AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

The 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About

A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.

Sam KhanSam Khan The Cyber ExpertFounder and CEODecember 28, 2026 · 6 min read

Between Christmas and New Year, with an email folder and a whiteboard

The compliance lead at a 60-person medical billing company in Kansas City comes in on the Monday after Christmas because the office is empty and the phones do not ring. She does this every year. Coffee, whiteboard, and the email folder she calls "Later", which by December holds 91 messages.

In it: two client contracts with new security exhibits, a broker's renewal questionnaire, a state attorney general newsletter, three vendor notices about product changes, and a forwarded article from the CEO with the subject line "Do we need to worry about this?" sent in August and never answered.

She writes 2027 across the top of the board and starts pulling dates out of the pile. By eleven she has fourteen. By noon she has crossed out nine of them, because they belong to industries the company is not in, or to companies with a thousand employees, or because the "deadline" in the article turned out to be a vendor's marketing date rather than a regulator's.

Five remain. Two are real and dated. Two are proposed and unfinished. One is a date somebody paused eighteen months ago and has not rescheduled.

That whiteboard is the honest version of a compliance calendar. Most published ones are longer, and most of the extra entries are noise.

What the heck does this mean

A regulatory calendar mixes four different kinds of dates, and treating them as one list is how teams waste a quarter.

An effective date is when a rule becomes law. An applicability or compliance date is when you actually have to be doing the thing, and it is often later. An annual filing date repeats forever and belongs in the calendar every year, not once. And a proposed date is a regulator's projection, useful for planning and useless for promising.

There is a fifth category worth naming: the suspended date. The Department of Defense suspended CMMC Phase 2 on 13 July 2026, while Phase 1 self-assessments, SPRS posting and DFARS 252.204-7012 with its 72-hour incident reporting all stayed in force. No new date has been published. Anyone who gives you one is selling something.

Sort your fourteen entries into those five buckets and most of the anxiety leaves the room, because you can only miss the ones with dates.

The numbers that matter

The average cost of a data breach reached USD 4.99 million in the IBM Cost of a Data Breach Report 2026, which is the number that makes a calendar exercise cheap by comparison.

Vulnerability exploitation was the initial access route in 31 percent of breaches in the Verizon 2026 Data Breach Investigations Report, and no line on any compliance calendar patches a server for you.

Third parties were involved in 48 percent of breaches in the Verizon 2026 report, up 60 percent year over year, which is why so many of the dates on your board arrived as contract exhibits from customers rather than from regulators.

What to do this week

  1. Put 1 January 2027 on the board twice. California's CCPA obligations for automated decisionmaking technology apply from that date, and so does Colorado SB 26-189. If you hold personal data on California or Colorado residents, or you run any tool that scores, screens or ranks people, January is where your year starts. (CIS 3 Data Protection)
  2. Write 15 April 2027 in ink if you hold a New York Department of Financial Services licence. The Part 500 annual certification is due 15 April every year, and the evidence for it is gathered in March, not on 14 April. (CIS 17 Incident Response Management)
  3. Mark July 2027 as a planning marker for healthcare: final action on the HIPAA Security Rule update is projected for that month. Projected is not promised, so use the time to close the gaps every version of the rule will want anyway, starting with encryption and access reviews. (CIS 3 Data Protection)
  4. If you touch criminal justice information, put 1 October 2027 down for CJIS Security Policy 6.0, where full compliance is expected. Ask your records vendor in January which version their product meets, and keep the answer in writing. (CIS 15 Service Provider Management)
  5. Add 2 December 2027 for the EU AI Act high-risk obligations, deferred to that date, if your software reaches European users. Add 31 December 2028 for the FedRAMP Rev 5 authorization sunset if you sell to federal agencies, because that one shapes a roadmap rather than a quarter. (CIS 15 Service Provider Management)
  6. Clear the entries with no date at all. PCI DSS v4.0.1 is already fully in force, so it is a control question and not a calendar question. CMMC Phase 2 has no published return date, so the calendar entry is the work that never stops: the SPRS score, the annual affirmation and 72-hour reporting. (CIS 17 Incident Response Management)

Where AccuSights fits

We do the sorting exercise with you and then do the work behind it. The assessment maps what you hold and who you sell to against the frameworks that actually apply, which you can browse on our compliance framework assessment, and produces a one-page calendar you can hand to a board. Our team implements the controls at a reasonable rate, from data loss prevention and encryption to scanning and protection of the machines that hold the data. Take the three-minute Cyber Hygiene Test, then spend 15 minutes with an engineer and cross nine entries off your own whiteboard.

Questions people ask

Which 2027 dates actually apply to a 40-person company? Usually two or three, not twelve. The test is what you hold and who you sell to: personal data on California or Colorado residents brings the 1 January 2027 obligations into view, a New York financial licence brings the 15 April certification, protected health information brings the HIPAA Security Rule work, and criminal justice data brings CJIS. Everything else on the list is somebody else's problem, and knowing which is which is the first hour of work.

Is CMMC Phase 2 coming back in 2027? No return date has been published. The Department of Defense suspended Phase 2 on 13 July 2026, and Phase 1 self-assessments, SPRS posting and DFARS 252.204-7012 with its 72-hour reporting stayed in force throughout. Plan your 2027 around the obligations that never paused, and treat the return of third-party assessment as a scheduling question rather than a compliance one.

Does a US company need to care about the EU AI Act? Only if your product or your customers reach into the EU. The high-risk obligations were deferred to 2 December 2027, which is far enough out to be a design decision rather than a scramble. If you sell software that scores, ranks or screens people and any of those people are in Europe, put it on the roadmap now, because retrofitting explainability into a shipped product is the expensive version.

A calendar tells you when somebody will ask. It does not tell you when somebody will try the door, and that is the appointment nobody publishes.

Controls this post maps to

CIS 3 Data ProtectionCIS 15 Service Provider ManagementCIS 17 Incident Response Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.