Complying with government regulation is not really in the same class of issues.
A job well done!
I am referring mainly to the media hype and how it becomes the issue de jure and then ceases to matter. The media jumps on it and amplifies anyone who chimes or confirms the fear. Why? So they can run a 'if it bleeds it leads' type headline. While there could have been stories after the fact of problems for unpatched systems I don't remember any of those stories. And it is not because everyone patched their systems either.
I mean there were posts online about GDPR where some small insignificant company just folded up for fear of what would happen as if the EU was really going to go after that type of target. Anyone who has been in business for a long time knows that is not what is ever done.
To your point you are right because this isn't even (for US companies) a US regulation and if they have no customers in the EU then it is a stretch to be concerned about it (at least relative which is my point to the attention given to it by the media).
Seriously, that is my impression of all conversations here, US companies trying to understand a law written in EU. I imagine this to be very hard.
Exactly. And that is part of my point. Everyone acting as if something dreadful would happen if the timeline was not met RIGHT AWAY!!!. It would not. The EU might bring an action after initial outreach to the companies legal department. The legal dept would do a dance and explain why they need more time. The EU would then agree to the time line. Any any case would go to some court and would also involve appeals and some form of due process. During that time lawyers would work back and forth. Any fine would almost certainty not approach the worse case scenario. Not going to happen. And certainly not to a small fish or anything close to that.