Resources
Regulatory timeline
What applies when, in date order. Every entry names its source; proposals that are not yet adopted are labelled as such rather than presented as law.
- AppliesNIS2
Transposition deadline
Member States had to apply the measures transposing the directive from 18 October 2024.
Source: Directive (EU) 2022/2555 Art 41
- AppliesNIS2 Implementing Regulation
Implementing Regulation 2024/2690 adopted
Technical and methodological requirements for DNS, cloud, data centre, CDN, managed service, marketplace, search, social platform and trust service providers.
Source: Commission Implementing Regulation (EU) 2024/2690
- AppliesDORA
DORA applies
Financial entities and their critical ICT third-party providers are under the ICT risk, incident-reporting and testing regime.
Source: Regulation (EU) 2022/2554 Art 64
- AppliesAI Act
Prohibitions and Article 4 AI literacy apply
Every provider and deployer must take measures to support the AI literacy of its staff. The Digital Omnibus rewrote the duty in July 2026 but did not delay or remove it.
Source: Regulation (EU) 2024/1689 Arts 4 and 113, as amended by Regulation (EU) 2026/1744
- AppliesAI Act
General-purpose AI obligations apply
Documentation, copyright policy and transparency duties for GPAI model providers.
Source: Regulation (EU) 2024/1689 Art 113(b)
- AppliesCyber Resilience Act
Chapter IV applies
Notification of conformity assessment bodies (Articles 35 to 51) applies ahead of the main body of the regulation.
Source: Regulation (EU) 2024/2847 Art 71(2)
- EnforcementNIS2
Commission refers four Member States to the Court of Justice
Ireland, Spain, France and the Netherlands referred over transposition. The duty on companies is live regardless.
Source: European Commission press release IP/26/1499
- AppliesCyber Resilience Act
Article 14 reporting applies
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: early warning in 24 hours, notification in 72 hours.
Source: Regulation (EU) 2024/2847 Art 71(2)
- UpcomingAI Act
Stand-alone high-risk AI (Annex III) obligations
Originally 2 August 2026. The Digital Omnibus on AI moved this to 2 December 2027; it was adopted on 8 July 2026 and has been in force since 27 July 2026.
Source: Regulation (EU) 2026/1744, amending Regulation (EU) 2024/1689 Art 113
- UpcomingCyber Resilience Act
The CRA applies in full
Essential cybersecurity requirements, conformity assessment and market surveillance for products with digital elements.
Source: Regulation (EU) 2024/2847 Art 71(2)
- UpcomingAI Act
High-risk AI embedded in products
Originally 2 August 2027. Moved by the Digital Omnibus on AI, in force since 27 July 2026.
Source: Regulation (EU) 2026/1744, amending Regulation (EU) 2024/1689 Art 113
Dates verified against the official texts in this repository's regulations folder. Where a proposal changes a date, both the original and the proposed date are shown.