---
title: "Regulatory Universal Timeline - 38 Source Timelines and 1297 Compliance Events"
canonical_url: "https://www.sorena.io/artifacts/global/regulatory-universal-timelines"
source_url: "https://www.sorena.io/artifacts/global/regulatory-universal-timelines"
author: "Sorena AI"
description: "Use Sorena AI Regulatory Universal Timeline to review 38 source timelines and 1297 dated compliance events in one view."
published_at: "2026-02-12"
updated_at: "2026-02-12"
keywords:
  - "regulatory Universal Timeline"
  - "compliance timeline"
  - "compliance calendar"
  - "regulatory deadlines"
  - "deadline planning"
  - "governance reporting"
  - "PNG timeline export"
  - "Sorena AI timeline"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Regulatory Universal Timeline - 38 Source Timelines and 1297 Compliance Events

Use Sorena AI Regulatory Universal Timeline to review 38 source timelines and 1297 dated compliance events in one view.

![Regulatory Universal Timeline - 38 Source Timelines and 1297 Compliance Events](https://cdn.sorena.io/cheatsheets/sorena-ai-regulatory-universal-timeline-small.png)

*Universal Timeline* *Merged Local Dataset*

## Regulatory Universal Timeline

This page merges 38 source timelines and 1297 dated events from the local artifacts catalog into one interactive compliance timeline. Filter by source label, inspect milestone detail, zoom from 1973 to 2050, and export the current view as a PNG snapshot.

The viewer normalizes timeline labels from regulation identifiers so teams can compare timing across frameworks without rewriting the source events.

[Create my custom view](/solutions/assessment.md) | [Talk to an expert](/contact.md)

By Sorena AI | Updated Mar 2026 | No sign-up required

**Key highlights:** 38 source timelines | PNG export and filters

## Topic Guides

- [Compliance Calendar for Regulatory Universal Timelines](/artifacts/global/regulatory-universal-timelines/compliance-calendar.md): Build an internal compliance calendar from Regulatory Universal Timelines by converting external dates into owned milestones, lead times, collision windows, and evidence gates.
- [Evidence Reuse for Regulatory Universal Timeline](/artifacts/global/regulatory-universal-timelines/framework-overlap-and-evidence-reuse.md): Use Sorena AI Regulatory Universal Timelines to spot framework overlap, reuse evidence across aligned obligations, and keep cited deadline decisions traceable.
- [How to Use Regulatory Universal Timelines](/artifacts/global/regulatory-universal-timelines/how-to-use.md): Step by step guide for using Sorena AI Regulatory Universal Timeline: source filters, category chips, event detail, zoom, minimap navigation.
- [Regulatory Universal Timeline Glossary](/artifacts/global/regulatory-universal-timelines/glossary.md): Glossary for Sorena AI Regulatory Universal Timeline covering source timelines, category chips, milestone events, ranged events, export snapshots.
- [Regulatory Universal Timelines Export and Sharing Guide](/artifacts/global/regulatory-universal-timelines/export-and-sharing.md): Share Sorena AI Regulatory Universal Timeline correctly: browser generated PNG export, filter context, version notes, leadership reporting packs.
- [What is included in the Regulatory Universal Timeline](/artifacts/global/regulatory-universal-timelines/what-is-included.md): Review current coverage for Sorena AI Regulatory Universal Timeline: which local timeline files are merged, what event fields are included.

## Universal Timeline

*38 source timelines*

Use category chips, zoom controls, minimap navigation, and event detail to review the current merged dataset.

The current build spans 1973 through 2050 and includes 339 milestone events.

## Merged compliance timeline viewer

The viewer auto-builds from local timeline datasets. Use source and category filters to isolate a framework, compare overlapping deadlines, click an event for detail, and export the current state for governance or audit reporting.

## Everyone's timeline. Now build yours.

This is the shared view. Sorena Law Tracker makes it yours: your laws, your deadlines, mapped to your controls and refreshed the second a rule moves.

[Build my timeline](/solutions/law-tracker.md)

[Open Research Copilot](/solutions/research-copilot.md)

## EU NIS2 Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2020-12-16 | Commission publishes NIS2 proposal | Legislative History | [COM(2020) 823](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52020PC0823&ref=sorena.io#:~:text=Brussels%2C%2016.12.2020%20COM%282020%29%20823%20final) |
| 2021-12-03 | NIS2 Council agrees its position | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2021/12/03/strengthening-eu-wide-cybersecurity-and-resilience-council-agrees-its-position/?ref=sorena.io) |
| 2022-05-13 | NIS2 political agreement reached | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2022/05/13/renforcer-la-cybersecurite-et-la-resilience-a-l-echelle-de-l-ue-accord-provisoire-du-conseil-et-du-parlement-europeen/?ref=sorena.io) |
| 2022-07-13 | NIS2 ITRE committee adopts agreed text | Legislative History | [Source](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-review-of-the-nis-directive?ref=sorena.io#:~:text=adopted%20by%20the%20ITRE%20committee%20on%2013%20July%202022) |
| 2022-11-10 | NIS2 Parliament plenary adoption | Legislative History | [Source](https://www.europarl.europa.eu/news/en/press-room/20221107IPR49608/cybersecurity-parliament-adopts-new-law-to-strengthen-eu-wide-resilience?ref=sorena.io#:~:text=MEPs%20adopted%20the%20text%20with%20577%20votes%20to%206%2C%20with%2031%20abstentions.) |
| 2022-11-28 | NIS2 Council formal adoption | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2022/11/28/eu-decides-to-strengthen-cybersecurity-and-resilience-across-the-union-council-adopts-new-legislation/?ref=sorena.io) |
| 2022-12-14 | NIS2 final act signed by co-legislators | Official Publication | [Source](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-review-of-the-nis-directive?ref=sorena.io#:~:text=signed%20by%20both%20co%2Dlegislators%20on%2014%20December%202022) |
| 2022-12-27 | NIS2 published in Official Journal | Official Publication | [OJ L 333, 27.12.2022](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng?ref=sorena.io#:~:text=OJ%20L%20333%2C%2027.12.2022) |
| 2023-01-16 | NIS2 entry into force | Official Publication | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=This%20Directive%20shall%20enter%20into%20force%20on%20the%20twentieth%20day%20following%20that%20of%20its%20publication) |
| 2023-01-16 | NIS2 delegated-act power period begins | Commission Deliverables | [Arts. 24(2), 38(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io) |
| 2023-07-17 | NIS2 Commission deadline for Article 4 guidelines | Commission Deliverables | [Art. 4(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52023XC0918%2801%29&ref=sorena.io#:~:text=the%20Commission%20shall%2C%20by%2017%20July%202023%2C%20provide%20guidelines) |
| 2023-09-14 | NIS2 guidelines on Article 3(4) published | Commission Deliverables | [2023/C 324/02](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AC%3A2023%3A324%3AFULL&ref=sorena.io) |
| 2023-09-18 | NIS2 guidelines on Article 4(1)-(2) published | Commission Deliverables | [2023/C 328/02](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52023XC0918%2801%29&ref=sorena.io#:~:text=pursuant%20to%20Article%204%283%29%20of%20Directive%20%28EU%29%202022/2555%2C%20the%20Commission%20shall%2C%20by%2017%20July%202023%2C%20provide%20guidelines) |
| 2023-12-22 | Corrigendum: Article 19(1) deadline wording | Corrigendum | [Art. 19(1)](https://eur-lex.europa.eu/eli/dir/2022/2555/corrigendum/2023-12-22/oj/eng?ref=sorena.io#:~:text=for%3A%20%E2%80%9CThe%20Cooperation%20Group%20shall%2C%20on%2017%20January%202025%E2%80%9D%20read%3A%20%E2%80%9Cby%2017%20January%202025%E2%80%9D) |
| 2024-02-01 | NIS2 Cooperation Group work programme due | Cooperation & Networks | [Art. 14(7)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%201%20February%202024%20and%20every%20two%20years%20thereafter%2C%20the%20Cooperation%20Group%20shall%20establish%20a%20work%20programme) |
| 2024-07-17 | EU-CyCLONe first report due | Cooperation & Networks | [Art. 16(7)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=By%2017%20July%202024%20and%20every%2018%20months%20thereafter%2C%20EU-CyCLONe%20shall%20submit%20to%20the%20European%20Parliament%20and%20to%20the%20Council%20a%20report%20assessing%20its%20work.) |
| 2024-10-17 | Implementing Regulation 2024/2690 adopted | Implementing Acts | [Reg. (EU) 2024/2690; Arts. 21(5), 23(11)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402690&ref=sorena.io) |
| 2024-10-17 | NIS2 transposition deadline | National Transposition | [Art. 41(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%2017%20October%202024%2C%20Member%20States%20shall%20adopt%20and%20publish%20the%20measures) |
| 2024-10-18 | Implementing Regulation 2024/2690 published in OJ | Implementing Acts | [OJ L 2024/2690](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402690&ref=sorena.io) |
| 2024-10-18 | NIS1 repealed, NIS2 measures apply | National Transposition | [Arts. 41-44](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io) |
| 2024-11-07 | Implementing Regulation 2024/2690 enters into force | Implementing Acts | [OJ L 2024/2690](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402690&ref=sorena.io#:~:text=This%20Regulation%20shall%20enter%20into%20force%20on%20the%20twentieth%20day%20following%20that%20of%20its%20publication) |
| 2024-11-28 | Commission opens transposition infringement procedures | Enforcement & Infringements | [Art. 258 TFEU](https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive?ref=sorena.io) |
| 2025-01-17 | NIS2 registry information submission due | National Obligations | [Art. 27(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=Member%20States%20shall%20require%20entities%20referred%20to%20in%20paragraph%201%20to%20submit%20the%20following%20information%20to%20the%20competent%20authorities%20by%2017%20January%202025) |
| 2025-01-17 | NIS2 Member States notify penalty rules | National Obligations | [Art. 36](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=Member%20States%20shall%2C%20by%2017%20January%202025%2C%20notify%20the%20Commission%20of%20those%20rules) |
| 2025-01-17 | NIS2 CSIRTs network progress report due | Cooperation & Networks | [Art. 15(4)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=By%2017%20January%202025%2C%20and%20every%20two%20years%20thereafter%2C%20the%20CSIRTs%20network%20shall) |
| 2025-01-17 | NIS2 peer-review methodology due | Cooperation & Networks | [Art. 19(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=The%20Cooperation%20Group%20shall%2C%20by%2017%20January%202025%2C%20establish) |
| 2025-04-17 | NIS2 entity list established | National Obligations | [Art. 3(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%2017%20April%202025%2C%20Member%20States%20shall%20establish%20a%20list%20of%20essential%20and%20important%20entities) |
| 2025-04-17 | NIS2 aggregate entity data notification | National Obligations | [Art. 3(5)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%2017%20April%202025%20and%20every%20two%20years%20thereafter%2C%20the%20competent%20authorities%20shall%20notify) |
| 2025-05-07 | Commission sends reasoned opinions to 19 Member States | Enforcement & Infringements | [Art. 258 TFEU](https://ec.europa.eu/commission/presscorner/detail/en/inf_25_982?ref=sorena.io) |
| 2025-06-26 | ENISA technical implementation guidance published | Cooperation & Networks | [Version 1.0](https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance?ref=sorena.io) |
| 2026-01-20 | Commission proposes NIS2 amendment | Legislative History | [COM(2026) 13](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52026PC0013&ref=sorena.io) |
| 2027-10-17 | Commission review of NIS2 | Commission Deliverables | [Art. 40](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=By%2017%20October%202027%20and%20every%2036%20months%20thereafter%2C%20the%20Commission%20shall%20review) |

