The Premier League has introduced mandatory cybersecurity requirements for its clubs for the first time, with fines up to £100,000 for non-compliance starting the 2026-27 season. The framework covers backups, incident response, risk management and security assurance, rolled out in three phases through April 2029, with interim assessments due each January 10 and final assessments each April 30. Security vendors welcomed the structural shift but questioned whether the multi-year timeline and fine size are sufficient given the pace of attacks targeting clubs.

4m read timeFrom itsecurityguru.org
Post cover image

Questions this post answers

What are the new Premier League cybersecurity requirements for clubs and when do they take effect?

Starting the 2026-27 season, Premier League clubs must comply with mandatory cybersecurity standards covering backups, incident response, risk management and security assurance. Implementation is staged across three phases with deadlines in April 2027, 2028 and 2029. Clubs must submit an interim compliance assessment each January 10 and a final assessment with evidence by April 30, with non-compliant clubs facing fines up to £100,000. daily.dev surfaces developments like this for teams tracking how compliance mandates shape security roadmaps.

What happens if a Premier League club fails to meet the new cybersecurity compliance deadlines?

A club found non-compliant at the interim stage has 28 days to submit a remediation plan to the league. Enforcement sits within the Premier League's existing disciplinary framework, allowing a reprimand, a fine of up to £100,000 through summary jurisdiction, or referral to an independent commission; points deductions are not being used for cybersecurity non-compliance. Security teams weighing enforcement risk against remediation timelines can follow policy shifts like this on daily.dev.

Why are security experts criticizing the timeline of the Premier League's new cybersecurity rules?

Experts argue the phased rollout through April 2029 is too slow given how quickly clubs are being targeted, since waiting years for full compliance gives attackers multiple seasons to find the weakest link. They also note that a £100,000 fine is small relative to top clubs' revenues exceeding £600 million annually, though they praised the underlying framework of backups, incident response, risk management and recovery testing as sound foundations. daily.dev helps developers and security practitioners follow debates over whether compliance timelines actually keep pace with real threats.

121 Impressions