Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Compliance Trends of 2025: What Security and Compliance Teams Need to Know Now

compliance trends

Originally published September 2025. Updated September 1, 2026 to reflect finalized rules, revised deadlines, and 2026 enforcement status for all frameworks covered below.

The compliance trends that defined 2025 did not stay in 2025. DORA took full effect in January. The EU AI Act’s first prohibitions kicked in February. The SEC cyber disclosure rule reached all public companies by mid-year. PCI DSS v4.0’s 64 future-dated requirements became mandatory in March. Each of these crossed from anticipated to enforced, and the organizations that treated them as future problems found themselves in reactive mode. This guide maps what changed in 2025, what is still unfolding, and what security and compliance teams need to do now.

Key Takeaways

  • 2025 was the year compliance frameworks moved from guidance to enforcement across encryption, AI, incident disclosure, and supply chain risk simultaneously.
  • DORA (effective January 17, 2025) and the EU AI Act (enforcement began February 2025) represent the two largest new regulatory obligations for organizations with EU exposure.
  • NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024, setting the post-quantum migration clock. RSA and ECC face deprecation around 2030 under NIST IR 8547.
  • The SEC cyber disclosure rule’s 4-business-day materiality reporting requirement is now in full effect for all public companies, making incident response plans a direct compliance artifact.
  • PCI DSS v4.0’s 64 previously future-dated requirements became mandatory on March 31, 2025, including phishing-resistant authentication, web application security testing, and prescriptive log management.
  • The proposed HIPAA Security Rule update to make encryption mandatory has not been finalized as of mid-2026. Organizations should monitor HHS rulemaking and treat ePHI encryption as an expected requirement.
  • A cryptographic inventory is the mandatory prerequisite for PQC migration, HIPAA encryption evidence, CMMC cryptographic controls, and any audit involving key management documentation.

2025 Compliance Framework Status: What Was New, What Changed, What Is Still Pending

The table below gives security and compliance teams a single reference for the major frameworks that moved in 2025 and their current enforcement status as of mid-2026:

FrameworkWhat changed in 2025Status as of mid-2026Primary audience
DORA (EU)Took full effect January 17, 2025; ICT risk management, resilience testing, third-party provisions requiredIn force; supervisory examinations underway; TLPT requirements applying to systemic firmsEU banks, insurers, investment firms, critical ICT providers
EU AI ActProhibited-AI provisions effective February 2, 2025; GPAI model rules effective August 2, 2025High-risk system requirements effective August 2, 2026; registration database openEU AI developers, deployers, importers of high-risk AI systems
PCI DSS v4.064 future-dated requirements became mandatory March 31, 2025; v3.2.1 retired March 2024In force; QSA assessments now use v4.0 exclusivelyAny organization that stores, processes, or transmits cardholder data
SEC Cyber Disclosure4-business-day material incident reporting; annual 10-K risk management disclosuresIn force for all reporting companies; enforcement actions visible in 2025 filingsUS publicly traded companies
HIPAA Security Rule (proposed)HHS proposed making encryption mandatory (no longer addressable) in January 2025Not yet finalized; NPRM comment period closed; final rule timeline uncertainUS healthcare covered entities and business associates
NIS2 (EU)Member states required to transpose by October 2024; enforcement began across EUTransposition varies by member state; enforcement active in most EU jurisdictionsEssential and important entities across 18 sectors in the EU
CIRCIA (US)CISA published proposed rules in April 2024; comment period closedFinal rule not yet published as of mid-2026; monitoring CISA timeline requiredCritical infrastructure operators in 16 CISA sectors
NIST PQC (FIPS 203/204/205)NIST finalized three PQC standards in August 2024Migration planning active; RSA/ECC deprecation targeted around 2030 under NIST IR 8547All organizations using public-key cryptography
EU Cyber Resilience Act (CRA)Adopted October 2024; applies to manufacturers and importers of digital productsFull enforcement by end of 2027; CE marking requirements for connected productsManufacturers, importers, distributors of software and IoT products in the EU
Framework status as of September 2026. Always verify current enforcement status with primary regulatory sources before making compliance decisions.

