Regulatory trackers
What each regulator currently requires, reviewed every week, with the articles we have published on it.
Canada
United States
- NIST SP 800-63 Digital Identity Guidelines● Rev 4 Final Released July 2025
- CISA Zero Trust Maturity Model● Version 2.0 Published and In Effect
- NYDFS Cybersecurity Regulation (23 NYCRR 500)● Awaiting first review
- HIPAA Security Rule● Awaiting first review
- CCPA / CPRA Regulations● In Force; CCPA/CPRA Regulations Effective Jan 1, 2026
United Kingdom
- Data (Use and Access) Act 2025● In force; prospective provisions pending commencement
- Cyber Security and Resilience Bill● Introduced to Parliament; passed Commons committee
- UK Digital Identity and Attributes Trust Framework● v1.0 Published June 2026, Currently Certifiable
- NCSC Cyber Assessment Framework● CAF v4.0 Active, Reviewed August 2025
- FCA Operational Resilience● Fully in force; new rules from March 2027
European Union
- NIS2 Directive● In force; targeted amendments proposed Jan 2026
- DORA (Digital Operational Resilience Act)● In Force since 17 January 2025
- eIDAS 2.0 / EU Digital Identity Wallet● In Force; Wallets Required by End of 2026
- Cyber Resilience Act● In Force; Full Obligations Apply Dec 2027
- EU AI Act● Fully In Effect as of 2 August 2026