This website uses cookies

Read our Privacy policy and Terms of use for more information.

Two Regimes, One Date: 11 September

Twelve developments across eight jurisdictions this week — but one date organizes all of it. On 11 September, the EU's Cyber Resilience Act reporting duty and South Korea's rewritten privacy law both switch on. That's eight days out.

At a Glance

  • CRA reporting goes live — from 11 Sep, EU makers of products with digital elements must report actively exploited vulnerabilities to ENISA within 24 hours.

  • Korea's 10% fines land — the amended PIPA takes effect 11 Sep with turnover-based penalties and statutory CEO accountability.

  • Fed AML comment closes — the Federal Reserve's AML/CFT program rule (Docket R-1835) closes for comment 8 Sep.

  • China's PI-processor draft — the CAC Large Personal Information Processor consolidated draft closes for comment 7 Sep.

  • CalPrivacy fines a data broker — SalesIntel hit with $36,400; a new advisory warns of $200/day for inaccurate registrations.

  • CISA flags seven exploited bugs — new KEV entries start risk-based federal remediation clocks under BOD 26-04.

Critical Actions

  1. Stand up your CRA Article 14 reporting workflow — live 11 September. Manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA's Single Reporting Platform and their national CSIRT on a staged clock: 24-hour early warning, 72-hour technical notification, 14-day final report. It covers products already on the market. Action: Name who files, test Single Reporting Platform access, and pre-draft your 24/72-hour templates now. European Commission — CRA reporting

  2. Assign CEO-level PIPA accountability — effective 11 September. South Korea's amended Personal Information Protection Act adds a punitive tier of up to 10% of total annual turnover for the worst conduct, on top of the 3% baseline, and attaches personal supervisory liability to the CEO. Action: Confirm in writing who holds CEO-level accountability and document privacy-program investment, which can mitigate penalties. IAPP analysis (PIPC is the issuing authority)

  3. File on the Fed's AML/CFT program rule by 8 September. The Federal Reserve Board's proposed rule requiring supervised banks to maintain effective, risk-based AML/CFT programs (Docket R-1835, published 9 July 2026) closes for comment 8 Sep. Action: Submit comments if affected and map your BSA program to the standard. Federal Register

Enforcement Watch

  • CalPrivacy — SalesIntel Research, Inc., $36,400. On 1 Sep the California Privacy Protection Agency fined the Virginia data broker for missing the 2025 Data Broker Registry deadline and ordered it onto the DROP deletion platform. On 3 Sep it issued Enforcement Advisory 2026-01, warning of a $200/day fine for inaccurate registrations. CalPrivacy

  • Ofcom — provider of fapello.com, £200/day accruing. The UK regulator's Online Safety Act penalty against the site's provider continues to accrue toward its 7 September stop-date for failing to use age assurance. Ofcom

  • CISA — seven new exploited vulnerabilities. On 2 Sep CISA added seven actively exploited CVEs to its Known Exploited Vulnerabilities Catalog, setting BOD 26-04 remediation clocks for federal agencies. CISA

Deadline Watch

  • 7 Sep — CAC Large Personal Information Processor draft comments close (China).

  • 8 Sep — Federal Reserve AML/CFT program NPRM (R-1835) comments close (US Federal).

  • 11 Sep — EU CRA Article 14 reporting goes live (European Union).

  • 11 Sep — South Korea PIPA overhaul takes effect: 10% fines, CEO liability.

  • 16 Sep — FDA ISH companion-diagnostic reclassification (Class III to II) effective (US Federal).

  • 30 Sep — California Governor's deadline to sign or veto the enrolled AI bills.

  • 1 Oct — Austria NISG 2026 first NIS2 deadline; FedRAMP in-process grace cutoff.

  • 3 Oct — Poland NIS2 registration; 31 Oct — Italy NIS2 basic-measures compliance.

Around the World

  • United States (California) — six tracked AI bills (SB 867, 903, 947, 951, 1050, 1119) completed the Legislature on 31 Aug; the Governor has until 30 Sep to sign or veto, while CalPrivacy's data-broker blitz continues. CA Senate Daily Summary

  • United Kingdom — Ofcom's fapello.com penalty accrues toward 7 Sep; the Cyber Security and Resilience Bill remains in House of Lords Committee Stage.

  • China — the Large PI Processor draft closes 7 Sep; the Small PI Processor measures (Order No. 25) took effect 1 Sep and are now in force. CAC

  • United States (Utah) — SB 73's age-verification trigger did not flip on 3 Sep; the state agreed to forbear against Aylo pending a court ruling, in exchange for a maintained Utah geo-block. Utah SB 73

Deep Dive

European Union · Cybersecurity

The CRA's 24-Hour Clock Starts Ticking

For years, coordinated vulnerability disclosure in Europe was a best practice — something responsible vendors did on their own timelines. On 11 September 2026, it becomes law with a stopwatch attached. Article 14 of the EU Cyber Resilience Act requires every manufacturer of a product with digital elements placed on the EU market to report an actively exploited vulnerability to ENISA and its national CSIRT within 24 hours of becoming aware of it — followed by a technical notification within 72 hours and a full report within 14 days. Crucially, this applies to products already on the market, so the installed base a company shipped years ago is now in scope.

The gap most organizations haven't closed isn't legal — it's operational. A 24-hour clock means the reporting decision can't route through a weekly triage meeting or wait for legal sign-off on a Friday. It needs a named owner, a pre-authorized decision to report, tested access to ENISA's Single Reporting Platform, and report templates drafted before the first real incident — because the clock starts when any part of the organization becomes aware, not when the security team formally opens a ticket. Here's what a defensible CRA reporting program actually needs to look like...

The analysis continues for CyberEyeQ Pro subscribers. Unlock the full deep-dive recommendations, all five weekly action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk