Tim McAllister / Field notes & resources

The dates do not move

The Forcing Function Calendar

Regulatory deadlines, standards transitions, and published policy milestones reshaping enterprise digital trust between 2026 and 2030.

Reviewed Quarterly review cadence

Treat adopted dates as constraints in the operating plan. Work backward to the inventory, ownership, engineering, and evidence needed to meet them. Laws and policies can be amended; the scope and status beside each date matter.

01 / Next up

The dates to plan against

Selected adopted milestones still ahead at the September 2026 review. Each applies within its stated scope.

  1. Adopted date

    EU regulation

    Cyber Resilience Act reporting begins

    Manufacturers must report actively exploited vulnerabilities and severe security incidents. Early warning is due within 24 hours of awareness; the next notification is due within 72 hours. Final reports follow separate clocks.

    Scope. CRA Article 14, for covered products with digital elements. This reporting phase precedes the main product requirements.

    The operating question

    Can the team recognize a reportable event, reach the accountable owner, and submit the early warning within 24 hours?

  2. Adopted date

    EU regulation

    Existing AI systems: content-marking transition ends

    Certain providers of synthetic-content AI systems placed on the market before 2 August 2026 must meet Article 50(2) marking requirements by this date.

    Scope. A specific transition for existing systems, rather than a new start date for all AI transparency obligations.

    The operating question

    Can your AI suppliers show how generated output remains identifiable when it leaves their application?

  3. Adopted date

    National security policy

    CNSA 2.0 enters new NSS acquisitions

    New acquisitions for U.S. National Security Systems must be CNSA 2.0 compliant unless an exception applies. Deployment requirements also depend on the relevant validation profile.

    Scope. CNSSP 15 as explained in NSA’s CNSA 2.0 FAQ, version 2.1. This is specific to National Security Systems (NSS).

    The operating question

    Does the procurement specification require the right algorithms, validation path, and upgrade capacity before the purchase is committed?

  4. Adopted date

    TLS standard

    Public TLS certificates: 100 days

    The maximum validity of newly issued public TLS certificates falls to 100 days. Domain and IP validation reuse falls to 100 days as well.

    Scope. Publicly trusted TLS server certificates; private PKI follows its own policies.

    The operating question

    What fails first when renewal frequency doubles: discovery, validation, approval, deployment, or recovery?

  5. Adopted date

    Browser policy

    Chrome-trusted issuance becomes serverAuth-only

    Subscriber certificates newly issued from the covered Chrome-trusted hierarchies must contain only serverAuth. Issuers may end dual-purpose issuance earlier.

    Scope. This changes public certificate issuance. Chrome’s root store does not perform client authentication; this is not a blanket shutdown of mTLS.

    The operating question

    Have applications using public certificates for client authentication moved to an explicitly managed client-identity trust model?

  6. Adopted date

    EU regulation

    AI Act: Annex III high-risk systems

    The amended AI Act applies high-risk rules to covered Annex III systems, including specified uses in employment, education, and other sensitive areas.

    Scope. The AI Omnibus entered into force on 27 July 2026. Classification, provider/deployer roles, and transitional provisions determine applicability.

    The operating question

    Can you connect each high-risk use case to an owner, its evidence, its human oversight, and its change controls?

  7. Adopted date

    EU regulation

    Cyber Resilience Act main requirements apply

    The CRA’s main requirements apply, including product cybersecurity, vulnerability handling, technical documentation, and conformity assessment.

    Scope. Covered products with digital elements placed on the EU market. Exclusions and rules for existing products or substantial modifications matter.

    The operating question

    Can a product team produce the required evidence from its normal development and support process?

  8. Adopted date

    EU regulation

    AI Act: high-risk AI in regulated products

    High-risk rules apply to covered AI embedded in products under the Annex I product-safety framework, on the amended timetable.

    Scope. Article 6(1) classification and the applicable product legislation determine whether a system belongs in this phase.

    The operating question

    Are AI assurance and product conformity assessment using the same release evidence and accountable owners?

  9. Adopted date

    TLS standard

    Public TLS certificates: 47 days

    New public TLS certificates have a maximum validity of 47 days. Domain and IP validation data can be reused for only 10 days.

