CyberEyeQ Daily
Actionable Regulatory Intelligence — Monday, 3 August 2026
Today's Focus: Cybersecurity, Data Security & Cloud Security
TODAY'S TOP STORY
Dutch NIS2 law is in force in 12 days — 8,000+ orgs, no grace period
The Netherlands' Cyberbeveiligingswet (Cbw), its transposition of the EU NIS2 Directive, enters into force 15 August 2026 after the Senate (Eerste Kamer) approved it on 7 July. From day one it applies in full — registration with NCSC-NL, a duty of care, incident-reporting, and board-level accountability — to more than 8,000 organisations, from municipalities and water authorities to essential and important entities. There is no transition period, and the entry-into-force lands a month after the Commission referred the Netherlands to the CJEU for late transposition. If you have a Dutch or pan-EU footprint, scope confirmation and management sign-off cannot wait.
ON THE CALENDAR THIS WEEK
Four hard gates land in the next 12 days:
3 Aug (today): FedRAMP 20x Class A pipeline opens — SOC 2 Type II or a current RAR gets you in.
10 Aug: FedRAMP temporary Rev5 paths ("Lost Sponsor," "Ready Conversion") open — use the form, not the shared inbox.
14 Aug, 12:00 pm ET: US CMMC Reform Task Force RFI closes.
15 Aug: Dutch Cyberbeveiligingswet enters into force.
ALSO TODAY
FedRAMP opens the Class A on-ramp today. The 20x Class A pipeline (Program Certification) opens 3 August — the first PMO-assessed path with no agency sponsor, replacing FedRAMP Ready. Class B and C follow 31 August. Confirm your SOC 2 Type II currency and submit early; PMO assessment capacity is finite. FedRAMP
EU Cyber Resilience Act reporting starts 11 September. Art. 14 will require manufacturers of products with digital elements to file a 24-hour early warning and 72-hour notification via ENISA's Single Reporting Platform — which is not yet live. Fines reach €15 million or 2.5% of worldwide turnover. Build a manual reporting runbook now. European Commission
China's data risk-assessment Measures take effect 20 August. Jointly issued by CAC, MIIT and MPS, they impose recurring — and in some cases reportable — security risk assessments on network-data handlers, especially "important data" and large-scale processors. Confirm whether you are in scope. Hunton
DEADLINE ALERT
≤14 days: FedRAMP Class A opens (3 Aug) · FedRAMP Rev5 temporary paths (10 Aug) · CMMC RFI closes (14 Aug) · Dutch Cbw in force (15 Aug). China Measures follow at 17 days (20 Aug); EU CRA Art. 14 at 39 days (11 Sep).
ONE THING TO DO TODAY
If you operate in the Netherlands, confirm your essential-vs-important entity status and open your NCSC-NL registration workflow today — the Cyberbeveiligingswet is in force on 15 August with immediate governance duties and no grace period.
TOMORROW'S FOCUS
Privacy — personal data protection developments and enforcement.
CyberEyeQ — Actionable Regulatory Intelligence
Questions or feedback: [email protected]