← GRC Hub

📅 EU Cybersecurity Regulatory Calendar

Key deadlines and milestones for DORA, NIS2, GDPR, CRA and related EU cybersecurity regulations.

Dataset v1.0.0 · reviewed 2026-06-10 · sources & methodology →
Framework
Showing 4 of 25 events
Date Framework Type Event Description Source Calendar
25 May 2018 GDPR applicability GDPR fully applicable Regulation (EU) 2016/679 becomes directly applicable across the EU after the two-year transition period. EUR-Lex ↗
16 Jul 2020 GDPR milestone Schrems II ruling — Privacy Shield invalidated CJEU judgment in Case C-311/18 invalidates the EU-US Privacy Shield framework, affecting transatlantic data transfers. CJEU ↗
4 Jun 2021 GDPR milestone Modernised Standard Contractual Clauses adopted Commission Decision adopting new SCCs for the transfer of personal data to third countries. European Commission ↗
16 Jan 2023 DORA applicability DORA enters into force Regulation (EU) 2022/2554 on digital operational resilience for the financial sector enters into force with a 24-month implementation runway. EUR-Lex ↗
16 Jan 2023 NIS2 applicability NIS2 Directive enters into force Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union enters into force. EUR-Lex ↗
10 Jul 2023 GDPR milestone EU-US Data Privacy Framework adopted Commission adopts adequacy decision for the EU-US Data Privacy Framework, restoring a transfer mechanism for certified US organisations. European Commission ↗
17 Jan 2024 DORA rts/its First batch of DORA Level 2 RTS/ITS submitted ESAs submit first batch of regulatory and implementing technical standards (ICT risk management framework, incident classification, register of information, TLPT). EBA ↗
25 Jun 2024 DORA rts/its Delegated Regulation (EU) 2024/1774 published Commission Delegated Regulation supplementing DORA with regulatory technical standards on ICT risk management framework and the simplified ICT risk management framework. EUR-Lex ↗
25 Jun 2024 DORA rts/its Delegated Regulation (EU) 2024/1772 published Commission Delegated Regulation supplementing DORA with regulatory technical standards on the classification of ICT-related incidents and cyber threats. EUR-Lex ↗
17 Jul 2024 DORA rts/its Second batch of DORA Level 2 RTS/ITS submitted ESAs submit second batch of DORA technical standards covering subcontracting of ICT services, threat-led penetration testing, and oversight of critical ICT third-party providers. ESMA ↗
17 Oct 2024 NIS2 deadline Member State transposition deadline EU Member States must transpose NIS2 into national law by this date. EUR-Lex ↗
18 Oct 2024 NIS2 applicability NIS2 obligations apply (transposed Member States) NIS2 obligations apply to essential and important entities in Member States that have transposed the Directive. EUR-Lex ↗
18 Oct 2024 NIS2 rts/its NIS2 Implementing Regulation (EU) 2024/2690 applies Commission Implementing Regulation laying down detailed technical and methodological requirements for the cybersecurity risk-management measures and incident-significance thresholds for relevant entities under Article 21 and Article 23 NIS2. EUR-Lex ↗
10 Dec 2024 CRA applicability Cyber Resilience Act enters into force Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements enters into force. EUR-Lex ↗
17 Jan 2025 DORA applicability DORA fully applicable DORA becomes applicable to financial entities and critical ICT third-party providers across the EU. EUR-Lex ↗
17 Apr 2025 NIS2 deadline Member States establish entity registers Member States must establish the list of essential and important entities and entities providing domain name registration services. EUR-Lex ↗
30 Apr 2025 DORA deadline First Register of Information submission window Competent authorities collect Registers of Information from financial entities for onward submission to the ESAs (per ESA collection arrangements). EBA ↗
26 Jun 2025 ENISA milestone ENISA implementation guidance on NIS2 security measures ENISA publishes technical implementation guidance accompanying Implementing Regulation (EU) 2024/2690 for relevant entities under NIS2 Art. 21. ENISA ↗
Oct 2025 ENISA milestone ENISA Threat Landscape annual update ENISA publishes its annual Threat Landscape report covering the top threats observed in the previous reporting period. ENISA ↗
17 Jan 2026 DORA review DORA Commission review milestone European Commission begins the periodic review of DORA's application and effectiveness; potential follow-up legislative proposals. EUR-Lex ↗
30 Apr 2026 DORA deadline Annual Register of Information submission Financial entities submit updated Register of Information for ICT third-party arrangements under DORA Art. 28(3). EUR-Lex ↗
11 Sep 2026 CRA deadline Vulnerability and incident reporting obligations apply Manufacturers' obligations on reporting actively exploited vulnerabilities and severe incidents (Art. 14) begin to apply. EUR-Lex ↗
30 Apr 2027 DORA deadline Annual Register of Information submission Financial entities submit updated Register of Information for ICT third-party arrangements under DORA Art. 28(3). EUR-Lex ↗
17 Oct 2027 NIS2 review Commission review of NIS2 Commission to review the functioning of NIS2 and submit a report to the European Parliament and the Council (Art. 40). EUR-Lex ↗
11 Dec 2027 CRA applicability CRA fully applicable Full application of the CRA: products with digital elements placed on the EU market must comply with the essential cybersecurity requirements (Annex I). EUR-Lex ↗