Deadlines and dates
When each obligation takes effect, with its legal source alongside. Because not every date passed around as a deadline is actually written into law.
Last updated: 05.08.2026
- Statutory deadline
- Written into the legal text.
- Transitional rule
- Applies only to legacy cases; check the scope carefully.
- Administrative grace period
- A statement about enforcement practice, not about the law.
Upcoming dates
2026
- 8 September 2026 Tuesday
DIGITAL X Cologne, isidaten on site
All three founders are on Deutsche Telekom’s partner floor: the information security, the data protection and the IT management perspective at one table.
- 11 September 2026 Friday
Cyber Resilience Act: manufacturers’ reporting obligations
Manufacturers must report actively exploited vulnerabilities and severe security incidents, simultaneously to the competent CSIRT and to ENISA. The duty applies long before the regulation takes full effect, and it covers products placed on the market before 11 December 2027.
- 12 September 2026 Saturday
Data Act: access to connected product data
Connected products placed on the market from this day must be designed so that users can access the data generated easily and, where possible, directly. Products placed on the market earlier are not covered.
- 2 December 2026 Wednesday
AI Act: marking by providers of existing systems
Providers of AI systems that generate synthetic audio, image, video or text content and placed their system on the market before 2 August 2026 must implement machine-readable marking by this date. The deadline applies to providers and their procedures, not to retroactively labelling older content.
2027
- 12 January 2027 Tuesday
Data Act: switching charges end
Providers of data processing services may no longer charge for carrying out a provider switch. Until then, reduced charges are permitted, capped at the costs actually incurred.
- 12 September 2027 Sunday
Data Act: legacy contracts for data processing services
From this day, Chapter IV also covers contracts concluded on or before 12 September 2025, provided they are open-ended or end no earlier than 11 January 2034. A good reason to search the contract register for exactly those two characteristics.
- 2 December 2027 Thursday
AI Act: high-risk obligations under Annex III
Originally set for 2 August 2026, deferred in July 2026. Eight areas are affected, among them biometrics, critical infrastructure, employment and access to essential services. The deferral is preparation time, not a pause.
- 11 December 2027 Saturday
Cyber Resilience Act applies in full
From this day, products with digital elements may only be placed on the market if they meet the essential cybersecurity requirements, including conformity assessment, CE marking and a support period for security updates.
2028
- 2 August 2028 Wednesday
AI Act: high-risk AI in regulated products
For AI systems embedded as a safety component in products under Annex I, the later date applies. This one was also deferred in July 2026, from 2027 to 2028.
How to read this list
Product-related context, not legal advice. The linked legal text always prevails. Whether an obligation applies to you depends on your sector, size and role, and no calendar can make that assessment for you.
Already passed
Kept in place, because your own chronology often matters more than the next date.
2026
- 2 August 2026
AI Act: general date of application
The transparency duties under Article 50 have applied since this day and affect almost anyone using AI in external contact: chatbot disclosure, machine-readable marking of generated content. The high-risk obligations, by contrast, were deferred shortly before.
- 31 July 2026
NIS2: end of the BSI grace period for registration
This much-quoted date was in no statute. It was a BSI grace period for outstanding registrations, that is, a statement about enforcement practice. The statutory deadline was 6 March 2026, and the actual obligations never depended on registration anyway.
- 11 June 2026
Cyber Resilience Act: chapter on notified bodies
The rules on notifying conformity assessment bodies have applied since this day. For manufacturers this is mainly a signal: the assessment infrastructure is being built now, before the product requirements bite.
- 6 March 2026
NIS2: statutory registration deadline
Registration no later than three months after first falling within scope. For everyone already covered when the implementing act entered into force, the deadline expired on this day. Registering later is not on time, it is late.
2025
- 6 December 2025
German NIS2 implementing act enters into force
Without a transition period. From this day the duties on risk management, incident reporting and evidence apply, regardless of whether a registration has taken place.
- 12 September 2025
Data Act: date of application
The regulation has applied since this day. Chapter IV on unfair contract terms covers contracts concluded after it; legacy contracts follow in September 2027.
Who tracks this at your organisation?
We maintain this list by hand. In the legal register, a source watcher does the job: it observes the official sources and reports when a new version appears.