**Event details:**

- **2020-12-16 - Commission publishes NIS2 proposal**: European Commission publishes the NIS2 proposal COM(2020) 823 final, proposing measures for a high common level of cybersecurity across the Union.
- **2021-12-03 - NIS2 Council agrees its position**: Council agrees its position (general approach) to start negotiations with the European Parliament.
- **2022-05-13 - NIS2 political agreement reached**: Council and European Parliament reach provisional political agreement on NIS2.
- **2022-07-13 - NIS2 ITRE committee adopts agreed text**: EP Industry, Research and Energy (ITRE) committee adopts the agreed text after trilogue.
- **2022-11-10 - NIS2 Parliament plenary adoption**: European Parliament adopts NIS2 in plenary: 577 in favour, 6 against, 31 abstentions.
- **2022-11-28 - NIS2 Council formal adoption**: Council of the EU formally adopts NIS2.
- **2022-12-14 - NIS2 final act signed by co-legislators**: NIS2 Directive signed by both co-legislators on 14 December 2022.
- **2022-12-27 - NIS2 published in Official Journal**: Directive (EU) 2022/2555 published in the Official Journal of the European Union (OJ L 333, 27.12.2022).
- **2023-01-16 - NIS2 entry into force**: NIS2 enters into force on the 20th day following OJ publication (16 January 2023). Member States have until 17 October 2024 to transpose.
- **2023-01-16 - NIS2 delegated-act power period begins**: The Commission power to adopt delegated acts under Article 24(2) applies for five years from 16 January 2023 and is tacitly extended unless the European Parliament or Council opposes under Article 38.
- **2023-07-17 - NIS2 Commission deadline for Article 4 guidelines**: Commission deadline to provide guidelines clarifying the application of Article 4(1) and Article 4(2).
- **2023-09-14 - NIS2 guidelines on Article 3(4) published**: Commission publishes Guidelines on the application of Article 3(4) with a data-collection template for establishing entity lists.
- **2023-09-18 - NIS2 guidelines on Article 4(1)-(2) published**: Commission publishes Guidelines on equivalence with sector-specific Union legal acts, pursuant to Article 4(3) (deadline was 17 Jul 2023).
- **2023-12-22 - Corrigendum: Article 19(1) deadline wording**: Corrigendum changes Article 19(1) deadline wording from 'on' to 'by' 17 January 2025 for the Cooperation Group peer-review methodology.
- **2024-02-01 - NIS2 Cooperation Group work programme due**: Cooperation Group must establish a work programme by 1 February 2024 and every two years thereafter.
- **2024-07-17 - EU-CyCLONe first report due**: EU-CyCLONe must submit a report assessing its work to the European Parliament and Council by 17 July 2024 and every 18 months thereafter.
- **2024-10-17 - Implementing Regulation 2024/2690 adopted**: Commission adopts Implementing Regulation (EU) 2024/2690 under Articles 21(5) and 23(11), laying down technical and methodological cybersecurity risk-management requirements and significant-incident criteria for DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, online marketplace providers, online search engine providers, social networking service platform providers, and trust service providers.
- **2024-10-17 - NIS2 transposition deadline**: Member States must adopt and publish national transposition measures by 17 October 2024. Measures apply from 18 October 2024.
- **2024-10-18 - Implementing Regulation 2024/2690 published in OJ**: Commission Implementing Regulation (EU) 2024/2690 is published in the Official Journal on 18 October 2024.
- **2024-10-18 - NIS1 repealed, NIS2 measures apply**: Directive (EU) 2016/1148 (NIS1) is repealed with effect from 18 October 2024 and national NIS2 measures apply from this date. Article 19 of eIDAS and Articles 40 and 41 of the European Electronic Communications Code are also deleted with effect from 18 October 2024.
- **2024-11-07 - Implementing Regulation 2024/2690 enters into force**: Commission Implementing Regulation (EU) 2024/2690 enters into force on the twentieth day following its Official Journal publication (published 18 October 2024).
- **2024-11-28 - Commission opens transposition infringement procedures**: The Commission sends letters of formal notice to 23 Member States for failing to fully transpose NIS2; the Member States had two months to respond and complete transposition.
- **2025-01-17 - NIS2 registry information submission due**: Member States must require entities referred to in Article 27(1) to submit registry information to competent authorities by 17 January 2025.
- **2025-01-17 - NIS2 Member States notify penalty rules**: Member States must notify the Commission of their national penalty rules and enforcement measures by 17 January 2025.
- **2025-01-17 - NIS2 CSIRTs network progress report due**: CSIRTs network must adopt a report assessing progress in operational cooperation by 17 January 2025 and every two years thereafter.
- **2025-01-17 - NIS2 peer-review methodology due**: Cooperation Group must establish the peer-review methodology and organisational aspects by 17 January 2025.
- **2025-04-17 - NIS2 entity list established**: Member States must establish a list of essential and important entities (and entities providing domain name registration services) by 17 April 2025.
- **2025-04-17 - NIS2 aggregate entity data notification**: Competent authorities must notify the Commission and Cooperation Group of aggregate list data (number of essential and important entities per sector) by 17 April 2025 and every two years thereafter.
- **2025-05-07 - Commission sends reasoned opinions to 19 Member States**: The Commission sends reasoned opinions to 19 Member States for failing to notify full NIS2 transposition; they had two months to respond before possible referral to the Court of Justice.
- **2025-06-26 - ENISA technical implementation guidance published**: ENISA publishes the NIS2 Technical Implementation Guidance (version 1.0) supporting implementation of Implementing Regulation (EU) 2024/2690.
- **2026-01-20 - Commission proposes NIS2 amendment**: Commission publishes proposal to amend NIS2 (simplification and alignment). This is a proposal, not yet law.
- **2027-10-17 - Commission review of NIS2**: The Commission shall review the functioning of the NIS2 Directive by 17 October 2027 and every 36 months thereafter, and submit a report to the European Parliament and Council.