What Did Global Data Protection Regulation Look Like in 2025?

As of 2025, 144 countries had established data protection or consumer privacy laws, covering roughly 79 to 82% of the world’s population. In the United States, 21 states had passed comprehensive consumer privacy statutes by year end 2025, up from 13 at the start of the year. Eight new state laws took effect in 2025 alone, including Delaware, Iowa, Nebraska, and New Hampshire (all January 1), followed by Tennessee, Indiana, Montana, Oregon, and Texas later in the year.

The EU’s General Data Protection Regulation (GDPR) remained the global benchmark. EU regulators issued approximately EUR 1.2 billion in fines in 2024 for GDPR violations, demonstrating that enforcement has teeth even as discussions continued on simplifying compliance for SMEs. Outside Europe, India’s Digital Personal Data Protection Act (enacted 2023) moved toward implementation, and Brazil, South Korea, and Kenya all had updated or newly active data protection statutes in 2025.

The U.S. still lacks a single federal privacy law. The American Data Privacy and Protection Act (ADPPA) stalled without passing, though it signaled bipartisan interest in data minimization, consent requirements, and private rights of action. The practical implication for organizations operating in the U.S. remains a patchwork of state requirements that must be tracked individually, with California’s CCPA/CPRA as the most demanding baseline.

For organizations operating internationally, the EU-U.S. Data Privacy Framework (agreed in 2023) provides the current legal mechanism for transatlantic data transfers following the invalidation of Privacy Shield. That framework remains in effect as of mid-2026, though it continues to face legal challenges in European courts.

What Did Encryption and Cryptographic Compliance Require in 2025?

Encryption moved from a best-practice recommendation to an explicit compliance requirement across multiple frameworks in 2025. GDPR had always cited encryption as a recommended safeguard that could avoid breach notification obligations. In 2025, frameworks went further. The EU’s NIS2 Directive lists policies for the use of cryptography and encryption as a required security measure for essential and important entities. PCI DSS v4.0 mandates AES-256 or equivalent for cardholder data at rest and TLS 1.2 minimum (TLS 1.3 preferred) for data in transit. The proposed HIPAA Security Rule update would make encryption of electronic protected health information (ePHI) a required specification rather than an addressable one.

The post-quantum dimension added urgency. NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024. NIST IR 8547 guidance points toward deprecating RSA and ECC around 2030. The harvest-now-decrypt-later threat means organizations storing long-lived sensitive data already face exposure even before quantum computers capable of breaking RSA are available. Federal agencies under NSM-10 had active obligations to inventory cryptographic systems and develop migration plans. Private sector organizations under CMMC, FedRAMP, and DORA face the same migration window.

Tailored Advisory Services

We assess, strategize & implement encryption strategies and solutions customized to your requirements.

Key Findings from the 2025 Encryption Trends Data

  • Encryption adoption at record levels: Enterprise deployment of encryption surged in 2025, with more organizations applying it consistently across databases, applications, and cloud services. The Ponemon Institute’s 2025 study noted the largest single-year increase in enterprise encryption deployment in over a decade. Key management remained the primary operational challenge, specifically managing key sprawl across hybrid cloud environments and producing key custody documentation for auditors.
  • BYOK and HYOK for data sovereignty: With 76% of enterprises using multiple public cloud providers, organizations increasingly asserted control through Bring Your Own Key (BYOK) and Hold Your Own Key (HYOK) models, where the enterprise retains custody of the key encryption key rather than delegating it to the cloud provider. This approach directly addresses the data sovereignty requirements of GDPR, DORA, and EU data transfer rules. For a detailed breakdown of these models, see our guide to retaining control of encryption keys in the cloud.
  • PQC prototyping underway: Approximately 57 to 60% of organizations reported evaluating or prototyping NIST PQC algorithms in 2025. Nearly half were assessing their cryptographic inventory to identify where upgrades would be required. The practical bottleneck is that you cannot migrate cryptographic material you cannot see, making a complete cryptographic inventory via CBOM Secure the required first step before any PQC migration planning.
  • Crypto agility as a compliance capability: Approximately 45% of organizations reported prioritizing crypto agility, the organizational ability to swap cryptographic algorithms and keys without re-architecting applications, as a strategic goal. Regulators and auditors in 2026 are beginning to ask directly whether an organization can demonstrate this capability as part of PQC readiness assessments.

