Today's Focus: Cybersecurity, Data Security & Cloud Security
It's an EU cyber super-week. Three hard dates land in the next 72 hours — and the through-line is the Cyber Resilience Act.
Today's Top Story: EU Cyber Resilience Act hits its first hard deadline
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) reaches its first operative milestone this Thursday: Member States must designate conformity-assessment bodies by 11 June 2026 (3 days). That sets up the bigger date — from 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents on a 24-hour early warning / 72-hour notification / 14-day final report clock, filed once via the CRA Single Reporting Platform to their lead CSIRT and shared with ENISA. The Act's main secure-by-design and CE-marking obligations follow on 11 December 2027. Cloud-connected and SaaS products are in scope where they carry digital elements. European Commission — CRA reporting
Also Today
EU cybersecurity package goes to TTE Council. Telecoms ministers review the Commission's cybersecurity package at the Transport, Telecommunications and Energy Council on 9 June (1 day) — covering a revision of the EU Cybersecurity Act (Reg (EU) 2019/881), ICT supply-chain security, a stronger ENISA mandate, and NIS2 simplification. Watch the agreed negotiating direction, and whether certification-scheme simplification touches your EUCC/EUCS work. European Commission
UK Cyber Security and Resilience Bill reaches its final Commons stages. Report stage and third reading are scheduled for 10 June (2 days). The Bill expands the NIS Regulations 2018 — pulling in managed service providers and data centres, tightening reporting, and adding a two-tier penalty regime. Track any government amendments to scope or penalties. GOV.UK
US CIRCIA final rule still pending; town hall 18 June. CISA's CIRCIA rule slipped from October 2025 to May 2026 and remains unpublished; a critical-infrastructure-sector town hall is set for 18 June (10 days). As proposed, 16 sectors and an estimated 300,000+ entities would report covered incidents within 72 hours and ransom payments within 24 hours. CISA — CIRCIA
Cloud: FedRAMP consolidates, Brussels goes sovereign. FedRAMP's Consolidated Rules for 2026 (CR26) finalize by end of June and take effect 1 July, collapsing authorizations into a single "FedRAMP Certified" label (in force through 31 Dec 2028). In parallel, the European Commission tabled the Cloud and AI Development Act (CADA) on 3 June — a four-level cloud/AI sovereignty framework for public-sector procurement, plus a goal to triple EU data-centre capacity. FedRAMP · EC — CADA
⏰ Deadline Alert (next 14 days)
9 June — EU cybersecurity package at TTE Council
10 June — UK CSR Bill: Commons report stage & third reading
11 June — EU CRA: conformity-assessment-body designation
18 June — US CIRCIA rulemaking town hall (critical infrastructure)
One Thing to Do Today
If you ship products with digital elements into the EU, map your CRA incident-reporting workflow — 24h early warning, 72h notification, 14-day final report — to the Single Reporting Platform now. The 11 September 2026 start date arrives faster than a reporting runbook gets built.
Tomorrow's Focus
Privacy & personal data protection.
CyberEyeQ — Actionable Regulatory Intelligence. Questions or feedback: [email protected]