Chronology
Master timeline
Key adoption and application dates from the knowledge base. Cross-check against EUR-Lex before relying on deadlines.
Master timeline
Verified against the Official Journal / Commission publications as of 2026-07-16. Good
source for a website timeline component (mirrored in _data/regulations.json).
Past — how we got here
| Date | Event |
|---|---|
| 2013-08-12 | Directive 2013/40/EU on attacks against information systems in force |
| 2016-07-06 | NIS1 Directive (2016/1148) adopted — first EU-wide cyber law |
| 2018-05-25 | GDPR applies (security of processing + 72h breach notification) |
| 2019-06-27 | Cybersecurity Act (2019/881) in force — permanent ENISA mandate + certification framework |
| 2020-01-29 | 5G Cybersecurity Toolbox published (soft law) |
| 2023-01-16 | NIS2 (2022/2555), CER (2022/2557) and DORA (2022/2554) enter into force |
| 2024-02-15 | Croatia becomes first Member State to transpose NIS2 |
| 2024-02-27 | EUCC — first EU certification scheme (Impl. Reg. 2024/482) adopted; applies Feb 2025 |
| 2024-05-20 | eIDAS 2 (2024/1183) in force — EU Digital Identity Wallet framework |
| 2024-08-01 | AI Act (2024/1689) in force (phased application follows) |
| 2024-10-17 | NIS2 + CER transposition deadline — met only by BE, HR, IT, LT |
| 2024-10-17 | NIS2 Implementing Reg. 2024/2690 (digital infrastructure entities) adopted |
| 2024-11-28 | Commission opens infringement proceedings vs 23 Member States (NIS2) |
| 2024-12-10 | Cyber Resilience Act (2024/2847) enters into force |
| 2025-01-15 | Cybersecurity Act amendment (managed security services) + Cyber Solidarity Act (2025/38) adopted |
| 2025-01-17 | DORA applies — full ICT-risk regime for the financial sector |
| 2025-05-07 | Commission sends reasoned opinions to 19 Member States on NIS2 |
| 2025-08-01 | RED cybersecurity requirements apply (Delegated Reg. 2022/30) — connected radio/IoT |
| 2025-11 | Digital Omnibus proposed — incl. Single Entry Point for incident reporting |
| 2025-12-06 | Germany’s NIS2 law (NIS2UmsuCG) in force |
| 2026-01-20 | EU Cybersecurity Package proposed: Cybersecurity Act 2 (COM(2026) 11) + targeted NIS2 amendments |
| 2026-02-13 | Bulgaria transposes NIS2 (22 of 27 states now done) |
| 2026-04-02 | Poland’s NIS2 law in force (adaptation period to 2027-04-02) |
Now / imminent (as of July 2026)
| Date | Event |
|---|---|
| 2026-06-11 | CRA provisions on conformity assessment bodies apply |
| 2026-07 | France expected to adopt its combined NIS2/CER/DORA “Resilience Bill” ⚠️ VERIFY |
| 2026-07-01 | Netherlands Cyberbeveiligingswet targeted entry into force ⚠️ VERIFY |
| 2026-07-17 | CER: deadline for Member States to identify their critical entities |
| 2026-09-11 | CRA reporting obligations start — actively exploited vulnerabilities & severe incidents |
| 2026-10-01 | Austria’s NISG 2026 enters into force |
Coming up
| Date | Event |
|---|---|
| 2026 (H2) | Political agreement targeted on the Jan-2026 package; first NIS2 fines anticipated |
| ~2026-12 | eIDAS 2: Member States to offer EU Digital Identity Wallets ⚠️ VERIFY exact date |
| 2026-12-09 | New Product Liability Directive (2024/2853) transposition deadline (software defects) |
| 2027-04-02 | Poland: end of adaptation period |
| 2027-12-11 | CRA fully applies — essential requirements + CE marking for all products with digital elements |
| +18–24 months after Digital Omnibus adoption | Single Entry Point for incident reporting goes live |
| adoption + 12 months | NIS2 targeted amendments: national transposition deadline (once adopted) |