Audit-Ready Cryptographic Compliance Checklist

The following checklist maps the most commonly audited cryptographic controls to their framework requirements and evidence artifacts:

ControlFramework requirementEvidence artifactOwner
Encrypt data at rest (AES-256 or equivalent)PCI DSS v4.0 Req 3.5; HIPAA Security Rule (proposed); NIS2 Article 21Encryption policy; configuration evidence from database/storage systemsInfrastructure / Security Engineering
Encrypt data in transit (TLS 1.2 minimum)PCI DSS v4.0 Req 4.2.1; NIST SP 800-52 Rev 2; NIS2TLS configuration reports; vulnerability scan results showing no TLS 1.0/1.1Network / Application Engineering
Cryptographic key inventory documentedCMMC 3.13.10; DORA Art. 9; NIST CSF PR.DS-2Key management register or CBOM; HSM partition inventorySecurity / Cryptography Team
Key rotation policy enforcedPCI DSS v4.0 Req 3.7; NIST SP 800-57; ISO 27001 A.10.1Key rotation logs; rotation schedule documented in key management policySecurity Engineering
FIPS 140-2/140-3 validated modules in useFIPS 140-3 (mandatory for US federal); CMMC; FedRAMPNIST CMVP certificate numbers for HSMs in use; CMVP validation status verifiedInfrastructure
PQC migration inventory completedNSM-10 (US federal); NIST IR 8547; DORA (algorithmic risk)Cryptographic Bill of Materials (CBOM) identifying all RSA/ECC key usesSecurity Architecture
No deprecated algorithms in production (MD5, SHA-1, DES, RC4)PCI DSS v4.0; NIST SP 800-131A; FIPS 186-5Vulnerability scan or cryptographic discovery output confirming no deprecated algorithm useSecurity Engineering

What Did AI Governance Requirements Look Like in 2025?

The EU AI Act (Regulation EU 2024/1689) became the world’s first comprehensive AI law to move from adoption to enforcement in 2025. Its phased timeline is important to understand precisely, because the most demanding requirements are still coming:

  1. February 2, 2025: Prohibitions on unacceptable-risk AI took effect. Banned uses include real-time biometric surveillance in publicly accessible spaces (with narrow law enforcement exceptions), AI systems that exploit psychological vulnerabilities, social scoring systems, and certain predictive policing applications.
  2. August 2, 2025: General-purpose AI (GPAI) model transparency obligations began. Providers of GPAI models must document training data, provide technical documentation, and comply with EU copyright law. Providers of GPAI models with systemic risk (above a defined compute threshold) face additional adversarial testing requirements.
  3. August 2, 2026: Full obligations for high-risk AI systems take effect. High-risk uses include AI in critical infrastructure management, employment and worker management decisions, credit scoring, biometric categorization, and AI components in medical devices or vehicles. These systems require conformity assessments, registration in the EU AI database, human oversight mechanisms, and post-market monitoring.

In the United States, no comprehensive federal AI law passed in 2025. The Federal Trade Commission (FTC) used existing consumer protection authority to address AI-related deception and discrimination. The Equal Employment Opportunity Commission (EEOC) continued enforcement posture on AI hiring tools with discriminatory disparate impact. At the state level, Colorado’s AI law and Illinois’ AI Video Interview Act added state-level AI compliance obligations that vary by sector and use case. The TAKE IT DOWN Act, targeting non-consensual intimate images generated by AI, was signed into law in 2025.

The practical compliance action for organizations using AI systems: classify every AI system in use against the EU AI Act risk tiers now, before August 2026, if the organization has any EU exposure. The Compliance Advisory team at Encryption Consulting can support AI risk classification exercises as part of broader Compliance Advisory engagements.

What Did Cybersecurity Disclosure and Incident Reporting Require in 2025?

