NIS2, the Cyber Resilience Act, Data Act, DSA, eIDAS, AI Act, the Digital Omnibus … – EU digital law is growing fast. This ticker bundles the key laws with their compliance deadlines and a countdown to the next obligation.
Deadlines hand-verified against EUR-Lex and updated regularly.
EU-wide cybersecurity requirements for all products with digital elements (hardware and software) across the full lifecycle – with CE marking and vulnerability reporting duties.
Governs fair access to and use of data from connected (IoT) products and related services; affects manufacturers, users and cloud providers.
The EU’s first comprehensive AI regulation with a staggered timeline. The high-risk deadlines were postponed by Digital Omnibus Regulation (EU) 2026/1744 – details in the dedicated AI roadmap.
Modernises EU product liability and, for the first time, explicitly treats software and AI systems as 'products' under strict liability.
Requires every member state to provide all citizens with a voluntary EU Digital Identity Wallet (EUDI Wallet) by the end of 2026.
EU-wide access to and exchange of electronic health data – for care (primary use) and research/innovation (secondary use).
EU-wide baseline cybersecurity standards (risk management, incident reporting, registration) for medium and large entities across 18 critical and important sectors.
Germany: the transposition law (NIS2UmsuCG) is in force since 6 Dec 2025 – no transition period, covering ~29,500 entities.
Framework for the financial sector's digital operational resilience: ICT risk management, incident reporting, resilience testing and oversight of ICT third-party providers.
Directly applicable EU regulation; supervised in Germany by BaFin.
Strengthens EU-wide detection, preparedness and response to cyber threats – incl. a European alert system (cyber hubs) and an emergency mechanism. Addresses EU/state structures, not individual businesses.
Rules for the re-use of protected public-sector data, for data-intermediation services and for data altruism.
Obligations for online intermediaries, platforms and marketplaces against illegal content – with stricter duties for very large platforms (VLOPs).
Conduct rules for dominant 'gatekeeper' platforms to ensure fair and contestable digital markets.
Commission simplification package (Nov 2025) in two parts. The AI part is in force as Regulation (EU) 2026/1744 and postpones the AI Act high-risk deadlines. The data-protection/cookie part (GDPR, ePrivacy, NIS2, Data Act) is still only a proposal.
The AI part is done: adopted by the European Parliament on 16 June 2026, published on 24 July 2026 as Regulation (EU) 2026/1744, in force since 27 July 2026. The postponed high-risk deadlines (Annex III → 2 Dec 2027, Annex I → 2 Aug 2028) are therefore enacted law, and Art. 5 has two new prohibitions (from 2 Dec 2026). The 2 August 2026 date for the transparency obligations was expressly not moved. The data-protection/cookie part remains a Commission proposal and may still change significantly.
Last checked: 28 July 2026
Curated overview, not legal advice. Deadlines are verified against EUR-Lex and official EU sources; see the status above. Specific obligations and exceptions follow from each legal act. The AI part of the 'Digital Omnibus' is in force as Regulation (EU) 2026/1744; its data-protection/cookie part is still a proposal – deadlines flagged there may change.
The key EU digital and cyber laws with their compliance deadlines – sorted by the next upcoming deadline, with a countdown. From NIS2 to the Cyber Resilience Act to the AI Act and the Digital Omnibus.
The deadlines are hand-verified against EUR-Lex (the EU Official Journal) and official European Commission sources. We curate the list deliberately, because a wrongly stated deadline is worse than none.
The Digital Omnibus is a Commission simplification package. The AI part is done: adopted by the European Parliament on 16 June 2026, published on 24 July 2026 as Regulation (EU) 2026/1744, and in force since 27 July 2026. The data-protection/cookie part is still only a proposal — only that part is still flagged as such here.
Yes. Germany transposed the NIS2 Directive late but has now done so: the NIS2 transposition law (NIS2UmsuCG) is in force since 6 December 2025 – with no transition period.
No. The ticker is an orientation overview. Which obligations apply specifically to your company is something we're happy to clarify in a conversation.
We translate NIS2, CRA, Data Act & the AI Act into concrete steps for your company – without compliance theatre.
These tools complement the current result.