Regulatory Deadline Tracker
Target dates for cryptographic inventories, post-quantum migration, cybersecurity and AI rules around the world, and how much time is left to meet each one.
Each entry is checked against its primary source at least every 90 days. Most recent check: .
- In effect
Qatar · Qatar Central Bank Supervisory
The guideline enters into force, including the AI register disclosed to QCB annually, QCB approval before launching a new AI system as provider or signing a high-risk AI purchase, licensing or outsourcing agreement, human oversight protocols and customer notification.
- In effect
European Union · European Commission Binding
Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.
- In effect
European Union · European Parliament and Council Binding
Prohibited AI practices in Article 5 apply, together with the AI literacy duty in Article 4.
- In effect
Global payments · PCI Security Standards Council Binding
Keep documentation of the cryptographic cipher suites and protocols in use, with a current inventory of what each does and where it runs, active tracking of whether each remains safe and a plan for reacting to foreseeable cryptographic weaknesses, and review it at least once every 12 months. Treated as a best practice until this date and required since.
- In effect
Bahrain · Information and eGovernment Authority (approved by the Ministerial Committee for Information and Communication Technology) Binding
Government entities must comply with the rules, requirements and guiding principles of the policy from the date of its approval.
- In effect
Australia · Australian Prudential Regulation Authority Binding
Operational risk management and business continuity standard commences.
- In effect
European Union · European Parliament and Council Binding
Obligations for providers of general-purpose AI models (Chapter V) apply.
- In effect
Japan · Government of Japan (Cabinet Office) Binding
The AI Promotion Act is fully in force, including the AI Strategy Headquarters.
- In effect
China · Cyberspace Administration of China with MIIT, MPS and NRTA Binding
Labelling duties for AI-generated synthetic content take effect.
- In effect
United States (New York) · New York State Department of Financial Services Binding
Maintain a complete, documented asset inventory, alongside the expanded multi-factor authentication duty in section 500.12.
- In effect
United States (Texas) · Texas Legislature Binding
The Texas AI governance act takes effect.
- In effect
South Korea · National Assembly of Korea Binding
The AI Framework Act takes effect.
- In effect
United Arab Emirates (ADGM) · ADGM Financial Services Regulatory Authority Binding
Maintain an incident response plan, which GEN section 3.5.16 requires from this date.
- In effect
India · Ministry of Electronics and Information Technology Binding
Due diligence and labelling duties for synthetically generated information, meaning realistic AI-made or altered audio, visual or audiovisual content, take effect.
- In effect
United States · US Securities and Exchange Commission Binding
Smaller covered institutions must run an incident response programme. After learning of actual or probable unauthorised access to customer information, they must tell the people whose sensitive information is, or probably is, affected as quickly as they can and within 30 days at most, subject to limited exceptions.
- In effect
European Union · European Parliament and Council Binding
General application date, including the Article 50 transparency duties for chatbots, deepfakes and emotion recognition.
- In effect
Canada · Office of the Superintendent of Financial Institutions (OSFI) Supervisory
Full adherence to the guideline, including identifying and mapping critical operations and setting tolerances for disruption.
- In effect
European Union · European Parliament and Council Binding
Manufacturer reporting obligations in Article 14 apply.
- Upcoming
United States · Office of Management and Budget Binding
Submit a post-quantum cryptography migration plan to OMB and the Office of the National Cyber Director, no later than 120 days after the memorandum. The date shown is calculated by us as 120 days after 24 June 2026; the memorandum gives only the number of days.
- Upcoming
European Union · European Parliament and Council Binding
New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material apply.
- Upcoming
European Union · European Parliament and Council Binding
Machine-readable marking of synthetic content under Article 50(2) for generative systems already on the market before 2 August 2026.
- Upcoming
United States · The White House Binding
The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
European Union · NIS Cooperation Group Guidance
All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.
- Upcoming
United States (Colorado) · Colorado General Assembly Binding
Main developer and deployer duties for automated decision-making technology in consequential decisions apply.
