This website uses cookies

Read our Privacy policy and Terms of use for more information.

Today's Focus: Cybersecurity, Data Security & Cloud Security

Today's Top Story: China's Data-Risk Assessment Rules Take Effect Thursday

China's Measures for Risk Assessment of Network Data Security (Order No. 24) take legal effect on 20 August 2026 — three days out. Jointly issued on 18 June 2026 by the Cyberspace Administration of China, the MIIT and the Ministry of Public Security, they require processors of "important data" to run a documented security risk assessment at least once a year, plus a special assessment whenever the data's security situation materially changes. The Measures operationalise the Network Data Security Management Regulations (in force since January 2025) and point to national standard GB/T 45577-2025 for methodology. Any organisation — including cloud tenants — handling important data or large volumes of personal information in China needs an annual assessment and a reporting path in place by Thursday.

On the Calendar This Week

Key regulatory dates landing within the next 14 days:

  • 20 Aug (Thu): China Order No. 24 network-data risk-assessment rules take effect.

  • 26 Aug (Wed): FedRAMP Agency Support Group meeting.

  • 31 Aug (Mon): FedRAMP 20x Class B and Class C certification pipelines open.

  • 31 Aug (Mon): Federal Secure Cloud Advisory Committee (FSCAC) meeting.

Also Today

Dutch NIS2 law is now live. The Netherlands' Cyberbeveiligingswet (Cbw) entered into force on 15 August with no general grace period. The duty of care, 24-hour early-warning / 72-hour incident reporting, and NCSC registration apply now to an estimated 8,000+ organisations, with fines up to €10 million or 2% of global turnover for essential entities. Confirm your registration and reporting workflow are operational — not planned.

The EU CRA reporting clock starts 11 September. Cyber Resilience Act Article 14 duties (24h early warning, 72h notification) begin in 25 days and cover products already on the market. ENISA says its Single Reporting Platform will be operational by then, with testing under way — but it is not yet live, so build your onboarding and reporting channel now rather than waiting.

US deadlines shifted, not gone. The CMMC Reform Task Force RFI closed 14 August; recommendations are expected around 13 September, and Phase 2 third-party assessments stay suspended — but NIST SP 800-171 self-assessments and annual affirmations remain mandatory. Separately, CISA now targets September 2026 for the CIRCIA final rule (72-hour incident / 24-hour ransom-payment reporting).

Deadline Alert

China Order No. 24 — 20 August 2026 (3 days). Important-data processors must have an annual network-data-security risk-assessment procedure in place.

One Thing to Do Today

If your organisation processes "important data" in China, stand up — or document — an annual network-data-security risk-assessment procedure before Thursday 20 August, referencing GB/T 45577-2025.

Tomorrow's Focus

Privacy & personal data protection — the week's privacy-regulation movements and enforcement.

CyberEyeQ — Actionable Regulatory Intelligence. Questions or feedback: [email protected]