Compliance calendar

Deadlines and dates

When each obligation takes effect, with its legal source alongside. Because not every date passed around as a deadline is actually written into law.

Last updated: 05.08.2026

Statutory deadline
Written into the legal text.
Transitional rule
Applies only to legacy cases; check the scope carefully.
Administrative grace period
A statement about enforcement practice, not about the law.

Upcoming dates

2026

  1. 8 September 2026 Tuesday
    Event We will be there

    DIGITAL X Cologne, isidaten on site

    All three founders are on Deutsche Telekom’s partner floor: the information security, the data protection and the IT management perspective at one table.

    Rheinauhafen, Cologne

  2. 11 September 2026 Friday
    Statutory deadline

    Cyber Resilience Act: manufacturers’ reporting obligations

    Manufacturers must report actively exploited vulnerabilities and severe security incidents, simultaneously to the competent CSIRT and to ENISA. The duty applies long before the regulation takes full effect, and it covers products placed on the market before 11 December 2027.

    Legal source: Art. 14 in conjunction with Art. 71(2) Regulation (EU) 2024/2847 · EUR-Lex

  3. 12 September 2026 Saturday
    Statutory deadline

    Data Act: access to connected product data

    Connected products placed on the market from this day must be designed so that users can access the data generated easily and, where possible, directly. Products placed on the market earlier are not covered.

    Legal source: Art. 3(1) in conjunction with Art. 50 Regulation (EU) 2023/2854 · EUR-Lex

  4. 2 December 2026 Wednesday
    Transitional rule

    AI Act: marking by providers of existing systems

    Providers of AI systems that generate synthetic audio, image, video or text content and placed their system on the market before 2 August 2026 must implement machine-readable marking by this date. The deadline applies to providers and their procedures, not to retroactively labelling older content.

    Legal source: Art. 111(4) AI Act, added by Regulation (EU) 2026/1744 · EUR-Lex

2027

  1. 12 January 2027 Tuesday
    Statutory deadline

    Data Act: switching charges end

    Providers of data processing services may no longer charge for carrying out a provider switch. Until then, reduced charges are permitted, capped at the costs actually incurred.

    Legal source: Art. 29(1) Regulation (EU) 2023/2854 · EUR-Lex

  2. 12 September 2027 Sunday
    Transitional rule

    Data Act: legacy contracts for data processing services

    From this day, Chapter IV also covers contracts concluded on or before 12 September 2025, provided they are open-ended or end no earlier than 11 January 2034. A good reason to search the contract register for exactly those two characteristics.

    Legal source: Art. 50 Regulation (EU) 2023/2854 · EUR-Lex

  3. 2 December 2027 Thursday
    Statutory deadline

    AI Act: high-risk obligations under Annex III

    Originally set for 2 August 2026, deferred in July 2026. Eight areas are affected, among them biometrics, critical infrastructure, employment and access to essential services. The deferral is preparation time, not a pause.

    Legal source: Art. 113 AI Act, amended by Regulation (EU) 2026/1744 · EUR-Lex

  4. 11 December 2027 Saturday
    Statutory deadline

    Cyber Resilience Act applies in full

    From this day, products with digital elements may only be placed on the market if they meet the essential cybersecurity requirements, including conformity assessment, CE marking and a support period for security updates.

    Legal source: Art. 71(2) Regulation (EU) 2024/2847 · EUR-Lex

2028

  1. 2 August 2028 Wednesday
    Statutory deadline

    AI Act: high-risk AI in regulated products

    For AI systems embedded as a safety component in products under Annex I, the later date applies. This one was also deferred in July 2026, from 2027 to 2028.

    Legal source: Art. 113 AI Act, amended by Regulation (EU) 2026/1744 · EUR-Lex

How to read this list

Product-related context, not legal advice. The linked legal text always prevails. Whether an obligation applies to you depends on your sector, size and role, and no calendar can make that assessment for you.

Already passed

Kept in place, because your own chronology often matters more than the next date.

2026

  1. 2 August 2026
    Statutory deadline

    AI Act: general date of application

    The transparency duties under Article 50 have applied since this day and affect almost anyone using AI in external contact: chatbot disclosure, machine-readable marking of generated content. The high-risk obligations, by contrast, were deferred shortly before.

    Legal source: Art. 113 AI Act, Regulation (EU) 2024/1689 · EUR-Lex

  2. 31 July 2026
    Administrative grace period

    NIS2: end of the BSI grace period for registration

    This much-quoted date was in no statute. It was a BSI grace period for outstanding registrations, that is, a statement about enforcement practice. The statutory deadline was 6 March 2026, and the actual obligations never depended on registration anyway.

    Legal source: BSI administrative practice, not a legal provision

  3. 11 June 2026
    Statutory deadline

    Cyber Resilience Act: chapter on notified bodies

    The rules on notifying conformity assessment bodies have applied since this day. For manufacturers this is mainly a signal: the assessment infrastructure is being built now, before the product requirements bite.

    Legal source: Chapter IV (Art. 35 to 51) in conjunction with Art. 71(2) Regulation (EU) 2024/2847 · EUR-Lex

  4. 6 March 2026
    Statutory deadline

    NIS2: statutory registration deadline

    Registration no later than three months after first falling within scope. For everyone already covered when the implementing act entered into force, the deadline expired on this day. Registering later is not on time, it is late.

    Legal source: Section 33 BSIG · gesetze-im-internet.de

2025

  1. 6 December 2025
    Statutory deadline

    German NIS2 implementing act enters into force

    Without a transition period. From this day the duties on risk management, incident reporting and evidence apply, regardless of whether a registration has taken place.

    Legal source: BSIG as amended by the NIS2 implementing act · gesetze-im-internet.de

  2. 12 September 2025
    Statutory deadline

    Data Act: date of application

    The regulation has applied since this day. Chapter IV on unfair contract terms covers contracts concluded after it; legacy contracts follow in September 2027.

    Legal source: Art. 50 Regulation (EU) 2023/2854 · EUR-Lex

Who tracks this at your organisation?

We maintain this list by hand. In the legal register, a source watcher does the job: it observes the official sources and reports when a new version appears.