## EU AI Act Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2023-05-01 | Commission standardisation request to CEN and CENELEC | Standardisation & harmonised standards | [Source](https://ai-watch.ec.europa.eu/news/harmonised-standards-european-ai-act-2024-10-25_en?ref=sorena.io) |
| 2023-10-17 | ETSI announces TC SAI transition for AI Act support | ETSI deliverables | [Source](https://www.etsi.org/newsroom/news/2288-etsi-s-securing-ai-group-becomes-a-technical-committee-to-help-etsi-to-answer-the-eu-ai-act?ref=sorena.io) |
| 2023-12-04 | ETSI TC SAI inaugural meeting scheduled | ETSI deliverables | [Source](https://www.etsi.org/newsroom/news/2288-etsi-s-securing-ai-group-becomes-a-technical-committee-to-help-etsi-to-answer-the-eu-ai-act?ref=sorena.io) |
| 2024-01-24 | Commission Decision establishes the European AI Office | Notified bodies & governance | [Source](https://digital-strategy.ec.europa.eu/en/library/commission-decision-establishing-european-ai-office?ref=sorena.io) |
| 2024-04-01 | ETSI TR 104 225 privacy aspects of AI/ML systems published | ETSI deliverables | [Source](https://www.etsi.org/deliver/etsi_tr/104200_104299/104225/01.01.01_60/tr_104225v010101p.pdf?ref=sorena.io) |
| 2024-06-13 | AI Act adopted as Regulation (EU) 2024/1689 | Legislative milestones | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2024-07-12 | AI Act published in the Official Journal | Legislative milestones | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2024-08-01 | AI Act enters into force | Legislative milestones | [Source](https://commission.europa.eu/news-and-media/news/ai-act-enters-force-2024-08-01_en?ref=sorena.io) |
| 2024-10-25 | JRC brief on harmonised standards for the AI Act published | Standardisation & harmonised standards | [Source](https://ai-watch.ec.europa.eu/news/harmonised-standards-european-ai-act-2024-10-25_en?ref=sorena.io) |
| 2024-11-02 | Member States identify Article 77 public authorities | Notified bodies & governance | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2025-02-02 | Chapters I and II apply (including prohibited AI practices) | Prohibitions | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2025-03-01 | ETSI TS 104 224 on AI transparency published | ETSI deliverables | [Source](https://www.etsi.org/deliver/etsi_ts/104200_104299/104224/01.01.01_60/ts_104224v010101p.pdf?ref=sorena.io) |
| 2025-04-01 | ETSI TS 104 223 baseline cyber security requirements published | ETSI deliverables | [Source](https://www.etsi.org/deliver/etsi_ts/104200_104299/104223/01.01.01_60/ts_104223v010101p.pdf?ref=sorena.io) |
| 2025-05-01 | ETSI TR 104 065 AI Act mapping published | ETSI deliverables | [Source](https://www.etsi.org/deliver/etsi_tr/104000_104099/104065/01.01.01_60/tr_104065v010101p.pdf?ref=sorena.io) |
| 2025-05-01 | ETSI TR 104 128 cyber security guide published | ETSI deliverables | [Source](https://www.etsi.org/deliver/etsi_tr/104100_104199/104128/01.01.01_60/tr_104128v010101p.pdf?ref=sorena.io) |
| 2025-05-02 | GPAI codes of practice readiness deadline | GPAI | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2025-07-10 | General-Purpose AI Code of Practice published | GPAI | [Source](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai?ref=sorena.io) |
| 2025-07-18 | Commission adopts guidelines on GPAI obligations scope | GPAI | [Source](https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act?ref=sorena.io) |
| 2025-08-02 | GPAI, governance, notified-body and penalty provisions apply | GPAI | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2025-08-02 | National competent authorities and contact points due | Notified bodies & governance | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2025-08-02 | Serious-incident guidance due for high-risk AI systems | Incident reporting & post-market | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2025-09-01 | Consultation to develop guidelines and a Code of Practice (transparent AI systems) | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/news/commission-launches-consultation-develop-guidelines-and-code-practice-transparent-ai-systems?ref=sorena.io) |
| 2025-09-26 | Consultation on serious AI incident reporting interplay | Incident reporting & post-market | [Source](https://digital-strategy.ec.europa.eu/en/library/ai-act-commission-publishes-reporting-template-serious-incidents-involving-general-purpose-ai?ref=sorena.io) |
| 2025-10-01 | AI-generated-content transparency Code of Practice chairs selected | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/news/meet-chairs-leading-development-new-code-practice-transparency-ai-generated-content?ref=sorena.io) |
| 2025-10-30 | prEN 18286 enters public enquiry | Standardisation & harmonised standards | [Source](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) |
| 2025-11-04 | Reporting template for serious incidents (GPAI systemic risk) published | Incident reporting & post-market | [Source](https://digital-strategy.ec.europa.eu/en/library/ai-act-commission-publishes-reporting-template-serious-incidents-involving-general-purpose-ai?ref=sorena.io) |
| 2025-11-05 | AI-generated-content transparency Code of Practice kick-off plenary | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/news/commission-launches-work-code-practice-marking-and-labelling-ai-generated-content?ref=sorena.io) |
| 2025-11-17 | First AI-generated-content transparency Code of Practice working group meetings | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/library/first-working-groups-convened-advance-code-practice-marking-and-labelling-ai-generated-content?ref=sorena.io) |
| 2025-11-19 | Digital Omnibus proposes support-tool-linked high-risk dates | Standardisation & harmonised standards | [Source](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) |
| 2025-12-04 | Commission publishes AI Act implementation-guidelines roadmap | Other guidance | [Source](https://digital-strategy.ec.europa.eu/en/news/supporting-implementation-ai-act-clear-guidelines?ref=sorena.io) |
| 2025-12-05 | Template published for public summary of GPAI training content | GPAI | [Source](https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models?ref=sorena.io) |
| 2025-12-17 | First draft of AI-generated-content transparency Code of Practice published | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/library/first-draft-code-practice-transparency-ai-generated-content?ref=sorena.io) |
| 2026-01-12 | AI-generated-content transparency Code of Practice second-round working group meetings | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content?ref=sorena.io) |
| 2026-01-21 | AI-generated-content transparency Code of Practice workshops for working groups 1 and 2 | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content?ref=sorena.io) |
| 2026-02-02 | High-risk classification guidelines deadline | High-risk AI | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2026-02-02 | Post-market monitoring plan template deadline | Incident reporting & post-market | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2026-03-03 | Second draft of AI-generated-content transparency Code of Practice published | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content?ref=sorena.io) |
| 2026-05-08 | Draft Article 50 transparency guidelines published | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/consultations/consultation-draft-guidelines-transparency-obligations-under-ai-act?ref=sorena.io) |
| 2026-05-19 | Draft high-risk AI classification guidelines published | High-risk AI | [Source](https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems?ref=sorena.io) |
| 2026-06-03 | Article 50 transparency-guidelines consultation closes | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/consultations/consultation-draft-guidelines-transparency-obligations-under-ai-act?ref=sorena.io) |
| 2026-06-10 | Final Article 50 transparency Code of Practice published | Transparency & labelling | [Source](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content?ref=sorena.io) |
| 2026-07-23 | High-risk classification-guidelines consultation closes | High-risk AI | [Source](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems?ref=sorena.io) |
| 2026-08-02 | AI Act applies (main obligations start) | Legislative milestones | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2026-08-02 | Commission enforcement powers for GPAI enter into application | GPAI | [Source](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) |
| 2026-08-02 | AI regulatory sandboxes operational deadline | Other guidance | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2027-08-02 | Adopted AI Act Article 6(1) application date | High-risk AI | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2027-08-02 | Existing GPAI providers must comply by this date | GPAI | [Source](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) |
| 2027-12-02 | AI Omnibus high-risk-area enforcement date | High-risk AI | [Source](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems?ref=sorena.io) |
| 2028-08-02 | First AI Office, transparency and standardisation review deadline | Standardisation & harmonised standards | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2028-08-02 | AI Omnibus product-integrated high-risk enforcement date | High-risk AI | [Source](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems?ref=sorena.io) |
| 2029-08-02 | First full AI Act evaluation and review deadline | Legislative milestones | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2030-08-02 | Public-authority pre-existing high-risk systems compliance deadline | High-risk AI | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |
| 2030-12-31 | Large-scale IT system AI components compliance deadline | High-risk AI | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) |