Mandatory incident disclosure became a firm legal obligation for the largest category of organizations in 2025. Two frameworks drove most of the compliance activity:

SEC cyber disclosure rule: The Securities and Exchange Commission’s cybersecurity disclosure rule required publicly traded companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining that an incident is material. The rule also required annual Form 10-K disclosures of cyber risk management processes, board oversight arrangements, and management’s role in cybersecurity governance. Smaller reporting companies came into full compliance in 2025. By year-end 2024, 95% of S&P 500 boards had explicitly assigned cybersecurity oversight at board level, partly in response to these disclosure requirements.

CIRCIA status: The Cyber Incident Reporting for Critical Infrastructure Act of 2022 directed CISA to create mandatory 72-hour incident reporting and 24-hour ransomware payment reporting for critical infrastructure operators. CISA published a Notice of Proposed Rulemaking in April 2024. As of mid-2026, the final rule has not been published. Organizations in the 16 CISA critical infrastructure sectors should monitor CISA’s rulemaking timeline and structure incident response plans around the proposed 72-hour window regardless of when the final rule takes effect.

Additional sector-specific reporting obligations that were active in 2025 included: NYDFS Cybersecurity Regulation (72-hour notice to NYDFS for certain cyber events), OCC/FFIEC bank notification requirements (36-hour notice to banking regulators for material cyber incidents), DoD contractor incident reporting under DFARS 252.204-7012, and HIPAA breach notification (60 days for breaches affecting 500 or more individuals, with OCR enforcement active).

Tailored Advisory Services

We assess, strategize & implement encryption strategies and solutions customized to your requirements.

How to Build an Incident Response Process That Meets 2025 Disclosure Requirements

The SEC’s 4-business-day reporting clock and CIRCIA’s proposed 72-hour window are short enough that incident response process design is now a compliance function, not just a security operations function. The following numbered process maps response steps to disclosure obligations:

  1. Detect and triage (Day 0): The clock for SEC reporting starts when the organization determines an incident is material, not when the incident began. Establish clear triage criteria for what constitutes a material cyber incident, aligned to the SEC definition (a reasonable investor would consider it important). Document the triage decision with timestamps.
  2. Activate legal and compliance (Day 0-1): Legal counsel determines materiality and reporting obligations across applicable frameworks (SEC, NYDFS, HIPAA, CIRCIA, GDPR 72-hour window as applicable). Do not rely on IT alone to make this determination. Many SEC enforcement inquiries have focused on the gap between when IT knew and when leadership determined materiality.
  3. Notify regulators (Day 1-3): File Form 8-K (SEC), notify NYDFS, OCC, or sector regulator as applicable. For GDPR, notify the relevant supervisory authority within 72 hours of becoming aware of a breach if there is a risk to individuals’ rights and freedoms.
  4. Draft public and stakeholder communications (Day 2-4): Prepare investor communications aligned with the 8-K filing. Draft customer notifications if personal data is involved, per applicable breach notification laws. Coordinate legal review before any public statement.
  5. Document the response timeline (ongoing): Maintain a detailed timeline of when the organization became aware, what actions were taken, and when each notification was made. This timeline is the evidence artifact for regulatory review if the response is later scrutinized.
  6. Post-incident review and remediation (Day 30-60): Conduct a root cause analysis and document remediation steps. Update HIPAA risk assessments, DORA incident documentation, or CMMC evidence packages as applicable. File any required follow-up disclosures with regulators.

How Did Compliance Integrate with ESG and Board Governance in 2025?

In 2025, cybersecurity and data protection became explicit components of Environmental, Social, and Governance (ESG) reporting for the first time at scale. The EU’s Corporate Sustainability Reporting Directive (CSRD), effective in 2025 for large companies, required disclosures on governance and risk management that directly encompass how companies handle cybersecurity to ensure business continuity. The European Sustainability Reporting Standards (ESRS) under CSRD include business conduct disclosures that cover data security and privacy practices.

Rating agencies including MSCI and Sustainalytics incorporated data breach history and information security policy maturity into ESG scores. Nearly 79% of institutional investors surveyed in 2025 said boards should demonstrate expertise in cybersecurity and detail mitigation efforts. The SEC cyber disclosure rule’s requirement to identify which board committee is responsible for cybersecurity created direct accountability at the governance level: 77% of large U.S. companies reported cybersecurity as an explicit audit committee responsibility in 2025, up from 25% in 2019.

