← GRC Hub
EU Cybersecurity Regulatory Calendar
Key deadlines and milestones for DORA, NIS2, GDPR, CRA and related EU cybersecurity regulations.
Dataset v1.0.0 · reviewed 2026-06-10 · sources & methodology →
Framework
| Date | Framework | Type | Event | Description | Source | Calendar |
|---|---|---|---|---|---|---|
| 25 May 2018 | GDPR | applicability | GDPR fully applicable | Regulation (EU) 2016/679 becomes directly applicable across the EU after the two-year transition period. | EUR-Lex ↗ | |
| 16 Jul 2020 | GDPR | milestone | Schrems II ruling — Privacy Shield invalidated | CJEU judgment in Case C-311/18 invalidates the EU-US Privacy Shield framework, affecting transatlantic data transfers. | CJEU ↗ | |
| 4 Jun 2021 | GDPR | milestone | Modernised Standard Contractual Clauses adopted | Commission Decision adopting new SCCs for the transfer of personal data to third countries. | European Commission ↗ | |
| 16 Jan 2023 | DORA | applicability | DORA enters into force | Regulation (EU) 2022/2554 on digital operational resilience for the financial sector enters into force with a 24-month implementation runway. | EUR-Lex ↗ | |
| 16 Jan 2023 | NIS2 | applicability | NIS2 Directive enters into force | Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union enters into force. | EUR-Lex ↗ | |
| 10 Jul 2023 | GDPR | milestone | EU-US Data Privacy Framework adopted | Commission adopts adequacy decision for the EU-US Data Privacy Framework, restoring a transfer mechanism for certified US organisations. | European Commission ↗ | |
| 17 Jan 2024 | DORA | rts/its | First batch of DORA Level 2 RTS/ITS submitted | ESAs submit first batch of regulatory and implementing technical standards (ICT risk management framework, incident classification, register of information, TLPT). | EBA ↗ | |
| 25 Jun 2024 | DORA | rts/its | Delegated Regulation (EU) 2024/1774 published | Commission Delegated Regulation supplementing DORA with regulatory technical standards on ICT risk management framework and the simplified ICT risk management framework. | EUR-Lex ↗ | |
| 25 Jun 2024 | DORA | rts/its | Delegated Regulation (EU) 2024/1772 published | Commission Delegated Regulation supplementing DORA with regulatory technical standards on the classification of ICT-related incidents and cyber threats. | EUR-Lex ↗ | |
| 17 Jul 2024 | DORA | rts/its | Second batch of DORA Level 2 RTS/ITS submitted | ESAs submit second batch of DORA technical standards covering subcontracting of ICT services, threat-led penetration testing, and oversight of critical ICT third-party providers. | ESMA ↗ | |
| 17 Oct 2024 | NIS2 | deadline | Member State transposition deadline | EU Member States must transpose NIS2 into national law by this date. | EUR-Lex ↗ | |
| 18 Oct 2024 | NIS2 | applicability | NIS2 obligations apply (transposed Member States) | NIS2 obligations apply to essential and important entities in Member States that have transposed the Directive. | EUR-Lex ↗ | |
| 18 Oct 2024 | NIS2 | rts/its | NIS2 Implementing Regulation (EU) 2024/2690 applies | Commission Implementing Regulation laying down detailed technical and methodological requirements for the cybersecurity risk-management measures and incident-significance thresholds for relevant entities under Article 21 and Article 23 NIS2. | EUR-Lex ↗ | |
| 10 Dec 2024 | CRA | applicability | Cyber Resilience Act enters into force | Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements enters into force. | EUR-Lex ↗ | |
| 17 Jan 2025 | DORA | applicability | DORA fully applicable | DORA becomes applicable to financial entities and critical ICT third-party providers across the EU. | EUR-Lex ↗ | |
| 17 Apr 2025 | NIS2 | deadline | Member States establish entity registers | Member States must establish the list of essential and important entities and entities providing domain name registration services. | EUR-Lex ↗ | |
| 30 Apr 2025 | DORA | deadline | First Register of Information submission window | Competent authorities collect Registers of Information from financial entities for onward submission to the ESAs (per ESA collection arrangements). | EBA ↗ | |
| 26 Jun 2025 | ENISA | milestone | ENISA implementation guidance on NIS2 security measures | ENISA publishes technical implementation guidance accompanying Implementing Regulation (EU) 2024/2690 for relevant entities under NIS2 Art. 21. | ENISA ↗ | |
| Oct 2025 | ENISA | milestone | ENISA Threat Landscape annual update | ENISA publishes its annual Threat Landscape report covering the top threats observed in the previous reporting period. | ENISA ↗ | |
| 17 Jan 2026 | DORA | review | DORA Commission review milestone | European Commission begins the periodic review of DORA's application and effectiveness; potential follow-up legislative proposals. | EUR-Lex ↗ | |
| 30 Apr 2026 | DORA | deadline | Annual Register of Information submission | Financial entities submit updated Register of Information for ICT third-party arrangements under DORA Art. 28(3). | EUR-Lex ↗ | |
| 11 Sep 2026 | CRA | deadline | Vulnerability and incident reporting obligations apply | Manufacturers' obligations on reporting actively exploited vulnerabilities and severe incidents (Art. 14) begin to apply. | EUR-Lex ↗ | |
| 30 Apr 2027 | DORA | deadline | Annual Register of Information submission | Financial entities submit updated Register of Information for ICT third-party arrangements under DORA Art. 28(3). | EUR-Lex ↗ | |
| 17 Oct 2027 | NIS2 | review | Commission review of NIS2 | Commission to review the functioning of NIS2 and submit a report to the European Parliament and the Council (Art. 40). | EUR-Lex ↗ | |
| 11 Dec 2027 | CRA | applicability | CRA fully applicable | Full application of the CRA: products with digital elements placed on the EU market must comply with the essential cybersecurity requirements (Annex I). | EUR-Lex ↗ |
No events match your filters.