    Scope. Issuance and validation limits in the CA/B Forum TLS Baseline Requirements.

    The operating question

    Can validation, renewal, deployment, and rollback operate as one measured service with no dependency on an individual’s calendar?

  10. Adopted date

    Federal policy

    Federal priority systems: PQC key establishment

    Executive Order 14412 sets this date for PQC key establishment in federal high-value assets and high-impact systems. OMB M-26-15 implements a phased migration; digital signatures have a separate 2031 phase.

    Scope. Federal agency systems covered by the order and OMB guidance, excluding National Security Systems. This is not an economy-wide PQC deadline.

    The operating question

    Which systems protect information that must remain confidential beyond 2030, and which dependencies set their migration lead time?

  11. Adopted date

    National security policy

    NSS: phase out equipment unable to support CNSA 2.0

    Equipment and services unable to support CNSA 2.0 must be phased out unless otherwise specified. Mandated algorithm use follows by 31 December 2031, with stated exceptions.

    Scope. U.S. National Security Systems; CNSSP 15 and applicable NSA validation profiles govern the transition.

    The operating question

    Which long-lived devices need replacement because a firmware update cannot supply the required cryptography?

02 / Already effective

The baseline has already changed

These milestones had passed by the review date. They belong in today’s controls and operating evidence.

  1. Already effective

    TLS standard

    Public TLS certificates: 200 days

    Newly issued public TLS certificates have a maximum validity of 200 days. Domain and IP validation reuse also falls to 200 days.

    Scope. CA/B Forum TLS Baseline Requirements, sections 6.3.2 and 4.2.1; publicly trusted server certificates.

    The operating question

    Can every certificate owner demonstrate a renewal that reaches the running service without manual intervention?

  2. Already effective

    Browser policy

    Chrome separates new TLS issuing hierarchies

    Newly disclosed subordinate CA certificates in Chrome-trusted hierarchies must contain only the serverAuth extended key usage. The transition has already begun.

    Scope. Chrome Root Program policy 1.8, section 1.3.2. Existing hierarchies have separate transition rules.

    The operating question

    Which client identities still depend on a CA hierarchy whose primary purpose is public website trust?

  3. Already effective

    EU regulation

    AI Act transparency obligations apply

    Article 50 transparency rules apply to covered AI interactions and generated or manipulated content, with a limited transition for certain existing systems.

    Scope. Obligations differ for providers and deployers; exceptions and the December transition must be checked for the use case.

    The operating question

    Who owns disclosure and content marking across the AI tools your organization actually uses?

03 / On the watchlist

Direction without a universal deadline

Keep these developments in the roadmap, with their uncertainty intact.

  1. Rulemaking target

    Federal procurement

    Federal contractor PQC rulemaking target

    Executive Order 14412 directs a proposed FAR rule using this compliance target for covered contractors. The order’s rulemaking instruction is not itself a universal contractor compliance clause.

    Scope. Track the FAR rule and the terms of the actual contract before treating the target as an applicable obligation.

    The operating question

    Who monitors procurement changes and turns new cryptographic requirements into supplier and contract evidence?

Draft standard transition

NIST’s PQC transition proposal

NIST IR 8547 remains an initial public draft at this review. Its proposed transition includes deprecation of specified quantum-vulnerable uses after 2030 and disallowance after 2035. Check the algorithm, security strength, and eventual final guidance; this is not a universal ban on RSA in 2030.

NIST IR 8547 draft and status

Continuing standards work

Matter releases and device trust

Matter 1.6 was released on 17 June 2026. Track specification changes against the product’s certification and support plan. A release date alone does not establish a universal migration deadline for every device.

Connectivity Standards Alliance: Matter 1.6

04 / Put it to work

Turn the date into an operating plan.

The useful deliverable is a decision with an owner, a lead time, and evidence that the change works.

  1. Confirm applicability. Identify the products, systems, markets, and contracts actually in scope.
  2. Find the dependency. Work backward through suppliers, hardware refreshes, release cycles, and validation.
  3. Assign the evidence. Name who proves that the control operates, and how that proof stays current.
  4. Rehearse the failure. Test renewal failures, incident reporting, rollback, and recovery before the deadline.