DORA also connects to ESG by explicitly framing operational resilience as a systemic stability issue: a financial institution that cannot maintain digital operations under stress creates risks that extend beyond its own balance sheet. The implication is that compliance programs in 2026 and beyond need to produce board-level reporting artifacts, not just technical control evidence.

What Did Supply Chain and Third-Party Compliance Require in 2025?

Supply chain security obligations moved from voluntary frameworks to enforceable requirements across multiple jurisdictions in 2025. The EU’s NIS2 Directive made comprehensive supply chain risk management mandatory for essential and important entities, requiring organizations to identify and assess cyber risks associated with every supplier and digital service provider, implement security controls based on those assessments, and monitor supplier risks on a continuous basis.

DORA imposed parallel obligations on EU financial entities for ICT third-party risk: firms must inventory critical ICT providers, assess outsourcing risks, and include contractual provisions covering security requirements, incident notification, audit rights, and exit clauses. DORA also gives regulators authority to directly oversee designated critical third-party providers (CTPPs), such as large cloud providers serving EU banks.

The EU Cyber Resilience Act (CRA), adopted in October 2024 with full enforcement by end of 2027, extends this further: manufacturers, importers, and distributors of software and hardware products with digital elements must build cybersecurity in by design, provide Software Bills of Materials (SBOMs), and maintain vulnerability disclosure programs. Any organization that sells digital products in the EU needs to be tracking CRA compliance now, even though the full enforcement date is 2027.

In the U.S., software supply chain security became an active focus following CISA’s Secure Software Development Framework (SSDF) and OMB M-22-18, which requires federal agencies and their software suppliers to attest to secure development practices. For defense contractors, CMMC Level 2 and Level 3 requirements include supply chain risk management controls.

The practical gap identified in 2025 surveys is significant: 88% of CISOs reported concern about supply chain cyber risk, but less than half of organizations monitored even 50% of their suppliers for cybersecurity issues. For organizations building third-party risk management programs to meet NIS2, DORA, or CMMC requirements, the minimum viable program includes: a vendor inventory with risk tier classification, security questionnaires for critical vendors, contractual incident notification clauses (48-hour notice is common), right-to-audit clauses, and documentation of the assessment process as audit evidence. For software supply chain visibility, SBOMs produced by CodeSign Secure provide the artifact that both DORA and the CRA require.

What Did Identity and Access Management Compliance Require in 2025?

Multifactor authentication (MFA) became a baseline requirement rather than a best practice in 2025. NIS2’s Article 21 baseline security measures explicitly list multifactor or continuous authentication as a required control. The proposed HIPAA Security Rule update would make MFA mandatory for all access to systems handling ePHI. PCI DSS v4.0 requires MFA for all non-console administrative access and all remote access to the cardholder data environment. The NYDFS Cybersecurity Regulation requires MFA for access to any nonpublic information system. Cyber insurance underwriters widely require MFA as a condition of coverage, making it both a regulatory and commercial requirement.

IAM Controls Compliance Mapping

  • Multifactor Authentication (MFA): Required under NIS2 Article 21, PCI DSS v4.0 Req 8.4, proposed HIPAA update, NYDFS Cybersecurity Regulation Section 500.12, and CMMC 3.5.3. Evidence artifact: MFA coverage report from identity provider showing all user accounts, especially privileged and remote access accounts.
  • Least privilege and role-based access control (RBAC): Required under NIS2, NIST SP 800-171 (CMMC baseline), ISO 27001 A.9.2, and PCI DSS v4.0 Req 7. Evidence artifact: quarterly user access review records; RBAC role matrix; privilege escalation logs.
  • Privileged Access Management (PAM): Required or strongly implied by NYDFS, FFIEC, CMMC 3.1.6, and NIS2 baseline controls. Evidence artifact: PAM solution deployment scope; session recording evidence; just-in-time provisioning logs for administrative accounts.
  • Network segmentation and device trust: Required under NERC CIP for electric utilities; proposed HIPAA update explicitly requires network segmentation; NIS2 baseline controls include network security monitoring. Evidence artifact: network architecture diagrams showing segmentation; firewall rule reviews; device health compliance reports from endpoint management.
  • Zero Trust architecture alignment: CISA’s Zero Trust Maturity Model provides the reference framework. DoD Zero Trust Strategy (2022) sets the target for defense networks and contractors by 2027. No single regulation mandates Zero Trust by name, but implementing its principles satisfies the specific IAM, segmentation, and monitoring controls that multiple frameworks require. Evidence artifact: Zero Trust maturity assessment against CISA model; documentation of identity verification, device verification, and micro-segmentation implementation.