**Event details:**

- **2023-05-01 - Commission standardisation request to CEN and CENELEC**: May 2023: The Commission mandated CEN and CENELEC to develop harmonised standards for AI Act high-risk requirements.
- **2023-10-17 - ETSI announces TC SAI transition for AI Act support**: 17 October 2023: ETSI announced that Securing AI work would transfer from ISG SAI to a new Technical Committee for Securing AI to support the EU AI Act response.
- **2023-12-04 - ETSI TC SAI inaugural meeting scheduled**: 4 December 2023: ETSI scheduled the inaugural meeting of the Technical Committee for Securing AI.
- **2024-01-24 - Commission Decision establishes the European AI Office**: 24 January 2024: European Commission publishes the decision establishing the European AI Office.
- **2024-04-01 - ETSI TR 104 225 privacy aspects of AI/ML systems published**: April 2024: ETSI TR 104 225 V1.1.1 on privacy aspects of AI/ML systems was published; month-only source precision is represented as the first day of the month.
- **2024-06-13 - AI Act adopted as Regulation (EU) 2024/1689**: 13 June 2024: Regulation (EU) 2024/1689 was adopted; the Official Journal publication followed on 12 July 2024.
- **2024-07-12 - AI Act published in the Official Journal**: 12 July 2024: Regulation (EU) 2024/1689 is published in the Official Journal (OJ L, 12.7.2024).
- **2024-08-01 - AI Act enters into force**: 1 August 2024: The EU AI Act enters into force (20 days after publication).
- **2024-10-25 - JRC brief on harmonised standards for the AI Act published**: 25 October 2024: AI Watch/JRC published a brief explaining the role and state of play of harmonised standards for the AI Act.
- **2024-11-02 - Member States identify Article 77 public authorities**: 2 November 2024: Member States had to identify and publish the public authorities or bodies that can supervise or enforce fundamental-rights obligations under Article 77.
- **2025-02-02 - Chapters I and II apply (including prohibited AI practices)**: 2 February 2025: Chapters I and II apply under the AI Act entry into force and application rules.
- **2025-03-01 - ETSI TS 104 224 on AI transparency published**: March 2025: ETSI TS 104 224 V1.1.1 on transparency and explicability of AI systems was published; month-only source precision is represented as the first day of the month.
- **2025-04-01 - ETSI TS 104 223 baseline cyber security requirements published**: April 2025: ETSI TS 104 223 V1.1.1 on baseline cyber security requirements for AI models and systems was published; month-only source precision is represented as the first day of the month.
- **2025-05-01 - ETSI TR 104 065 AI Act mapping published**: May 2025: ETSI TR 104 065 V1.1.1 mapped the AI Act to the ETSI workplan; month-only source precision is represented as the first day of the month.
- **2025-05-01 - ETSI TR 104 128 cyber security guide published**: May 2025: ETSI TR 104 128 V1.1.1 guide to cyber security for AI models and systems was published; month-only source precision is represented as the first day of the month.
- **2025-05-02 - GPAI codes of practice readiness deadline**: 2 May 2025: Article 56(9) required GPAI codes of practice to be ready at the latest.
- **2025-07-10 - General-Purpose AI Code of Practice published**: 10 July 2025: The General-Purpose AI (GPAI) Code of Practice is published as a voluntary tool to help providers meet AI Act obligations.
- **2025-07-18 - Commission adopts guidelines on GPAI obligations scope**: 18 July 2025: Commission finalises its guidelines on the scope of obligations for general-purpose AI models (C(2025) 5045 final).
- **2025-08-02 - GPAI, governance, notified-body and penalty provisions apply**: 2 August 2025: Chapter V, Chapter III Section 4, Chapter VII, Chapter XII and Article 78 apply under Article 113(b), while Article 101 enforcement fines start later.
- **2025-08-02 - National competent authorities and contact points due**: 2 August 2025: Member States had to make competent-authority and single-point-of-contact information public and notify the Commission under Article 70.
- **2025-08-02 - Serious-incident guidance due for high-risk AI systems**: 2 August 2025: Article 73(7) required Commission guidance to facilitate compliance with serious-incident reporting obligations.
- **2025-09-01 - Consultation to develop guidelines and a Code of Practice (transparent AI systems)**: September 2025: Consultation to develop guidelines and a Code of Practice on transparent AI systems, plus a call for expression of interest to participate.
- **2025-09-26 - Consultation on serious AI incident reporting interplay**: 26 September 2025: Consultation referenced alongside serious incident reporting guidance and templates for AI incidents.
- **2025-10-01 - AI-generated-content transparency Code of Practice chairs selected**: October 2025: Eligibility checks and selection of chairs and vice-chairs for the AI-generated-content transparency Code of Practice.
- **2025-10-30 - prEN 18286 enters public enquiry**: 30 October 2025: prEN 18286, a quality-management-system draft for EU AI Act regulatory purposes, became the first harmonised AI standard to enter public enquiry.
- **2025-11-04 - Reporting template for serious incidents (GPAI systemic risk) published**: 4 November 2025: Commission publishes a reporting template for serious incidents involving general-purpose AI models with systemic risk.
- **2025-11-05 - AI-generated-content transparency Code of Practice kick-off plenary**: 5 November 2025: Kick-off plenary; start of the first drafting round for the AI-generated-content transparency Code of Practice.
- **2025-11-17 - First AI-generated-content transparency Code of Practice working group meetings**: 17-18 November 2025: First working group meetings for the AI-generated-content transparency Code of Practice.
- **2025-11-19 - Digital Omnibus proposes support-tool-linked high-risk dates**: 19 November 2025: The Digital Omnibus proposal linked high-risk AI application dates to the availability of support tools, including harmonised standards; later high-risk enforcement dates are listed separately.
- **2025-12-04 - Commission publishes AI Act implementation-guidelines roadmap**: 4 December 2025: The Commission published a roadmap of AI Act implementation guidance planned for 2026, including high-risk classification, Article 50 transparency, serious incidents, FRIAs, value-chain responsibilities, substantial modification, post-market monitoring, and interplay with other EU legislation.
- **2025-12-05 - Template published for public summary of GPAI training content**: 5 December 2025: Commission publishes an explanatory notice and a template for the public summary of training content (Article 53(1)(d)).
- **2025-12-17 - First draft of AI-generated-content transparency Code of Practice published**: 17 December 2025: Publication of the first draft of the AI-generated-content transparency Code of Practice.
- **2026-01-12 - AI-generated-content transparency Code of Practice second-round working group meetings**: 12 and 14 January 2026: Working group meetings for the AI-generated-content transparency Code of Practice; start of the second drafting round.
- **2026-01-21 - AI-generated-content transparency Code of Practice workshops for working groups 1 and 2**: 21-22 January 2026: Workshops for AI-generated-content transparency Code of Practice working groups 1 and 2.
- **2026-02-02 - High-risk classification guidelines deadline**: 2 February 2026: Article 6(5) required Commission guidelines with practical examples of high-risk and non-high-risk AI-system use cases by this date.
- **2026-02-02 - Post-market monitoring plan template deadline**: 2 February 2026: Article 72(3) required an implementing act for the post-market monitoring plan template and required elements by this date.
- **2026-03-03 - Second draft of AI-generated-content transparency Code of Practice published**: 3 March 2026: Publication of the second draft of the AI-generated-content transparency Code of Practice.
- **2026-05-08 - Draft Article 50 transparency guidelines published**: 8 May 2026: The Commission published draft guidelines on transparency obligations for certain AI systems under Article 50 of the AI Act.
- **2026-05-19 - Draft high-risk AI classification guidelines published**: 19 May 2026: The Commission published draft guidelines on classification of high-risk AI systems under Article 6, including practical examples.
- **2026-06-03 - Article 50 transparency-guidelines consultation closes**: 3 June 2026: Commission consultation on draft Article 50 transparency-obligation guidelines closed.
- **2026-06-10 - Final Article 50 transparency Code of Practice published**: 10 June 2026: Publication of the final Code of Practice on Transparency of AI-Generated Content for Article 50 marking, detection, and labelling obligations.
- **2026-07-23 - High-risk classification-guidelines consultation closes**: 23 July 2026: Targeted stakeholder consultation on the draft guidelines for classification of high-risk AI systems closes.
- **2026-08-02 - AI Act applies (main obligations start)**: 2 August 2026: The AI Act applies in general (per Article 113).
- **2026-08-02 - Commission enforcement powers for GPAI enter into application**: 2 August 2026: Commission enforcement powers for obligations on providers of GPAI models enter into application (including fines).
- **2026-08-02 - AI regulatory sandboxes operational deadline**: 2 August 2026: Article 57 required at least one national AI regulatory sandbox to be operational, or equivalent joint or existing sandbox participation.
- **2027-08-02 - Adopted AI Act Article 6(1) application date**: 2 August 2027: Article 113 of Regulation (EU) 2024/1689, as adopted, applies Article 6(1) and corresponding obligations from this date; this remains the adopted-law baseline beside the later Commission AI Omnibus enforcement timeline.
- **2027-08-02 - Existing GPAI providers must comply by this date**: By 2 August 2027: Providers of GPAI models placed on the market before 2 August 2025 must comply, per Commission guidance.
- **2027-12-02 - AI Omnibus high-risk-area enforcement date**: 2 December 2027: Following the political agreement on the AI Omnibus, Commission high-risk systems guidance says rules for systems used in certain high-risk areas, including biometrics, critical infrastructure, education, employment, migration, asylum, and border control, apply from this date.
- **2028-08-02 - First AI Office, transparency and standardisation review deadline**: 2 August 2028: Article 112 requires Commission reviews covering high-risk headings, transparency obligations, governance, AI Office functioning, GPAI energy-efficiency standardisation deliverables and voluntary codes of conduct.
- **2028-08-02 - AI Omnibus product-integrated high-risk enforcement date**: 2 August 2028: Following the political agreement on the AI Omnibus, Commission high-risk systems guidance says rules for systems integrated into products, such as robotics and industrial machinery, apply from this date.
- **2029-08-02 - First full AI Act evaluation and review deadline**: 2 August 2029: Article 112 requires the Commission to submit its first evaluation and review report on the Regulation, and every four years thereafter.
- **2030-08-02 - Public-authority pre-existing high-risk systems compliance deadline**: 2 August 2030: Providers and deployers must bring pre-existing high-risk AI systems intended for use by public authorities into compliance by this date.
- **2030-12-31 - Large-scale IT system AI components compliance deadline**: 31 December 2030: AI components of large-scale IT systems listed in Annex X and placed on the market or put into service before 2 August 2027 must be brought into compliance.

