Compliance calendar

Deadlines and dates

When each obligation takes effect, with its legal source alongside. Because not every date passed around as a deadline is actually written into law.

Last updated: 10.09.2026

Statutory deadline
Written into the legal text.
Transitional rule
Applies only to legacy cases; check the scope carefully.
Administrative grace period
A statement about enforcement practice, not about the law.

Upcoming dates

2026

  1. 27 October 2026 Tuesday
    Event

    it-sa Expo&Congress, Nuremberg

    Three days until 29 October at the Nuremberg exhibition centre. This is also where the Grundschutz++ methodology is published, see the entry below.

    Nuremberg exhibition centre

    it-sa 365

  2. 27 October 2026 Tuesday
    Administrative grace period

    Grundschutz++: methodology published at it-sa

    At it-sa 2026 in Nuremberg, the BSI makes the Grundschutz++ methodology available to the community. The user catalogue replaces the IT-Grundschutz-Kompendium and sits machine-readable in the state-of-the-art library. The checklists proven with WiBA become a fixture. Not a legal date but the BSI plan.

    Legal source: BSI, Grundschutz++ milestone plan (as of 26.03.2026) · bsi.bund.de, Grundschutz++

  3. 2 December 2026 Wednesday
    Transitional rule

    AI Act: marking by providers of existing systems

    Providers of AI systems that generate synthetic audio, image, video or text content and placed their system on the market before 2 August 2026 must implement machine-readable marking by this date. The deadline applies to providers and their procedures, not to retroactively labelling older content.

    Legal source: Art. 111(4) AI Act, added by Regulation (EU) 2026/1744 · EUR-Lex

2027

  1. 1 January 2027 Friday
    Administrative grace period

    Grundschutz++ becomes certifiable

    From this day, certification applications for ISO 27001 on the basis of Grundschutz++ can be submitted, as well as for certification as GS++ consultant and GS++ audit team leader. Not a legal date but the BSI plan.

    Legal source: BSI, Grundschutz++ milestone plan (as of 26.03.2026) · bsi.bund.de, Grundschutz++

  2. 12 January 2027 Tuesday
    Statutory deadline

    Data Act: switching charges end

    Providers of data processing services may no longer charge for carrying out a provider switch. Until then, reduced charges are permitted, capped at the costs actually incurred.

    Legal source: Art. 29(1) Regulation (EU) 2023/2854 · EUR-Lex

  3. 14 January 2027 Thursday
    Statutory deadline

    Machinery Regulation: application begins, with cybersecurity requirements

    The Machinery Regulation replaces the Machinery Directive and for the first time explicitly requires protection against corruption as well as safety and reliability of control systems. For operators this is mainly a procurement question: machinery placed on the market from this day must meet the requirements and evidence them in the EU declaration of conformity.

    Legal source: Art. 54 in conjunction with Annex III section 1.1.9 Regulation (EU) 2023/1230 · EUR-Lex

  4. 26 July 2027 Monday
    Statutory deadline

    CSDDD: member state transposition deadline

    By this date member states must have transposed the EU due diligence directive into national law. The date still widely quoted is 26 July 2026: that is what the original directive said, until the "stop-the-clock" Directive (EU) 2025/794 postponed it by a year. First application for the largest group of companies moved from July 2027 to July 2028.

    Legal source: Art. 37 Dir. (EU) 2024/1760, amended by Dir. (EU) 2025/794 · EUR-Lex, Richtlinie (EU) 2025/794

  5. 12 September 2027 Sunday
    Transitional rule

    Data Act: legacy contracts for data processing services

    From this day, Chapter IV also covers contracts concluded on or before 12 September 2025, provided they are open-ended or end no earlier than 11 January 2034. A good reason to search the contract register for exactly those two characteristics.

    Legal source: Art. 50 Regulation (EU) 2023/2854 · EUR-Lex

  6. 2 December 2027 Thursday
    Statutory deadline

    AI Act: high-risk obligations under Annex III

    Originally set for 2 August 2026, deferred in July 2026. Eight areas are affected, among them biometrics, critical infrastructure, employment and access to essential services. The deferral is preparation time, not a pause.

    Legal source: Art. 113 AI Act, amended by Regulation (EU) 2026/1744 · EUR-Lex

  7. 11 December 2027 Saturday
    Statutory deadline

    Cyber Resilience Act applies in full

    From this day, products with digital elements may only be placed on the market if they meet the essential cybersecurity requirements, including conformity assessment, CE marking and a support period for security updates.

    Legal source: Art. 71(2) Regulation (EU) 2024/2847 · EUR-Lex

2028

  1. 2 August 2028 Wednesday
    Statutory deadline

    AI Act: high-risk AI in regulated products

    For AI systems embedded as a safety component in products under Annex I, the later date applies. This one was also deferred in July 2026, from 2027 to 2028.

