Upcoming

    India · Department of Science and Technology (National Quantum Mission) Guidance

    Build foundations: governance, cryptographic inventory and quantum risk assessment.

    Roadmap for a quantum-safe ecosystem in India (May 2026). Applies to critical information infrastructure organisations (national roadmap, not a regulation). Source · Explainer · Verified 7 Oct 2026

  37. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    New CII systems procured and implemented should support quantum-safe algorithms or be quantum-safe ready.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Explainer · Verified 7 Oct 2026

  38. Upcoming

    European Union · European Parliament and Council Binding

    High-risk requirements apply to AI in products covered by the EU product laws in Section A of Annex I. For Section B laws, such as machinery, vehicles and aviation, the requirements come mainly through those sector rules. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities (2 August 2030).

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113(c)(ii). Applies to providers of AI that is, or is a safety component of, an Annex I product that must undergo third-party conformity assessment. Source · Explainer · Verified 7 Oct 2026

  39. Upcoming

    Singapore · Monetary Authority of Singapore Supervisory

    Meet the supervisory expectations in sections 5 and 6 of the AI risk management guidelines by this date. The guidelines take effect on 7 October 2027.

    Guidelines on Artificial Intelligence Risk Management (7 October 2026). Applies to financial institutions regulated by MAS. Source · Explainer · Verified 7 Oct 2026

  40. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete discovery and build an initial migration plan.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially critical national infrastructure. Source · Verified 7 Oct 2026

  41. Upcoming

    India · Department of Science and Technology (National Quantum Mission) Guidance

    Migrate high-priority systems to post-quantum cryptography.

    Roadmap for a quantum-safe ecosystem in India (May 2026). Applies to critical information infrastructure organisations (national roadmap, not a regulation). Source · Explainer · Verified 7 Oct 2026

  42. Upcoming

    India · Department of Science and Technology (National Quantum Mission) Guidance

    Build foundations: governance, cryptographic inventory and quantum risk assessment.

    Roadmap for a quantum-safe ecosystem in India (May 2026). Applies to enterprises outside critical information infrastructure (national roadmap, not a regulation). Source · Explainer · Verified 7 Oct 2026

  43. Upcoming

    India · Department of Science and Technology (National Quantum Mission) Guidance

    Full post-quantum adoption, with post-quantum cryptography as the default.

    Roadmap for a quantum-safe ecosystem in India (May 2026). Applies to critical information infrastructure organisations (national roadmap, not a regulation). Source · Explainer · Verified 7 Oct 2026

  44. Upcoming

    United States · The White House Binding

    Agencies must support TLS 1.3 or a successor version as soon as practicable, and no later than this date, under requirements that the order directed OMB (for other systems) and NSA (for national security systems) to issue; OMB M-26-15 restates the date.

    Executive Order 14306 (6 June 2025), amending Executive Order 14144, section 4(f). Applies to US federal agencies, through OMB requirements for other systems and NSA requirements for national security systems. Source · Explainer · Verified 7 Oct 2026

  45. Upcoming

    European Union · European Parliament and Council Binding

    High-risk AI systems intended for use by public authorities that were placed on the market or put into service before the high-risk rules applied must comply, whether or not their design has changed.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 111(2). Applies to providers and deployers of high-risk AI systems used by public authorities. Source · Explainer · Verified 7 Oct 2026

  46. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(ii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  47. Upcoming

    Australia · Australian Signals Directorate Guidance

    Stop using traditional asymmetric cryptography such as RSA, Diffie-Hellman, ECDH and ECDSA.

    Planning for post-quantum cryptography (September 2025) and the ISM Guidelines for cryptography (ISM-0472, 0474, 0475, 0476). Applies to Australian government and organisations following the ISM. Source · Explainer · Verified 7 Oct 2026

  48. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for high-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 2. Applies to EU Member States. Source · Verified 7 Oct 2026

  49. Upcoming

    Hong Kong · Hong Kong Monetary Authority Announcement

    Aim for full sectoral quantum readiness (a Quantum Preparedness Index score of 10, up from 2.3).

    Quantum Preparedness Index and whitepaper (27 July 2026). Applies to the Hong Kong banking sector (stated aim, not a rule). Source · Explainer · Verified 7 Oct 2026

  50. Upcoming

    India · Department of Science and Technology (National Quantum Mission) Guidance

    Migrate high-priority systems to post-quantum cryptography.

    Roadmap for a quantum-safe ecosystem in India (May 2026). Applies to enterprises outside critical information infrastructure (national roadmap, not a regulation). Source · Explainer · Verified 7 Oct 2026

  51. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    Complete migration to quantum-safe cryptography.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Verified 7 Oct 2026

  52. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(iii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  53. Upcoming

    Canada · Canadian Centre for Cyber Security Guidance

    Migrate high-priority non-classified government systems.

    ITSM.40.001 Roadmap for the migration to post-quantum cryptography. Applies to Government of Canada non-classified systems. Source · Verified 7 Oct 2026

  54. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete early, highest-priority migration activities and refine the plan into a roadmap for completing migration by 2035.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially large organisations and critical national infrastructure. Source · Explainer · Verified 7 Oct 2026

  55. Upcoming

    India · Department of Science and Technology (National Quantum Mission) Guidance

    Full post-quantum adoption, with post-quantum cryptography as the default.

    Roadmap for a quantum-safe ecosystem in India (May 2026). Applies to enterprises outside critical information infrastructure (national roadmap, not a regulation). Source · Explainer · Verified 7 Oct 2026

  56. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete migration to post-quantum cryptography across systems and products.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations. Source · Verified 7 Oct 2026

  57. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for medium-risk use cases, and for low-risk use cases as far as feasible.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1). Applies to EU Member States. Source · Explainer · Verified 7 Oct 2026

  58. Upcoming

    Canada · Canadian Centre for Cyber Security Guidance

    Complete migration of the remaining non-classified government systems.

    ITSM.40.001 Roadmap for the migration to post-quantum cryptography. Applies to Government of Canada non-classified systems. Source · Explainer · Verified 7 Oct 2026

  59. Upcoming

    Canada · Office of the Superintendent of Financial Institutions (OSFI) Guidance

    Reach quantum readiness across all systems, the target the bulletin says guidelines generally recommend.

    Technology Risk Bulletin, Quantum Readiness Phases and Timelines (March 2026). Applies to federally regulated financial institutions (best practice, not a requirement). Source · Explainer · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

This tracker is general information, not legal advice. Whether a rule applies to you depends on your sector, location and contracts. Check the linked source for the current text.