## EU DORA Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2022-12-14 | DORA adopted | Legislative History | [Reg. (EU) 2022/2554 (of 14 December 2022)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2022-12-27 | DORA published in Official Journal | Official Publication | [OJ L 333, 27.12.2022](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2022-12-27 | Alignment Directive (EU) 2022/2556 published | Official Publication | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2556&ref=sorena.io#:~:text=By%2017%20January%202025%2C%20Member%20States%20shall%20adopt%20and%20publish) |
| 2023-01-16 | DORA enters into force | Official Publication | [Art. 64](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2023-06-19 | DORA ESAs first batch public consultation opens | ESAs Mandates & Deliverables | [Source](https://www.eba.europa.eu/publications-and-media/press-releases/esas-consult-first-batch-dora-policy-products?ref=sorena.io#:~:text=The%20consultation%20runs%20until%2011%20September%202023) |
| 2023-07-17 | Commission PSD2 review report deadline (cyber resilience of payment systems) | Commission Mandates & Reviews | [Art. 58(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2023-09-11 | DORA ESAs first batch public consultation closes | ESAs Mandates & Deliverables | [Source](https://www.eba.europa.eu/publications-and-media/press-releases/esas-consult-first-batch-dora-policy-products?ref=sorena.io#:~:text=The%20consultation%20runs%20until%2011%20September%202023) |
| 2023-12-08 | DORA ESAs second batch public consultation opens | ESAs Mandates & Deliverables | [Source](https://www.esma.europa.eu/press-news/consultations/esas-joint-consultation-second-batch-policy-mandates-under-digital?ref=sorena.io#:~:text=From%2008%20December%202023%20to%2004%20March%202024) |
| 2024-01-17 | Deadline: ESAs submit first wave draft RTS/ITS to the Commission | ESAs Mandates & Deliverables | [Arts. 15, 16(3), 18(4), 28(9)-(10)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-03-04 | DORA ESAs second batch public consultation closes | ESAs Mandates & Deliverables | [Source](https://www.esma.europa.eu/press-news/consultations/esas-joint-consultation-second-batch-policy-mandates-under-digital?ref=sorena.io#:~:text=08%20December%202023%20to%2004%20March%202024) |
| 2024-05-30 | Delegated Regs. 2024/1502 and 2024/1505 published in OJ | Delegated & Implementing Acts (OJ) | [OJ L, 2024/1502 and 2024/1505, 30.5.2024](https://eur-lex.europa.eu/eli/reg_del/2024/1502/oj/eng?ref=sorena.io) |
| 2024-06-19 | Delegated Regs. 2024/1502 and 2024/1505 enter into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2024/1502 Art. 7; Reg. (EU) 2024/1505 Art. 7](https://eur-lex.europa.eu/eli/reg_del/2024/1502/oj/eng?ref=sorena.io) |
| 2024-06-25 | Delegated Regs. 2024/1772, 2024/1773, 2024/1774 published in OJ | Delegated & Implementing Acts (OJ) | [OJ L, 2024/1772, 2024/1773, 2024/1774, 25.6.2024](https://eur-lex.europa.eu/eli/reg_del/2024/1772/oj/eng?ref=sorena.io) |
| 2024-07-15 | Delegated Regs. 2024/1772, 2024/1773, 2024/1774 enter into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2024/1772 Art. 13; Reg. (EU) 2024/1773 Art. 11; Reg. (EU) 2024/1774 Art. 42](https://eur-lex.europa.eu/eli/reg_del/2024/1774/oj/eng?ref=sorena.io) |
| 2024-07-17 | Deadline: ESAs submit draft RTS/ITS for incident reporting content and templates | ESAs Mandates & Deliverables | [Art. 20](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | Deadline: ESAs submit draft RTS for TLPT (TIBER-EU framework) | ESAs Mandates & Deliverables | [Art. 26(11)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | Deadline: ESAs develop guidelines on annual costs and losses from major incidents | ESAs Mandates & Deliverables | [Art. 11(11)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | Deadline: ESAs issue guidelines on oversight cooperation and information exchange | ESAs Mandates & Deliverables | [Art. 32(7)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | Deadline: ESAs submit draft RTS on subcontracting assessments | ESAs Mandates & Deliverables | [Art. 30(5)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | Deadline: ESAs submit draft RTS enabling the conduct of oversight activities | ESAs Mandates & Deliverables | [Art. 41(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | ESAs publish second batch of policy products (incl. TLPT RTS) | ESAs Mandates & Deliverables | [Source](https://www.esma.europa.eu/press-news/esma-news/esas-published-second-batch-policy-products-under-dora?ref=sorena.io) |
| 2024-07-17 | Deadline: Commission delegated act on further criteria for critical ICT third-party designation | Commission Mandates & Reviews | [Art. 31(6)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-07-17 | Deadline: Commission delegated act on oversight fees | Commission Mandates & Reviews | [Art. 43(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2024-11-29 | DORA CTPP Oversight Forum mandate (JC_24_93) | CTPP Oversight | [Source](https://www.eba.europa.eu/sites/default/files/2025-01/6536449d-31f1-4376-ab90-4570f6c3b81e/JC_24_93_Mandate%20Oversight%20Forum.pdf?ref=sorena.io) |
| 2024-12-02 | Implementing Reg. 2024/2956 published in OJ (register templates) | Register of Information | [Reg. (EU) 2024/2956](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2956&ref=sorena.io) |
| 2024-12-22 | Implementing Reg. 2024/2956 enters into force | Register of Information | [Reg. (EU) 2024/2956 Art. 7](https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj/eng?ref=sorena.io) |
| 2025-01-06 | DORA guidelines on oversight cooperation and information exchange: compliance deadline | Guidelines (Level 3) | [Source](https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/operational-resilience/joint-guidelines-oversight-cooperation-and-information-exchange-between-esas-and-competent?ref=sorena.io) |
| 2025-01-16 | Lead Overseer applies sub-criterion for CTPP designation (sub-criterion 1.4) | CTPP Oversight | [Delegated Reg. (EU) 2024/1502 Art. 7](https://eur-lex.europa.eu/eli/reg_del/2024/1502/oj/eng?ref=sorena.io) |
| 2025-01-17 | DORA applies | Applicability | [Art. 64](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2025-01-17 | DORA EU Hub feasibility report due | ESAs Mandates & Deliverables | [Art. 21(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2025-01-17 | DORA ESAs publish feasibility report on EU Hub centralisation (JC 2024 108) | ESAs Mandates & Deliverables | [Source](https://www.esma.europa.eu/press-news/esma-news/esas-publish-study-feasibility-further-centralisation-major-ict-related?ref=sorena.io) |
| 2025-01-17 | Member States notify penalty and criminal-law measures | National Obligations | [Art. 53](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2025-01-17 | DORA guidelines on oversight cooperation and information exchange: application date | Guidelines (Level 3) | [Source](https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/operational-resilience/joint-guidelines-oversight-cooperation-and-information-exchange-between-esas-and-competent?ref=sorena.io) |
| 2025-01-17 | Oversight Forum mandate applies | CTPP Oversight | [Source](https://www.eba.europa.eu/sites/default/files/2025-01/6536449d-31f1-4376-ab90-4570f6c3b81e/JC_24_93_Mandate%20Oversight%20Forum.pdf?ref=sorena.io) |
| 2025-02-13 | Delegated Reg. 2025/295 published in OJ (CTPP oversight activities) | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/295](https://eur-lex.europa.eu/eli/reg_del/2025/295/oj/eng?ref=sorena.io) |
| 2025-02-20 | Delegated Reg. 2025/301 published in OJ (incident reporting RTS) | Delegated & Implementing Acts (OJ) | [OJ L, 2025/301, 20.2.2025](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng?ref=sorena.io) |
| 2025-02-20 | Implementing Regulation 2025/302 - incident reporting templates (ITS) | Delegated & Implementing Acts (OJ) | [OJ L, 2025/302, 20.2.2025](https://eur-lex.europa.eu/eli/reg_impl/2025/302/oj/eng?ref=sorena.io) |
| 2025-03-05 | Delegated Reg. 2025/295 enters into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/295](https://eur-lex.europa.eu/eli/reg_del/2025/295/oj/eng?ref=sorena.io) |
| 2025-03-06 | Corrigendum (01) to Delegated Reg. 2024/1774 | Corrigendum | [Source](https://eur-lex.europa.eu/eli/reg_del/2024/1774/corrigendum/2025-03-06/oj/eng?ref=sorena.io) |
| 2025-03-12 | Incident reporting RTS/ITS enter into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/301 Art. 7; Reg. (EU) 2025/302 Art. 9](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng?ref=sorena.io) |
| 2025-03-24 | Delegated Reg. 2025/420 published in OJ (Joint Examination Teams) | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/420](https://eur-lex.europa.eu/eli/reg_del/2025/420/oj/eng?ref=sorena.io) |
| 2025-04-13 | Delegated Reg. 2025/420 enters into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/420 Art. 6](https://eur-lex.europa.eu/eli/reg_del/2025/420/oj/eng?ref=sorena.io) |
| 2025-05-15 | Corrigendum (02) to Delegated Reg. 2024/1774 | Corrigendum | [Source](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32024R1774R%2802%29&ref=sorena.io) |
| 2025-05-19 | Application and compliance date - Guidelines on costs/losses estimation | Guidelines (Level 3) | [Source](https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/operational-resilience/joint-guidelines-estimation-aggregated-annual-costs-and-losses-caused-major-ict-related-incidents?ref=sorena.io) |
| 2025-06-18 | Delegated Reg. 2025/1190 published in OJ (TLPT RTS) | Delegated & Implementing Acts (OJ) | [OJ L, 2025/1190, 18.6.2025](https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng?ref=sorena.io) |
| 2025-07-02 | Delegated Reg. 2025/532 published in OJ (subcontracting assessments) | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/532](https://eur-lex.europa.eu/eli/reg_del/2025/532/oj/eng?ref=sorena.io) |
| 2025-07-08 | Delegated Reg. 2025/1190 enters into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/1190 Art. 17](https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng?ref=sorena.io) |
| 2025-07-22 | Delegated Reg. 2025/532 enters into force | Delegated & Implementing Acts (OJ) | [Reg. (EU) 2025/532 Art. 7](https://eur-lex.europa.eu/eli/reg_del/2025/532/oj/eng?ref=sorena.io) |
| 2025-09-11 | Corrigendum to Implementing Reg. 2025/302 (incident templates) | Corrigendum | [Source](https://eur-lex.europa.eu/eli/reg_impl/2025/302/corrigendum/2025-09-11/oj/eng?ref=sorena.io) |
| 2025-09-12 | Corrigendum to Delegated Reg. 2025/301 (non-EN) | Corrigendum | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202590712&ref=sorena.io) |
| 2025-09-19 | Corrigendum to Implementing Reg. 2024/2956 (register templates) | Corrigendum | [Source](https://eur-lex.europa.eu/eli/reg_impl/2024/2956/corrigendum/2025-09-19/oj/eng?ref=sorena.io) |
| 2025-11-18 | DORA first list of designated critical ICT third-party service providers (CTPPs) published | CTPP Oversight | [Source](https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers?ref=sorena.io) |
| 2026-01-17 | Commission review on auditors and audit firms due | Commission Mandates & Reviews | [Art. 58(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |
| 2028-01-17 | Commission review of DORA due | Commission Mandates & Reviews | [Art. 58(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) |

