Two of the year's most consequential regimes switch on the same day — 11 September, eight days out. This week's episode walks through what changes and when, drawn from the same primary-source research behind the CyberEyeQ Weekly briefing.
This Week's Top Stories
1. EU Cyber Resilience Act reporting goes live 11 September. Manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities to ENISA on a staged clock — early warning within 24 hours, technical notification within 72 hours, final report within 14 days — covering products already on the market. European Commission · ENISA SRP · CRITICAL · Due 11 Sep.
2. South Korea's amended PIPA brings up-to-10% turnover fines and CEO liability 11 September. Signed 10 March 2026, the overhaul adds an aggravated penalty tier of up to 10% of total turnover for severe or repeat violations atop the 3% baseline, plus personal supervisory liability for the CEO. IAPP (PIPC is issuing authority) · CRITICAL · Due 11 Sep.
3. Federal Reserve AML/CFT program NPRM closes for comment 8 September. Docket R-1835 requires supervised banks to maintain effective, risk-based, reasonably designed AML/CFT programs. Federal Register · HIGH · Due 8 Sep.
4. China's CAC Large Personal Information Processor draft closes for comment 7 September. The consolidated draft sets baseline duties for large-scale processors. CAC · HIGH · Due 7 Sep.
5. CalPrivacy fines data broker SalesIntel $36,400. The California Privacy Protection Agency penalized the Virginia broker for missing the 2025 Data Broker Registry deadline and ordered it onto the DROP platform; Enforcement Advisory 2026-01 warns of $200/day for inaccurate registrations. CalPrivacy · MEDIUM.
6. CISA adds seven actively-exploited CVEs to the KEV catalog. The 2 September additions start risk-based federal remediation clocks under BOD 26-04. CISA · HIGH.
Compliance Action Items
By 7 Sep — Submit comments on China's CAC Large PI Processor draft if in scope.
By 8 Sep — File comments on the Fed's AML/CFT NPRM (R-1835), or begin aligning your BSA program to the standard.
By 11 Sep — Stand up your CRA Article 14 reporting workflow: name the filer, test ENISA SRP access, pre-draft 24h/72h templates.
By 11 Sep — Confirm in writing who holds CEO-level PIPA accountability and document privacy-program investment.
Now — Check the seven new CISA KEV entries against your estate and prioritize remediation.
For the full brief with every source, read the CyberEyeQ Weekly newsletter. This podcast is generated from the same primary-source research.