Premier League clubs must meet the league's information security baselines in three phases by 30 April 2027, 30 April 2028 and 30 April 2029, and they must report their position twice in each season.
Deadlines and recurring submissions
Here are the deadlines for each requirement.
| Requirement | Due |
|---|---|
| Phase One of the baselines | 30 April 2027 |
| Phase Two of the baselines | 30 April 2028 |
| Phase Three of the baselines | 30 April 2029 |
| Interim assessment | 10 January in each season |
| Final assessment, with supporting evidence | 30 April in each season |
Each phase has to be in place by its own deadline and then kept in place on a continuing basis. The obligation is ongoing, not a one-off filing exercise.
The season has two reporting points. One sits in mid-season and measures how far the club complies with the baselines that apply to it at that time. The other sits at the end of the cycle and has to be backed by evidence.
What clubs must submit each season
By 10 January in each season, a club must give an interim assessment in whatever form the league requires. That submission is about the extent of compliance with the baselines that apply to the club at that stage.
By 30 April in each season, the club must give a final assessment with supporting evidence showing that it complies. The evidence requirement is attached to the final assessment itself, so a bare statement is not enough.
What happens if a club is behind
If a club is not fully compliant when the interim assessment falls due, it must provide a detailed plan within 28 days. That plan has to set out the steps the club proposes to take to reach compliance.
The league can also require further information or evidence when it reasonably considers that material necessary to monitor progress. That power is not limited to one phase and does not depend on whether the club has already filed its plan.
Dispensations and promoted clubs
A club can seek a dispensation from one or more of these requirements if it shows that exceptional circumstances make compliance impossible. The league has absolute discretion on whether to grant it, and it can attach conditions or require the club to take steps.
A promoted club that has not been a league member since the 2026/27 season still has to meet all three phases by the same deadlines. If one of those deadlines has already passed before its shares transfer, that club must comply by the next deadline instead.
FAQ
Do Premier League clubs have to follow information security rules?
Yes. The requirement is to meet the league's information security baselines and keep them in place once each phase becomes due.
That sits alongside a reporting duty in every season, so clubs are required to show where they stand rather than simply work in private.
When do clubs have to meet the baselines?
The three phases fall on separate fixed dates, ending with Phase Three on 30 April 2029. Earlier phases do not drop away once a later phase arrives.
Each one must stay in place on a continuing basis after its own deadline.
What must a club do if it is not compliant?
If full compliance is missing at the interim stage, the club has 28 days to submit a detailed plan setting out the steps it proposes to take. The club may also be asked for extra information or evidence so its progress can be monitored.
The season still ends with a final assessment that must be supported by evidence.
Do promoted clubs get extra time?
They do not get a fresh set of overall deadlines. A promoted club that has not been in the league since the 2026/27 season is still tied to the same three phase dates.
Where one of those dates has already passed before its shares transfer, compliance moves to the next deadline.

