Today's Focus: Cybersecurity, Data Security & Cloud Security
Two hard deadlines land inside the next four days on opposite sides of the Atlantic: Germany's BSI treats 31 July as the point where unregistered NIS2 entities become an enforcement target, and FedRAMP's "Ready" on-ramp closes for good tomorrow. Two comment windows also close within the week.
Today's Top Story
Germany's NIS2 registration gate closes 31 July
Germany's BSI has told industry associations it will treat 31 July 2026 — four days out — as the cut-off after which unregistered entities become an enforcement priority under the NIS2 Implementation Act (BSIG, in force since December 2025). This is a leniency signal, not a statutory extension; the legal deadline was 6 March 2026, and late registration is already a fineable offence of up to €500,000, with personal liability on management bodies. Only about half of the roughly 30,000 in-scope German entities had registered by the end of May. If you operate essential or important entities in Germany, register with the BSI this week. Source
On the Calendar This Week
Four regulatory deadlines fall within the next seven days:
28 Jul (1 day) — FedRAMP "Ready" designation retires; no new Ready submissions accepted after today.
31 Jul (4 days) — Germany BSI NIS2 registration enforcement expectation.
2 Aug (6 days) — China CAC consultation on the rewritten Internet Information Service Measures closes.
3 Aug (7 days) — FedRAMP 20x Class A certification pipeline opens.
→ More on the calendar: https://cybereyeq.github.io/podcast/calendar/
Also Today
FedRAMP "Ready" retires tomorrow. From 28 July, no new FedRAMP Ready submissions are accepted; existing listings convert to "Legacy FedRAMP Ready," and Rev5 Ready holders must move to full FedRAMP Certification by the later of their next annual assessment expiry or 17 November 2026. The 20x Class A pipeline (Program Certification on a SOC 2 Type II plus 25 mandatory rules, no agency sponsor) opens 3 August. If you have a Ready-path package, submit it before end of day tomorrow. Source
China reopens its foundational internet rulebook for comment. The CAC's rewritten Measures for the Administration of Internet Information Services — a 6-chapter, 94-article overhaul of the 25-year-old original — is in second consultation, with comments due 2 August. It touches licensing, filing, security-management and data duties for providers operating in or into China. File comments if internet-service licensing scope is material to you. Source
CMMC reform RFI stays open — but keep 800-171 current. With CMMC Phase 2 suspended on 13 July pending a 60-day review, the Reform Task Force's Request for Information runs until 14 August, seeking input on cost, assessor capacity and whether commercial tools can substitute for separate assessments. The underlying NIST SP 800-171 self-assessment and DFARS 252.204-7012 duties are unchanged, so do not decommission Level 2 readiness. Source
⏰ Deadline Alert
Tomorrow (28 Jul): FedRAMP Ready retires. 4 days (31 Jul): Germany BSI NIS2 registration. 6 days (2 Aug): China CAC comments close. 7 days (3 Aug): FedRAMP 20x Class A opens.
One Thing to Do Today
If you run in-scope entities in Germany, complete your BSI NIS2 registration before 31 July — late registration is already a fineable offence and carries personal management liability.
Tomorrow's Focus
Privacy & personal data protection — enforcement actions and state-law deadlines.
CyberEyeQ — Actionable Regulatory Intelligence
Questions or feedback: [email protected]