Deadlines and dates
When each obligation takes effect, with its legal source alongside. Because not every date passed around as a deadline is actually written into law.
Last updated: 10.09.2026
- Statutory deadline
- Written into the legal text.
- Transitional rule
- Applies only to legacy cases; check the scope carefully.
- Administrative grace period
- A statement about enforcement practice, not about the law.
Upcoming dates
2026
- 27 October 2026 Tuesday
it-sa Expo&Congress, Nuremberg
Three days until 29 October at the Nuremberg exhibition centre. This is also where the Grundschutz++ methodology is published, see the entry below.
- 27 October 2026 Tuesday
Grundschutz++: methodology published at it-sa
At it-sa 2026 in Nuremberg, the BSI makes the Grundschutz++ methodology available to the community. The user catalogue replaces the IT-Grundschutz-Kompendium and sits machine-readable in the state-of-the-art library. The checklists proven with WiBA become a fixture. Not a legal date but the BSI plan.
- 2 December 2026 Wednesday
AI Act: marking by providers of existing systems
Providers of AI systems that generate synthetic audio, image, video or text content and placed their system on the market before 2 August 2026 must implement machine-readable marking by this date. The deadline applies to providers and their procedures, not to retroactively labelling older content.
2027
- 1 January 2027 Friday
Grundschutz++ becomes certifiable
From this day, certification applications for ISO 27001 on the basis of Grundschutz++ can be submitted, as well as for certification as GS++ consultant and GS++ audit team leader. Not a legal date but the BSI plan.
- 12 January 2027 Tuesday
Data Act: switching charges end
Providers of data processing services may no longer charge for carrying out a provider switch. Until then, reduced charges are permitted, capped at the costs actually incurred.
- 14 January 2027 Thursday
Machinery Regulation: application begins, with cybersecurity requirements
The Machinery Regulation replaces the Machinery Directive and for the first time explicitly requires protection against corruption as well as safety and reliability of control systems. For operators this is mainly a procurement question: machinery placed on the market from this day must meet the requirements and evidence them in the EU declaration of conformity.
- 26 July 2027 Monday
CSDDD: member state transposition deadline
By this date member states must have transposed the EU due diligence directive into national law. The date still widely quoted is 26 July 2026: that is what the original directive said, until the "stop-the-clock" Directive (EU) 2025/794 postponed it by a year. First application for the largest group of companies moved from July 2027 to July 2028.
- 12 September 2027 Sunday
Data Act: legacy contracts for data processing services
From this day, Chapter IV also covers contracts concluded on or before 12 September 2025, provided they are open-ended or end no earlier than 11 January 2034. A good reason to search the contract register for exactly those two characteristics.
- 2 December 2027 Thursday
AI Act: high-risk obligations under Annex III
Originally set for 2 August 2026, deferred in July 2026. Eight areas are affected, among them biometrics, critical infrastructure, employment and access to essential services. The deferral is preparation time, not a pause.
- 11 December 2027 Saturday
Cyber Resilience Act applies in full
From this day, products with digital elements may only be placed on the market if they meet the essential cybersecurity requirements, including conformity assessment, CE marking and a support period for security updates.
2028
- 2 August 2028 Wednesday
AI Act: high-risk AI in regulated products
For AI systems embedded as a safety component in products under Annex I, the later date applies. This one was also deferred in July 2026, from 2027 to 2028.
2030
- 27 June 2030 Thursday
German Accessibility Act: end of the transition period for existing products
Until this day service providers may continue to use products they were already lawfully using before 28 June 2025. Not afterwards. Contracts for services concluded earlier also end on this day at the latest, even if they were agreed for longer. Self-service terminals have a separate limit: the end of their economic life, at most fifteen years.
How to read this list
Product-related context, not legal advice. The linked legal text always prevails. Whether an obligation applies to you depends on your sector, size and role, and no calendar can make that assessment for you.
Already passed
Kept in place, because your own chronology often matters more than the next date.
2026
- 12 September 2026
Data Act: access to connected product data
Connected products placed on the market AFTER this day must be designed so that users can access the data generated by default, free of charge, machine-readable and, where possible, directly. The wording says “after 12 September 2026”, so the cut-off is the following day. Products placed on the market earlier are not covered. The pre-contractual information duty (Art. 3(2)) has applied since 12 September 2025.
- 11 September 2026
Cyber Resilience Act: manufacturers’ reporting obligations
Manufacturers must report actively exploited vulnerabilities and severe security incidents, simultaneously to the competent CSIRT and to ENISA. The duty applies long before the regulation takes full effect, and it covers products placed on the market before 11 December 2027.
- 8 September 2026
DIGITAL X Cologne, isidaten on site
All three founders are on Deutsche Telekom’s partner floor: the information security, the data protection and the IT management perspective at one table.
- 2 August 2026
AI Act: general date of application
The transparency duties under Article 50 have applied since this day and affect almost anyone using AI in external contact: chatbot disclosure, machine-readable marking of generated content. The high-risk obligations, by contrast, were deferred shortly before.
- 31 July 2026
NIS2: end of the BSI grace period for registration
This much-quoted date was in no statute. It was a BSI grace period for outstanding registrations, that is, a statement about enforcement practice. The statutory deadline was 6 March 2026, and the actual obligations never depended on registration anyway.
- 11 June 2026
Cyber Resilience Act: chapter on notified bodies
The rules on notifying conformity assessment bodies have applied since this day. For manufacturers this is mainly a signal: the assessment infrastructure is being built now, before the product requirements bite.
- 16 March 2026
German critical infrastructure umbrella act enters into force
The first cross-sector minimum requirements for the physical protection of critical installations, transposing CER Directive (EU) 2022/2557. This entry deliberately names no follow-up deadline: the obligations do not hang on a national cut-off date but on your own registration. Registration is due at the latest three months after an installation qualifies as critical (Section 8(1)); the risk analysis under Section 12 then applies nine months, and the resilience plan and reporting duties under Sections 13, 18 and 20 ten months after registration (Section 8(7)). Incidents must be reported within 24 hours, the detailed report within one month (Section 18(1)).
- 6 March 2026
NIS2: statutory registration deadline
Registration no later than three months after first falling within scope. For everyone already covered when the implementing act entered into force, the deadline expired on this day. Registering later is not on time, it is late.
2025
- 6 December 2025
German NIS2 implementing act enters into force
Without a transition period. From this day the duties on risk management, incident reporting and evidence apply, regardless of whether a registration has taken place.
- 12 September 2025
Data Act: date of application
The regulation has applied since this day. Chapter IV on unfair contract terms covers contracts concluded after it; legacy contracts follow in September 2027.
Who tracks this at your organisation?
We maintain this list by hand. In the legal register, a source watcher does the job: it observes the official sources and reports when a new version appears.