N
Nest Compliance Framework Watcher
6 sources monitored
1 change detected
last scan Aug 30, 2026 · 06:02 AM ET

Frameworks monitored

Six regulatory frameworks this practice's clients are subject to, checked against their source regulator on a daily scan.

Framework Source monitored Last checked Last known change Status
CCPA / CPRA California cppa.ca.govCalifornia Privacy Protection Agency 06:02 AM ETAug 30, 2026 Sep 23, 2025new filing regime approved ● Changed View alert →
NY DFS 23 NYCRR 500 New York dfs.ny.govNY Dept. of Financial Services 06:00 AM ETAug 30, 2026 Nov 1, 20232nd Amendment (phase-in closed Nov 1, 2025) ● Quiet
GLBA — FTC Safeguards Rule Federal ftc.govFederal Trade Commission 06:00 AM ETAug 30, 2026 May 13, 2024breach-notice duty took effect ● Quiet
PCI DSS Payment card industry pcisecuritystandards.orgPCI Security Standards Council 06:01 AM ETAug 30, 2026 Mar 31, 2025v4.0 new requirements became mandatory ● Quiet
HIPAA Security Rule Federal · health data hhs.govU.S. Dept. of Health & Human Services 06:01 AM ETAug 30, 2026 Unchanged since 2013overhaul proposed (NPRM), not yet final ● Quiet
GDPR European Union gdpr-info.euEU regulation text, Arts. 30 & 35 06:01 AM ETAug 30, 2026 Unchanged since 2018EU simplification proposal not yet in force ● Quiet

Next scheduled scan: Aug 31, 2026 · 06:00 AM ET

● Alert New filing regime

CCPA / CPRA — California

Detected in today's scan · Aug 30, 2026, 06:02 AM ET

What moved

On September 23, 2025, the California Office of Administrative Law approved final CPPA regulations creating an entirely new cybersecurity-audit and risk-assessment filing regime — one that did not exist before this ruling. It phases in through 2030.

  • Dec 31, 2027 initial risk assessments due
  • Apr 1, 2028 risk-assessment attestation due to CPPA
  • Apr 1, 2028 first cybersecurity-audit certifications due (earliest tier)
  • → 2030 full phase-in across all revenue tiers
cppa.ca.gov/announcements/2025/20250923.html ↗

Which client

⚠ SAMPLE DATA — illustrative placeholder, not an actual client
Client B
Healthcare SaaS California

Flagged because this client processes California consumer data and falls within scope of the new CPPA filing regime.

What to do next

  1. 1 Confirm Client B's annual gross revenue to fix the exact phase-in deadline — over $100M → Apr 1, 2028, $50–100M → Apr 1, 2029, under $50M → Apr 1, 2030.
  2. 2 Start the risk-assessment track now — initial assessments for ongoing high-risk processing are due to the CPPA by December 31, 2027, regardless of revenue tier.
  3. 3 Decide who performs the cybersecurity audit — the regulation calls for independence, so confirm now whether that's in-house separation or a third-party auditor before the 2027–2028 runway gets tight.
  4. 4 Brief Client B that this is a brand-new obligation — nothing like it existed before September 23, 2025, so there's no prior-year filing to point to.
Source: California Privacy Protection Agency · regulations approved 2025-09-23 ↗