Industry-Specific Compliance Challenges in 2025

Financial Services

DORA was the defining compliance event for EU financial services in 2025. Banks, insurers, and investment firms were required to have their ICT risk management frameworks, incident reporting procedures, third-party risk programs, and resilience testing in place by January 17, 2025. The most demanding DORA obligation for systemic institutions is Threat-Led Penetration Testing (TLPT), which must be conducted at minimum every three years by qualified testers using intelligence-led methodologies. DORA also requires firms to classify ICT incidents using defined criteria and report them to their financial supervisor within prescribed timelines: initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within one month.

In the U.S., PCI DSS v4.0’s March 2025 deadline brought 64 previously future-dated requirements into force. Key additions include: requirements for targeted risk analyses to support customized implementation of certain controls, phishing-resistant authentication methods (such as FIDO2) as a preferred alternative to traditional MFA, more prescriptive logging requirements with tamper-evident audit logs, and mandatory vulnerability management for payment page scripts.

Banking regulators in the U.S. continued requiring notification of major incidents within 36 hours (OCC, FDIC, Federal Reserve rule effective 2022). For a practical guide to DORA’s specific requirements, see our DORA compliance guide.

Healthcare

The proposed HIPAA Security Rule update (NPRM published January 2025) represents the most significant change to the rule since 2013. Key proposed changes include: making encryption of ePHI at rest and in transit a required specification (removing the addressable designation); requiring MFA for all access to systems containing ePHI; mandating annual technical security assessments; requiring asset inventory maintenance and network mapping; and mandating documented recovery plans with specific RTO and RPO targets.

As of mid-2026, the rule has not been finalized. Organizations should not assume this means no action is required. OCR’s enforcement history shows that the absence of a risk analysis, inadequate encryption, and weak access controls are the most commonly cited deficiencies in breach investigations. Treating the NPRM’s requirements as the practical standard of care is a defensible compliance posture while the rule is finalized.

The FDA’s cybersecurity requirements for medical devices (PATCH Act, enacted December 2022) remained in active effect in 2025, requiring new device submissions to include cybersecurity architecture documentation, SBOMs, post-market vulnerability monitoring plans, and coordinated vulnerability disclosure procedures. Hospitals maintaining inventories of connected devices and ensuring network segmentation for medical devices are meeting both FDA expectations and the proposed HIPAA network segmentation requirement simultaneously. For a broader view of HIPAA’s requirements, see our HIPAA education guide.

Critical Infrastructure

NIS2’s expansion of covered sectors brought many organizations into compliance scope for the first time in 2025. The directive now covers 18 sectors including energy, transport, banking, healthcare, public administration, digital infrastructure (DNS, data centers, cloud), waste management, space, and manufacturing of critical products. Essential entities (larger organizations in higher-criticality sectors) face more stringent requirements and direct supervisory oversight than important entities.

NIS2’s management accountability provision is one of its most significant changes from the original NIS1 directive: management bodies of essential entities can be held personally liable for compliance failures, and national authorities can temporarily prohibit individuals from exercising managerial responsibilities at entities that fail to comply. This creates a direct personal incentive for executives to ensure cybersecurity governance is functional, not ceremonial.

For a comprehensive breakdown of what NIS2 requires and how to build a compliant program, see our NIS2 compliance guide.

