Cybersecurity regulation stopped being aspirational years ago in some jurisdictions and became something with real deadlines and real penalties. Four regimes now cover most companies doing business with the EU, the US public markets, or federally regulated Canadian sectors — and each has its own clock.
EU: NIS2 is already law
The NIS2 Directive entered into force in January 2023 and required EU member states to transpose it into national law by 17 October 2024, repealing the original 2016 NIS directive the following day. NIS2 expands coverage from the original directive’s sectors to 18 total, adding public electronic communications providers, social media platforms, waste management, postal and courier services, space, and public administration bodies alongside the original energy, transport, health, water, finance and digital infrastructure sectors. Under Article 23, covered entities that suffer a significant incident must submit an early warning to their national CSIRT within 24 hours, a fuller incident notification within 72 hours, and a final report within one month.
Transposition has not been uniform. As of a July 2026 European Commission action, Ireland, Spain, France and the Netherlands were referred to the Court of Justice of the EU for failing to notify the Commission of national measures transposing NIS2 — meaning companies operating in those markets should confirm with local counsel exactly which national implementing rules currently apply, rather than assume the EU-wide deadline settled the matter everywhere at once.
EU: the Cyber Resilience Act’s reporting deadline
The Cyber Resilience Act (CRA) entered into force on 10 December 2024 and applies to virtually all hardware and software products sold into the EU with a digital element. Its obligations phase in on a staggered schedule: reporting duties under Article 14 take effect on 11 September 2026, while the bulk of the Act’s substantive requirements — secure-by-design obligations, vulnerability handling, conformity assessment — become enforceable on 11 December 2027.
Article 14 sets out two reporting tracks, both routed through the ENISA Single Reporting Platform to ENISA and the relevant national CSIRT simultaneously. For an actively exploited vulnerability, manufacturers must send an early warning within 24 hours of becoming aware, a more detailed notification within 72 hours, and a final report within 14 days of a fix becoming available. For a severe incident affecting product security, the same 24-hour and 72-hour windows apply, followed by a final report within one month.
United States: a year of SEC 8-K filings
The SEC’s cybersecurity disclosure rule took effect in December 2023, with the Item 1.05 material-incident disclosure requirement on Form 8-K applying to filings from mid-December 2023 onward and taking full effect for smaller reporting companies in 2024. The rule requires public companies to disclose a cybersecurity incident within four business days of determining it is material, describing its nature, scope and likely financial impact, with a narrow exception allowing delay when the US Attorney General determines immediate disclosure poses a national security risk.
Law firm tracking of filings shows the rule is being used unevenly: through February 2025, 41 companies had disclosed cybersecurity incidents via Form 8-K, but only 15 of those used the mandatory Item 1.05 materiality pathway, while 26 opted for the voluntary, non-material Item 8.01 disclosure instead — a pattern that followed SEC staff guidance in May 2024 clarifying that Item 1.05 filings should be reserved specifically for incidents a company has determined to be material, not used as a general breach-notification vehicle.
Canada: Bill C-26 died, Bill C-8 has replaced it
Canada’s attempt at a federal cybersecurity law for critical infrastructure has had a longer road. Bill C-26, which would have created the Critical Cyber Systems Protection Act covering telecommunications, finance, energy and transport operators, passed the House of Commons in June 2024 and cleared Senate third reading in December 2024. It never became law: a drafting conflict with a separate foreign-interference bill required last-minute Senate amendments, and Parliament’s prorogation ahead of the 2025 federal election killed the bill before royal assent.
The newly elected government under Prime Minister Mark Carney reintroduced substantially the same framework as Bill C-8 on 18 June 2025. As of early 2026, C-8 remains under review by the House of Commons Standing Committee on Public Safety and National Security, meaning federally regulated operators in telecom, finance, energy and transport are not yet subject to a binding Canadian equivalent of the EU’s incident-reporting regime — though the bill’s structure, mandatory incident reporting to a federal cyber authority and ministerial directive powers over designated operators, closely mirrors what NIS2 already requires in Europe. Canadian organizations with EU operations or supply-chain exposure are, in practice, already subject to comparable obligations under NIS2 even while C-8 awaits passage at home.
What this means for compliance planning
- EU-facing manufacturers of connected products have a firm deadline of 11 September 2026 for CRA vulnerability and incident reporting.
- Organizations already covered by NIS2 should confirm their specific national transposition law, given the Commission’s ongoing enforcement action against four member states.
- US public companies should treat the Item 1.05/Item 8.01 distinction as a materiality judgment, not a formality — the four-business-day clock only starts once materiality is determined.
- Canadian federally regulated operators should track Bill C-8’s committee progress; no binding federal incident-reporting mandate is yet in force.
Sources
- European Commission: NIS2 Directive
- European Commission: Cyber Resilience Act
- Crowell & Moring: CRA reporting deadline countdown
- Greenberg Traurig: SEC Cybersecurity Disclosure Trends, 2025 Update
- Parliament of Canada: LEGISinfo, Bill C-26 history
- SecurityBrief Canada: From Bill C-26 to C-8