**Event details:**

- **2022-12-14 - DORA adopted**: Regulation (EU) 2022/2554 on digital operational resilience for the financial sector is adopted by the European Parliament and the Council (date of the act: 14 December 2022).
- **2022-12-27 - DORA published in Official Journal**: Regulation (EU) 2022/2554 is published in the Official Journal of the European Union (OJ L 333, 27.12.2022).
- **2022-12-27 - Alignment Directive (EU) 2022/2556 published**: Directive (EU) 2022/2556 is published, aligning sectoral directives with DORA; Member States must transpose it by 17 January 2025.
- **2023-01-16 - DORA enters into force**: DORA enters into force on the twentieth day following its publication in the Official Journal (27 December 2022 -> 16 January 2023).
- **2023-06-19 - DORA ESAs first batch public consultation opens**: First batch of DORA policy products consultation window opens.
- **2023-07-17 - Commission PSD2 review report deadline (cyber resilience of payment systems)**: Within the PSD2 review context, the Commission must submit a report to the European Parliament and Council no later than 17 July 2023 assessing the need for increased cyber resilience of payment systems and payment-processing activities.
- **2023-09-11 - DORA ESAs first batch public consultation closes**: Closure of first batch consultation window.
- **2023-12-08 - DORA ESAs second batch public consultation opens**: Second batch of DORA policy mandates consultation opens.
- **2024-01-17 - Deadline: ESAs submit first wave draft RTS/ITS to the Commission**: Deadline for ESAs (through the Joint Committee) to submit several draft RTS/ITS to the Commission, including RTS on ICT risk management, RTS on the simplified ICT risk management framework, RTS on incident classification (materiality thresholds), and draft ITS/RTS related to the register of information and ICT third-party risk policy.
- **2024-03-04 - DORA ESAs second batch public consultation closes**: Closure of second batch consultation window.
- **2024-05-30 - Delegated Regs. 2024/1502 and 2024/1505 published in OJ**: Delegated Regulations (EU) 2024/1502 (designation criteria for critical ICT third-party service providers; adopted 22 February 2024) and 2024/1505 (oversight fees; adopted 22 February 2024) are published in the Official Journal.
- **2024-06-19 - Delegated Regs. 2024/1502 and 2024/1505 enter into force**: The delegated acts on CTPP designation criteria and oversight fees enter into force on the twentieth day following their 30 May 2024 Official Journal publication. Delegated Regulation (EU) 2024/1502 also has a specific sub-criterion 1.4 application date of 16 January 2025.
- **2024-06-25 - Delegated Regs. 2024/1772, 2024/1773, 2024/1774 published in OJ**: Delegated Regulations (EU) 2024/1772 (incident classification), 2024/1773 (policy content for ICT third-party contractual arrangements supporting critical/important functions) and 2024/1774 (ICT risk management tools/methods and simplified framework) are published in the Official Journal (all adopted 13 March 2024).
- **2024-07-15 - Delegated Regs. 2024/1772, 2024/1773, 2024/1774 enter into force**: The Level 2 acts on incident classification, ICT third-party contractual-arrangement policy content, and ICT risk management tools/methods enter into force on the twentieth day following their 25 June 2024 Official Journal publication.
- **2024-07-17 - Deadline: ESAs submit draft RTS/ITS for incident reporting content and templates**: Deadline for ESAs (through the Joint Committee, in consultation with ENISA and the ECB) to submit to the Commission draft RTS on incident-report content and time limits, and draft ITS on standard forms/templates/procedures for reporting major ICT-related incidents and notifying significant cyber threats.
- **2024-07-17 - Deadline: ESAs submit draft RTS for TLPT (TIBER-EU framework)**: Deadline for ESAs (in agreement with the ECB) to submit to the Commission draft RTS specifying criteria and detailed requirements for threat-led penetration testing (TLPT), including methodology phases, internal testers, and cooperation/mutual recognition aspects.
- **2024-07-17 - Deadline: ESAs develop guidelines on annual costs and losses from major incidents**: Deadline for ESAs (through the Joint Committee) to develop common guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents.
- **2024-07-17 - Deadline: ESAs issue guidelines on oversight cooperation and information exchange**: Deadline for ESAs to issue guidelines on cooperation between ESAs and competent authorities under the CTPP oversight framework, including task allocation/execution procedures and information-exchange details needed for follow-up of Lead Overseer recommendations.
- **2024-07-17 - Deadline: ESAs submit draft RTS on subcontracting assessments**: Deadline for ESAs (through the Joint Committee) to submit to the Commission draft RTS specifying further which elements a financial entity needs to determine and assess when subcontracting ICT services supporting critical or important functions.
- **2024-07-17 - Deadline: ESAs submit draft RTS enabling the conduct of oversight activities**: Deadline for ESAs (through the Joint Committee) to submit to the Commission draft RTS specifying harmonised conditions enabling the conduct of oversight activities for critical ICT third-party service providers (including information requests, reporting, and Joint Examination Team arrangements).
- **2024-07-17 - ESAs publish second batch of policy products (incl. TLPT RTS)**: ESAs publish the second batch of DORA policy products, including the TLPT RTS and the draft RTS/ITS for incident reporting.
- **2024-07-17 - Deadline: Commission delegated act on further criteria for critical ICT third-party designation**: Deadline for the Commission to adopt a delegated act supplementing DORA by specifying further the criteria for the designation of ICT third-party service providers as critical for financial entities (implemented via Delegated Regulation (EU) 2024/1502 of 22 February 2024; OJ publication 30 May 2024).
- **2024-07-17 - Deadline: Commission delegated act on oversight fees**: Deadline for the Commission to adopt a delegated act determining the amount of the oversight fees to be paid by critical ICT third-party service providers and the way those fees are to be paid (implemented via Delegated Regulation (EU) 2024/1505 of 22 February 2024; OJ publication 30 May 2024).
- **2024-11-29 - DORA CTPP Oversight Forum mandate (JC_24_93)**: Mandate of the Oversight Forum as a Joint Committee Sub-Committee of the European Supervisory Authorities (JC 2024 93, dated 29 November 2024).
- **2024-12-02 - Implementing Reg. 2024/2956 published in OJ (register templates)**: Implementing Regulation (EU) 2024/2956 (adopted 29 November 2024) is published, laying down implementing technical standards establishing standard templates for the register of information.