What Encryption Consulting Would Actually Recommend Based on 2025 Compliance Trends

The compliance landscape of 2025 rewarded organizations that had built audit-ready documentation practices, centralized key management visibility, and incident response processes designed around specific reporting timelines, not just general good practices. Here is what we observed distinguished organizations that navigated 2025 well from those that struggled:

Organizations that had completed a cryptographic inventory before 2025’s PQC and encryption requirements landed had a concrete starting point for migration planning and audit evidence. Those that had not faced the dual challenge of explaining their encryption posture to auditors while simultaneously trying to discover what they actually had deployed. A CBOM Secure engagement produces exactly the inventory that CMMC, DORA, and PQC migration planning require.

Organizations that had structured their incident response plans around specific regulatory timelines (4 business days for SEC, 72 hours for GDPR supervisory authorities, 36 hours for U.S. banking regulators) handled the first live test of these requirements without improvising. Those that had generic IR plans found that the materiality determination step, the cross-functional notification chain, and the regulatory filing preparation all took longer than the timeline allowed.

For organizations entering 2026 still building these foundations, the sequencing that works is: inventory first, policy second, tooling third. Buying a compliance platform before you have a documented policy and a complete asset inventory is the most common reason compliance projects stall or produce evidence packages that fail audit scrutiny.

How Encryption Consulting Can Help

Encryption Consulting is an ISO/IEC 27001:2022 and SOC 2 certified applied-cryptography and compliance advisory firm. We help organizations build the evidence packages, cryptographic controls, and governance documentation that the compliance trends of 2025 require, before the next audit or enforcement action forces the issue.

  • Compliance Advisory Services: Our structured Compliance Advisory Service maps your current state against GDPR, PCI DSS v4.0, HIPAA, NIS2, DORA, CMMC, and FedRAMP, identifies control gaps, and produces a prioritized remediation roadmap with audit-ready evidence templates. This is the right starting point for organizations that need a documented compliance posture across multiple frameworks simultaneously.
  • CBOM Secure (Cryptographic Inventory): CBOM Secure runs a discovery pass across your cloud accounts, on-premises infrastructure, and applications to produce a Cryptographic Bill of Materials (CBOM). This inventory is the prerequisite for PQC migration planning, HIPAA encryption evidence, DORA key management documentation, and CMMC cryptographic control assessments.
  • PQC Readiness and Advisory: Our PQC Readiness service and PQC Center of Excellence assess your current cryptographic exposure across every environment in scope, identify which key material and algorithms require migration before the NIST IR 8547 deprecation window, and produce a migration roadmap calibrated to your specific compliance obligations and operational timeline.
  • HSM as a Service: For organizations that need FIPS 140-3 Level 3 validated key custody to satisfy CMMC, FedRAMP, or DORA key management requirements, HSM-as-a-Service provides dedicated, compliance-grade HSM capacity without the hardware procurement and maintenance overhead of an on-premises deployment.
  • PKI as a Service: For organizations whose compliance programs require a documented, auditable certificate infrastructure for device identity, TLS, code signing, or user authentication, PKI-as-a-Service provides a fully managed CA with CP/CPS governance documentation, always-offline root CA with ceremony records, and customer-controlled key escrow, all of which are audit artifacts that NIS2, DORA, and HIPAA programs need.

Tailored Advisory Services

We assess, strategize & implement encryption strategies and solutions customized to your requirements.

Conclusion

The compliance trends of 2025 shared a common characteristic: frameworks that had been anticipated for years became enforceable realities. DORA moved from preparation to examination. The EU AI Act moved from publication to prohibition. PCI DSS v4.0’s future-dated requirements became present-dated requirements. The SEC’s cyber disclosure rule moved from proposed to enforced to scrutinized in the same calendar year.

The organizations that navigated 2025 well had two things in common: they had treated compliance deadlines as real dates rather than planning horizons, and they had built documentation practices that produced audit evidence as a byproduct of normal operations rather than as a scramble before every assessment. Those two habits are what separate organizations that find compliance manageable from those that find it perpetually reactive.

Looking into 2026 and 2027, the next wave is already visible: the EU AI Act’s high-risk system requirements take full effect in August 2026, the Cyber Resilience Act enforcement begins by 2027, and every organization using RSA or ECC is running a shorter clock toward the NIST IR 8547 deprecation window. The organizations that start the inventory, the classification, and the migration planning now will be the ones that do not have to explain to a regulator or a board why they are starting it under pressure.

