Cybersecurity · Industry brief
Top three stories shaping Cybersecurity today, written for someone who already works in the industry: regulation, M&A, new entrants, notable filings, and any precedent worth pulling. Cite the trade publication (e.g. trade press, government source, court docket) directly so I can follow up.
Cybersecurity · Industry brief
1 Min. Lesezeit
The U.S. Cyber Trust Mark regulation, mandated by the Federal Communications Commission for federally procured IoT devices by early 2027, is being compared to China's newly implemented Measures for the Administration of Cybersecurity Labels (effective July 1, 2025). Key differences include regulatory structure—the U.S. uses a single-agency, public-private model while China employs joint administration by the Cyberspace Administration of China, Ministry of Industry and Information Technology, and Ministry of Public Security; product scope variations with China applying to all internet-connected products via batch catalogs and the U.S. focusing on wireless consumer IoT; and enforcement approaches, with China emphasizing post-market supervision, revocation, and integration into national credit systems, while the U.S. relies on labeling authorization and FCC oversight with potential compliance hooks through federal procurement regulations. The Chinese regime uses a tiered three-star rating system with formal filing requirements and lifecycle reassessment obligations, whereas the U.S. employs a single trust mark with QR code registry access and ongoing consumer disclosure emphasis. [Source: jdsupra]
The EU Digital Omnibus amendments were formally adopted on 29 June 2026, reshaping cybersecurity and AI regulation timelines. Key enforcement deadlines include AI Act transparency obligations becoming enforceable from 2 August 2026 with penalties up to €15 million or 3% of global turnover, while high-risk AI rules shift to December 2027 and August 2028. The Cyber Resilience Act's reporting requirements for manufacturers on severe incidents and actively exploited vulnerabilities begin 11 September 2026. Separately, NIS2 and DORA already apply with further NIS2 reforms proposed for January 2026 to streamline ransomware reporting and add a single incident-reporting point. The Commission published draft AI Act high-risk classification guidelines on 19 May 2026 with final guidance expected by end of 2026, and released draft Article 50 transparency guidelines on 8 May 2026. Broader data, privacy and cybersecurity proposals remain in separate Omnibus tracks without fixed application dates, while the Digital Fitness Check is reviewing cumulative regulatory burdens across the rulebook with potential for further simplification measures. Source: Eversheds Sutherland. [Source: eversheds-su]
On June 30, 2026, New Jersey enacted legislation A5328 establishing data broker registration requirements with annual fees ranging from $5,000 to $1.5 million based on the number of New Jersey residents whose personal data is sold or licensed—significantly higher than other states' fees. The law uniquely requires registration of both data brokers and "data collectors" (businesses with direct customer relationships that sell collected data), applying broadly to SaaS providers, marketing platforms, fintech apps, and others beyond traditional data brokers. The legislation also imposes a strict prohibition on selling or licensing sensitive data (including health, financial credentials, biometric data, and children's data) with penalties of up to $50,000 per record, and requires annual reporting of breach history, opt-out mechanisms, data processors, and practices involving minors' data. Most provisions take effect immediately, though the public registry launches March 27, 2027. The law includes exemptions for GLBA-covered institutions, insurance companies, and certain data types under FCRA, GLBA, and HIPAA. Source: Troutman Pepper Locke (legal analysis). [Source: troutmanpriv]
(Yet) Another Approach to Product Cybersecurity Regulation4 hours ago ... ... enforcement role, though nominally there are testing agencies that will be stood up. ... Government filing versus registry model: China requires a formal filing ...jdsupra.com

The U.S. Cyber Trust Mark regulation, mandated by the Federal Communications Commission for federally procured IoT devices by early 2027, is being compared to China's newly implemented Measures for the Administration of Cybersecurity Labels (effective July 1, 2025). Key differences include regulatory structure—the U.S. uses a single-agency, public-private model while China employs joint administration by the Cyberspace Administration of China, Ministry of Industry and Information Technology, and Ministry of Public Security; product scope variations with China applying to all internet-connected products via batch catalogs and the U.S. focusing on wireless consumer IoT; and enforcement approaches, with China emphasizing post-market supervision, revocation, and integration into national credit systems, while the U.S. relies on labeling authorization and FCC oversight with potential compliance hooks through federal procurement regulations. The Chinese regime uses a tiered three-star rating system with formal filing requirements and lifecycle reassessment obligations, whereas the U.S. employs a single trust mark with QR code registry access and ongoing consumer disclosure emphasis.
The EU Digital Rulebook in Motion - Eversheds Sutherland18 hours ago ... Insurance Financing and Capital Markets · Insurance M&A, Reinsurance and ... Cybersecurity also has its own timeline, notably under DORA, NIS2 and the Cyber ...eversheds-sutherland.com
The EU Digital Omnibus amendments were formally adopted on 29 June 2026, reshaping cybersecurity and AI regulation timelines. Key enforcement deadlines include AI Act transparency obligations becoming enforceable from 2 August 2026 with penalties up to €15 million or 3% of global turnover, while high-risk AI rules shift to December 2027 and August 2028. The Cyber Resilience Act's reporting requirements for manufacturers on severe incidents and actively exploited vulnerabilities begin 11 September 2026. Separately, NIS2 and DORA already apply with further NIS2 reforms proposed for January 2026 to streamline ransomware reporting and add a single incident-reporting point. The Commission published draft AI Act high-risk classification guidelines on 19 May 2026 with final guidance expected by end of 2026, and released draft Article 50 transparency guidelines on 8 May 2026. Broader data, privacy and cybersecurity proposals remain in separate Omnibus tracks without fixed application dates, while the Digital Fitness Check is reviewing cumulative regulatory burdens across the rulebook with potential for further simplification measures. Source: Eversheds Sutherland.
New Jersey Enacts the Nation's Costliest Data Broker Law Yet3 hours ago ... Gene is a former regulator with two decades of experience who has overseen state privacy and cybersecurity regulation enforcement, led national, multistate ...troutmanprivacy.com

On June 30, 2026, New Jersey enacted legislation A5328 establishing data broker registration requirements with annual fees ranging from $5,000 to $1.5 million based on the number of New Jersey residents whose personal data is sold or licensed—significantly higher than other states' fees. The law uniquely requires registration of both data brokers and "data collectors" (businesses with direct customer relationships that sell collected data), applying broadly to SaaS providers, marketing platforms, fintech apps, and others beyond traditional data brokers. The legislation also imposes a strict prohibition on selling or licensing sensitive data (including health, financial credentials, biometric data, and children's data) with penalties of up to $50,000 per record, and requires annual reporting of breach history, opt-out mechanisms, data processors, and practices involving minors' data. Most provisions take effect immediately, though the public registry launches March 27, 2027. The law includes exemptions for GLBA-covered institutions, insurance companies, and certain data types under FCRA, GLBA, and HIPAA. Source: Troutman Pepper Locke (legal analysis).