- **2024-12-22 - Implementing Reg. 2024/2956 enters into force**: The register-of-information templates ITS enters into force on the twentieth day following its 2 December 2024 Official Journal publication.
- **2025-01-06 - DORA guidelines on oversight cooperation and information exchange: compliance deadline**: EBA's regulatory activity page lists 6 January 2025 as the compliance deadline for the Joint Guidelines on oversight cooperation and information exchange between the ESAs and competent authorities.
- **2025-01-16 - Lead Overseer applies sub-criterion for CTPP designation (sub-criterion 1.4)**: Under Delegated Regulation (EU) 2024/1502, the Lead Overseer applies sub-criterion 1.4 for the criticality assessment of ICT third-party service providers as of 16 January 2025.
- **2025-01-17 - DORA applies**: DORA applies from 17 January 2025.
- **2025-01-17 - DORA EU Hub feasibility report due**: ESAs joint report assessing the feasibility of further centralisation of incident reporting through a single EU Hub is due to the European Parliament, Council and Commission by 17 January 2025.
- **2025-01-17 - DORA ESAs publish feasibility report on EU Hub centralisation (JC 2024 108)**: ESAs publish their joint report on the feasibility of further centralising reporting of major ICT-related incidents through a single EU Hub (DORA Art. 21).
- **2025-01-17 - Member States notify penalty and criminal-law measures**: Member States must notify the Commission, ESMA, EBA and EIOPA of laws/regulations implementing the chapter on administrative penalties (and any relevant criminal law provisions) by 17 January 2025.
- **2025-01-17 - DORA guidelines on oversight cooperation and information exchange: application date**: Application date for the Joint Guidelines on oversight cooperation and information exchange between the ESAs and competent authorities.
- **2025-01-17 - Oversight Forum mandate applies**: The Oversight Forum mandate dated 29 November 2024 states that the mandate applies from 17 January 2025.
- **2025-02-13 - Delegated Reg. 2025/295 published in OJ (CTPP oversight activities)**: Delegated Regulation (EU) 2025/295 (adopted 24 October 2024) is published, specifying RTS on harmonised conditions enabling the conduct of oversight activities for critical ICT third-party service providers.
- **2025-02-20 - Delegated Reg. 2025/301 published in OJ (incident reporting RTS)**: Delegated Regulation (EU) 2025/301 (adopted 23 October 2024) specifies the content and time limits for the initial notification, and intermediate and final reports on, major ICT-related incidents, and the content of voluntary notifications of significant cyber threats.
- **2025-02-20 - Implementing Regulation 2025/302 - incident reporting templates (ITS)**: Implementing Regulation (EU) 2025/302 (adopted 23 October 2024) lays down implementing technical standards establishing the standard forms, templates and procedures for reporting major ICT-related incidents and notifying significant cyber threats, including use under transitional arrangements pending any EU Hub implementation (OJ publication 20 February 2025; earlier drafts sometimes used month-level dating).
- **2025-03-05 - Delegated Reg. 2025/295 enters into force**: The CTPP oversight-activities RTS enters into force on the twentieth day following its 13 February 2025 Official Journal publication.
- **2025-03-06 - Corrigendum (01) to Delegated Reg. 2024/1774**: First corrigendum to Delegated Regulation (EU) 2024/1774 (ICT risk management) published.
- **2025-03-12 - Incident reporting RTS/ITS enter into force**: Delegated Regulation (EU) 2025/301 and Implementing Regulation (EU) 2025/302 enter into force on the twentieth day following their 20 February 2025 Official Journal publication.
- **2025-03-24 - Delegated Reg. 2025/420 published in OJ (Joint Examination Teams)**: Delegated Regulation (EU) 2025/420 (adopted 16 December 2024) is published, specifying RTS on the composition, designation, tasks, and working arrangements of Joint Examination Teams for CTPP oversight.
- **2025-04-13 - Delegated Reg. 2025/420 enters into force**: The Joint Examination Team RTS enters into force on the twentieth day following its 24 March 2025 Official Journal publication.
- **2025-05-15 - Corrigendum (02) to Delegated Reg. 2024/1774**: Second corrigendum to Delegated Regulation (EU) 2024/1774 (ICT risk management) published.
- **2025-05-19 - Application and compliance date - Guidelines on costs/losses estimation**: Application and compliance date for the Joint Guidelines on estimating aggregated annual costs and losses caused by major ICT-related incidents.
- **2025-06-18 - Delegated Reg. 2025/1190 published in OJ (TLPT RTS)**: Delegated Regulation (EU) 2025/1190 (adopted 13 February 2025) specifies RTS on criteria and detailed requirements for threat-led penetration testing (TLPT).
- **2025-07-02 - Delegated Reg. 2025/532 published in OJ (subcontracting assessments)**: Delegated Regulation (EU) 2025/532 (adopted 24 March 2025) is published, specifying elements to determine and assess when subcontracting ICT services supporting critical or important functions.
- **2025-07-08 - Delegated Reg. 2025/1190 enters into force**: The TLPT RTS enters into force on the twentieth day following its 18 June 2025 Official Journal publication.
- **2025-07-22 - Delegated Reg. 2025/532 enters into force**: The subcontracting-assessment RTS enters into force on the twentieth day following its 2 July 2025 Official Journal publication.
- **2025-09-11 - Corrigendum to Implementing Reg. 2025/302 (incident templates)**: Corrigendum to Implementing Regulation (EU) 2025/302 published.
- **2025-09-12 - Corrigendum to Delegated Reg. 2025/301 (non-EN)**: Corrigendum to Delegated Regulation (EU) 2025/301 published; OJ note indicates it does not concern the English version.
- **2025-09-19 - Corrigendum to Implementing Reg. 2024/2956 (register templates)**: Corrigendum to Implementing Regulation (EU) 2024/2956 published.
- **2025-11-18 - DORA first list of designated critical ICT third-party service providers (CTPPs) published**: The European Supervisory Authorities publish the first list of designated critical ICT third-party service providers (CTPPs).
- **2026-01-17 - Commission review on auditors and audit firms due**: Commission must review and submit a report (and, where appropriate, a legislative proposal) on strengthened digital operational resilience requirements for statutory auditors and audit firms by 17 January 2026.
- **2028-01-17 - Commission review of DORA due**: Commission must review DORA and submit a report (and, where appropriate, a legislative proposal) by 17 January 2028.