    Legal source: Art. 113 AI Act, amended by Regulation (EU) 2026/1744 · EUR-Lex

2030

  1. 27 June 2030 Thursday
    Transitional rule

    German Accessibility Act: end of the transition period for existing products

    Until this day service providers may continue to use products they were already lawfully using before 28 June 2025. Not afterwards. Contracts for services concluded earlier also end on this day at the latest, even if they were agreed for longer. Self-service terminals have a separate limit: the end of their economic life, at most fifteen years.

    Legal source: Section 38(1) and (2) BFSG (German Accessibility Act) · Gesetze im Internet

How to read this list

Product-related context, not legal advice. The linked legal text always prevails. Whether an obligation applies to you depends on your sector, size and role, and no calendar can make that assessment for you.

Already passed

Kept in place, because your own chronology often matters more than the next date.

2026

  1. 12 September 2026
    Statutory deadline

    Data Act: access to connected product data

    Connected products placed on the market AFTER this day must be designed so that users can access the data generated by default, free of charge, machine-readable and, where possible, directly. The wording says “after 12 September 2026”, so the cut-off is the following day. Products placed on the market earlier are not covered. The pre-contractual information duty (Art. 3(2)) has applied since 12 September 2025.

    Legal source: Art. 3(1) in conjunction with Art. 50 Regulation (EU) 2023/2854 · EUR-Lex

  2. 11 September 2026
    Statutory deadline

    Cyber Resilience Act: manufacturers’ reporting obligations

    Manufacturers must report actively exploited vulnerabilities and severe security incidents, simultaneously to the competent CSIRT and to ENISA. The duty applies long before the regulation takes full effect, and it covers products placed on the market before 11 December 2027.

    Legal source: Art. 14 in conjunction with Art. 71(2) Regulation (EU) 2024/2847 · EUR-Lex

  3. 8 September 2026

    DIGITAL X Cologne, isidaten on site

    All three founders are on Deutsche Telekom’s partner floor: the information security, the data protection and the IT management perspective at one table.

  4. 2 August 2026
    Statutory deadline

    AI Act: general date of application

    The transparency duties under Article 50 have applied since this day and affect almost anyone using AI in external contact: chatbot disclosure, machine-readable marking of generated content. The high-risk obligations, by contrast, were deferred shortly before.

    Legal source: Art. 113 AI Act, Regulation (EU) 2024/1689 · EUR-Lex

  5. 31 July 2026
    Administrative grace period

    NIS2: end of the BSI grace period for registration

    This much-quoted date was in no statute. It was a BSI grace period for outstanding registrations, that is, a statement about enforcement practice. The statutory deadline was 6 March 2026, and the actual obligations never depended on registration anyway.

    Legal source: BSI administrative practice, not a legal provision

  6. 11 June 2026
    Statutory deadline

    Cyber Resilience Act: chapter on notified bodies

    The rules on notifying conformity assessment bodies have applied since this day. For manufacturers this is mainly a signal: the assessment infrastructure is being built now, before the product requirements bite.

    Legal source: Chapter IV (Art. 35 to 51) in conjunction with Art. 71(2) Regulation (EU) 2024/2847 · EUR-Lex

  7. 16 March 2026
    Statutory deadline

    German critical infrastructure umbrella act enters into force

    The first cross-sector minimum requirements for the physical protection of critical installations, transposing CER Directive (EU) 2022/2557. This entry deliberately names no follow-up deadline: the obligations do not hang on a national cut-off date but on your own registration. Registration is due at the latest three months after an installation qualifies as critical (Section 8(1)); the risk analysis under Section 12 then applies nine months, and the resilience plan and reporting duties under Sections 13, 18 and 20 ten months after registration (Section 8(7)). Incidents must be reported within 24 hours, the detailed report within one month (Section 18(1)).

    Legal source: Sections 8, 12, 13, 18 KRITISDachG · Gesetze im Internet, KRITISDachG

  8. 6 March 2026
    Statutory deadline

    NIS2: statutory registration deadline

    Registration no later than three months after first falling within scope. For everyone already covered when the implementing act entered into force, the deadline expired on this day. Registering later is not on time, it is late.

    Legal source: Section 33 BSIG · gesetze-im-internet.de

2025

  1. 6 December 2025
    Statutory deadline

    German NIS2 implementing act enters into force

    Without a transition period. From this day the duties on risk management, incident reporting and evidence apply, regardless of whether a registration has taken place.

    Legal source: BSIG as amended by the NIS2 implementing act · gesetze-im-internet.de

  2. 12 September 2025
    Statutory deadline

    Data Act: date of application

    The regulation has applied since this day. Chapter IV on unfair contract terms covers contracts concluded after it; legacy contracts follow in September 2027.

    Legal source: Art. 50 Regulation (EU) 2023/2854 · EUR-Lex

Who tracks this at your organisation?

We maintain this list by hand. In the legal register, a source watcher does the job: it observes the official sources and reports when a new version appears.