This website uses cookies

Read our Privacy policy and Terms of use for more information.

CyberEyeQ Daily

Actionable Regulatory Intelligence — Monday, 3 August 2026

Today's Focus: Cybersecurity, Data Security & Cloud Security

TODAY'S TOP STORY

Dutch NIS2 law is in force in 12 days — 8,000+ orgs, no grace period

The Netherlands' Cyberbeveiligingswet (Cbw), its transposition of the EU NIS2 Directive, enters into force 15 August 2026 after the Senate (Eerste Kamer) approved it on 7 July. From day one it applies in full — registration with NCSC-NL, a duty of care, incident-reporting, and board-level accountability — to more than 8,000 organisations, from municipalities and water authorities to essential and important entities. There is no transition period, and the entry-into-force lands a month after the Commission referred the Netherlands to the CJEU for late transposition. If you have a Dutch or pan-EU footprint, scope confirmation and management sign-off cannot wait.

ON THE CALENDAR THIS WEEK

Four hard gates land in the next 12 days:

  • 3 Aug (today): FedRAMP 20x Class A pipeline opens — SOC 2 Type II or a current RAR gets you in.

  • 10 Aug: FedRAMP temporary Rev5 paths ("Lost Sponsor," "Ready Conversion") open — use the form, not the shared inbox.

  • 14 Aug, 12:00 pm ET: US CMMC Reform Task Force RFI closes.

  • 15 Aug: Dutch Cyberbeveiligingswet enters into force.

ALSO TODAY

FedRAMP opens the Class A on-ramp today. The 20x Class A pipeline (Program Certification) opens 3 August — the first PMO-assessed path with no agency sponsor, replacing FedRAMP Ready. Class B and C follow 31 August. Confirm your SOC 2 Type II currency and submit early; PMO assessment capacity is finite. FedRAMP

EU Cyber Resilience Act reporting starts 11 September. Art. 14 will require manufacturers of products with digital elements to file a 24-hour early warning and 72-hour notification via ENISA's Single Reporting Platform — which is not yet live. Fines reach €15 million or 2.5% of worldwide turnover. Build a manual reporting runbook now. European Commission

China's data risk-assessment Measures take effect 20 August. Jointly issued by CAC, MIIT and MPS, they impose recurring — and in some cases reportable — security risk assessments on network-data handlers, especially "important data" and large-scale processors. Confirm whether you are in scope. Hunton

DEADLINE ALERT

≤14 days: FedRAMP Class A opens (3 Aug) · FedRAMP Rev5 temporary paths (10 Aug) · CMMC RFI closes (14 Aug) · Dutch Cbw in force (15 Aug). China Measures follow at 17 days (20 Aug); EU CRA Art. 14 at 39 days (11 Sep).

ONE THING TO DO TODAY

If you operate in the Netherlands, confirm your essential-vs-important entity status and open your NCSC-NL registration workflow today — the Cyberbeveiligingswet is in force on 15 August with immediate governance duties and no grace period.

TOMORROW'S FOCUS

Privacy — personal data protection developments and enforcement.

CyberEyeQ — Actionable Regulatory Intelligence

Questions or feedback: [email protected]

Keep Reading