- Upcoming
United States (New York) · New York State Legislature Binding
Transparency and safety incident reporting duties for large frontier AI developers apply, overseen by an office within the Department of Financial Services.
- Upcoming
United States · The White House Binding
CISA, in coordination with NIST, must release public guidance on the minimum elements of a cryptographic bill of materials within 270 days of the order. The date shown is calculated by us as 270 days after 22 June 2026.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Submit a quantum-safe migration plan to CSA.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Complete a quantum risk assessment with action plans.
- Upcoming
Switzerland · FINMA Supervisory
Draw up a post-quantum cryptography roadmap.
- Upcoming
European Union · European Parliament and Council Binding
General-purpose AI models placed on the market before 2 August 2025 must comply with the Chapter V obligations.
- Upcoming
Canada · Office of the Superintendent of Financial Institutions (OSFI) Supervisory
Complete scenario testing for all critical operations.
- Upcoming
Singapore · Monetary Authority of Singapore Supervisory
Sections 3 and 4 of the AI risk management guidelines take effect.
- Upcoming
European Union · European Parliament and Council Binding
High-risk requirements apply to the Annex III use cases, such as hiring, credit scoring, education and biometrics. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities, which must comply by 2 August 2030 (Article 111(2)).
- Upcoming
European Union · European Parliament and Council Binding
Main obligations apply, including the Annex I requirement to protect data confidentiality, for example by encrypting data at rest or in transit with state of the art mechanisms.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Build foundations: governance, cryptographic inventory and quantum risk assessment.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
New CII systems procured and implemented should support quantum-safe algorithms or be quantum-safe ready.
- Upcoming
European Union · European Parliament and Council Binding
High-risk requirements apply to AI in products covered by the EU product laws in Section A of Annex I. For Section B laws, such as machinery, vehicles and aviation, the requirements come mainly through those sector rules. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities (2 August 2030).
- Upcoming
Singapore · Monetary Authority of Singapore Supervisory
Meet the supervisory expectations in sections 5 and 6 of the AI risk management guidelines by this date. The guidelines take effect on 7 October 2027.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete discovery and build an initial migration plan.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Migrate high-priority systems to post-quantum cryptography.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Build foundations: governance, cryptographic inventory and quantum risk assessment.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Full post-quantum adoption, with post-quantum cryptography as the default.
- Upcoming
United States · The White House Binding
Agencies must support TLS 1.3 or a successor version as soon as practicable, and no later than this date, under requirements that the order directed OMB (for other systems) and NSA (for national security systems) to issue; OMB M-26-15 restates the date.
- Upcoming
European Union · European Parliament and Council Binding
High-risk AI systems intended for use by public authorities that were placed on the market or put into service before the high-risk rules applied must comply, whether or not their design has changed.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.
- Upcoming
Australia · Australian Signals Directorate Guidance
Stop using traditional asymmetric cryptography such as RSA, Diffie-Hellman, ECDH and ECDSA.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for high-risk use cases.
- Upcoming
Hong Kong · Hong Kong Monetary Authority Announcement
Aim for full sectoral quantum readiness (a Quantum Preparedness Index score of 10, up from 2.3).
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Migrate high-priority systems to post-quantum cryptography.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Complete migration to quantum-safe cryptography.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Migrate high-priority non-classified government systems.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete early, highest-priority migration activities and refine the plan into a roadmap for completing migration by 2035.
- Upcoming
India · Department of Science and Technology (National Quantum Mission) Guidance
Full post-quantum adoption, with post-quantum cryptography as the default.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete migration to post-quantum cryptography across systems and products.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for medium-risk use cases, and for low-risk use cases as far as feasible.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Complete migration of the remaining non-classified government systems.
- Upcoming
Canada · Office of the Superintendent of Financial Institutions (OSFI) Guidance
Reach quantum readiness across all systems, the target the bulletin says guidelines generally recommend.
This tracker is general information, not legal advice. Whether a rule applies to you depends on your sector, location and contracts. Check the linked source for the current text.