Last reviewed and updated: September 1, 2026. Encryption Consulting reviews this post when major regulatory updates occur, including CIRCIA final rule publication, HIPAA Security Rule finalization, NIST IR 8547 revisions, or new EU AI Act implementing regulations. For questions about your organization’s specific compliance requirements, contact our team.

Frequently Asked Questions

What were the biggest compliance trends of 2025?

The six most consequential compliance trends of 2025 were: global data privacy laws reaching 144 countries and 21 U.S. states with comprehensive statutes; encryption moving from addressable to effectively mandatory under NIS2 and the proposed HIPAA Security Rule update; the EU AI Act’s first enforcement provisions taking effect in February 2025; SEC cyber disclosure rules requiring 4-business-day reporting for material incidents; DORA taking full effect for EU financial entities in January 2025; and post-quantum cryptography readiness becoming an active procurement requirement following NIST’s August 2024 finalization of FIPS 203, 204, and 205.

What is the NIST post-quantum cryptography deadline for organizations?

NIST IR 8547 guidance points toward deprecating RSA and ECC around 2030, with full disallowance by 2035. NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024. Federal agencies under NSM-10 are already required to inventory cryptographic systems and develop migration plans. Private sector organizations subject to DORA, CMMC, or FedRAMP face the same migration window. The practical starting point is a cryptographic inventory to identify every RSA and ECC key in scope before migration planning can begin.

When did DORA take effect and what does it require?

The EU Digital Operational Resilience Act (DORA) took full effect on January 17, 2025 for banks, insurers, investment firms, and their critical ICT third-party providers. DORA requires a documented ICT risk management framework, annual resilience testing including Threat-Led Penetration Testing (TLPT) for systemic institutions, incident reporting to financial supervisors within defined timeframes, and contractual ICT third-party risk provisions including audit rights and exit clauses. Fines for non-compliance can reach 2% of total annual worldwide turnover for financial entities.

What did the EU AI Act require in 2025?

The EU AI Act began its phased enforcement in 2025. Prohibitions on unacceptable-risk AI uses took effect on February 2, 2025. General-purpose AI model transparency obligations began August 2, 2025. High-risk AI system requirements take full effect on August 2, 2026. Organizations must classify their AI systems, conduct conformity assessments for high-risk uses, maintain technical documentation, and register systems in the EU AI database.

What did the SEC cyber disclosure rule require in 2025?

The SEC’s rule required publicly traded companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality. It also required annual Form 10-K disclosures of cybersecurity risk management processes, board oversight arrangements, and management’s governance role. All reporting companies, including smaller reporting companies, were in full compliance scope by 2025.

What is CIRCIA and when did it take effect?

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act, 2022) directs CISA to issue rules requiring critical infrastructure operators to report substantial cyber incidents within 72 hours and ransomware payments within 24 hours. CISA published a Notice of Proposed Rulemaking in April 2024. As of mid-2026, the final rule has not been published. Organizations in critical infrastructure sectors should monitor CISA’s rulemaking and structure response plans around the proposed 72-hour window.

Is encryption now mandatory under HIPAA?

As of mid-2026, the proposed January 2025 HIPAA Security Rule update that would make encryption mandatory has not been finalized. The proposal would remove the addressable designation for ePHI encryption at rest and in transit. Organizations should treat ePHI encryption as a practical compliance expectation given OCR enforcement patterns, even while the formal rule change remains pending.

What should organizations prioritize for compliance in 2026 based on 2025 trends?

Based on 2025 compliance trends, organizations should prioritize four actions in 2026: complete a cryptographic inventory to baseline all keys, certificates, and algorithms before PQC migration planning; verify EU AI Act classification for any AI systems and begin conformity assessments ahead of the August 2026 high-risk system deadline; confirm DORA compliance evidence packages if operating EU financial services, as supervisory examinations are underway; and test incident response playbooks against SEC 4-business-day and CIRCIA 72-hour reporting windows before an actual incident forces the test.