## EU CRA Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2021-09-15 | CRA announced in State of the Union | Legislative History | [SOTEU 2021](https://commission.europa.eu/strategy-and-policy/state-union/state-union-2021_en?ref=sorena.io) |
| 2021-09-16 | Commission explainer on the CRA (quotes SOTEU speech) | Legislative History | [Source](https://commissioners.ec.europa.eu/how-european-cy-resilience-act-will-help-protect-europe-2021-09-16_en?ref=sorena.io) |
| 2022-03-16 | CRA public consultation | Legislative History | [Source](https://digital-strategy.ec.europa.eu/en/news/commission-invites-citizens-and-organisations-share-their-views-european-cyber-resilience-act?ref=sorena.io) |
| 2022-09-15 | CRA Commission proposal published | Legislative History | [COM(2022) 454](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0454&ref=sorena.io#:~:text=Brussels%2C%2015.9.2022%20COM(2022)454%20final) |
| 2023-06-08 | CRA Council general approach | Legislative History | [Source](https://www.consilium.europa.eu/en/policies/cybersecurity/timeline-cybersecurity/?ref=sorena.io#:~:text=The%20general%20approach%20on%20this%20proposal%20was%20reached%20on%208%20June) |
| 2023-07-19 | CRA Council common position | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2023/07/19/cyber-resilience-act-member-states-agree-common-position-on-security-requirements-for-digital-products/?ref=sorena.io) |
| 2023-07-19 | EP ITRE Committee adopts report | Legislative History | [Source](https://www.europarl.europa.eu/legislative-train/carriage/european-cyber-resilience-act/report?sid=7801&ref=sorena.io) |
| 2023-09-01 | Parliament enters interinstitutional negotiations | Legislative History | [Source](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-european-cyber-resilience-act?ref=sorena.io#:~:text=Parliament%20confirmed%20committee%20decision%20to%20enter%20into%20interinstitutional%20negotiations%20in%20September%202023) |
| 2023-11-30 | CRA political agreement reached | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2023/11/30/cyber-resilience-act-council-and-parliament-strike-a-deal-on-security-requirements-for-digital-products/?ref=sorena.io) |
| 2023-12-01 | Parliament press release on political agreement | Legislative History | [Source](https://www.europarl.europa.eu/news/en/press-room/20231106IPR09007/cyber-resilience-act-agreement-with-council-to-boost-digital-products-security?ref=sorena.io) |
| 2024-03-12 | Parliament plenary adoption | Legislative History | [P9_TA(2024)0130](https://www.europarl.europa.eu/news/en/press-room/20240308IPR18991/cyber-resilience-act-meps-adopt-plans-to-boost-security-of-digital-products?ref=sorena.io) |
| 2024-10-10 | CRA Council formal adoption | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2024/10/10/cyber-resilience-act-council-adopts-new-law-on-security-requirements-for-digital-products/?ref=sorena.io) |
| 2024-10-23 | EU Cyber Resilience Act date | Official Publication | [Reg. (EU) 2024/2847](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io) |
| 2024-11-20 | CRA published in Official Journal | Official Publication | [OJ L 2024/2847](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847&ref=sorena.io) |
| 2024-12-05 | Corrigendum: editorial title fix | Corrigendum | [Source](https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2024-12-05/oj/eng?ref=sorena.io#:~:text=On%20page%201%2C%20in%20the%20title%3A%20for%3A%20%E2%80%98Regulation%20(EU)%202024/2847) |
| 2024-12-10 | CRA entry into force | Applicability | [Art. 71(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io#:~:text=This%20Regulation%20shall%20enter%20into%20force%20on%20the%20twentieth%20day) |
| 2024-12-10 | Delegated powers conferred (5-year period begins) | Delegated & Implementing Acts | [Art. 61(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io#:~:text=shall%20be%20conferred%20on%20the%20Commission%20for%20a%20period%20of%20five%20years%20from%2010%20December%202024) |
| 2025-02-03 | Standardisation request M/606 adopted | Standardisation | [C(2025) 618](https://digital-strategy.ec.europa.eu/en/policies/cra-standardisation?ref=sorena.io#:~:text=has%20adopted%20a%20standardisation%20request%20M/606) |
| 2025-04-03 | M/606 officially accepted by CEN-CENELEC | Standardisation | [M/606](https://www.cencenelec.eu/news-events/news/2025/newsletter/ots-62-cra/?ref=sorena.io#:~:text=On%203%20April%2C%20the%20Standardization%20Request%20for%20the%20Cyber%20Resilience%20Act%20(CRA)%20was%20officially%20accepted) |
| 2025-07-02 | Corrigendum: Art. 64(10) cross-reference | Corrigendum | [Art. 64(10)](https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2025-07-02/oj/eng?ref=sorena.io#:~:text=By%20way%20of%20derogation%20from%20paragraphs%202%20to%209) |
| 2025-07-29 | Delegated Reg. 2025/1535 adopted | Delegated & Implementing Acts | [Reg. (EU) 2025/1535](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202501535&ref=sorena.io#:~:text=COMMISSION%20DELEGATED%20REGULATION%20(EU)%202025/1535) |
| 2025-10-03 | Corrigendum: Annex I language fix | Corrigendum | [Annex I](https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2025-10-03/oj/eng?ref=sorena.io#:~:text=annexe%20I%2C%20partie%20I%2C%20paragraphe%202)%2C%20point%20c) |
| 2025-10-17 | Corrigendum: Art. 67 numbering | Corrigendum | [Art. 67](https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2025-10-17/oj/eng?ref=sorena.io#:~:text=On%20page%2066%2C%20in%20Article%2067) |
| 2025-10-29 | Delegated Reg. 2025/1535 published in OJ | Delegated & Implementing Acts | [OJ L 2025/1535](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202501535&ref=sorena.io) |
| 2025-11-18 | Delegated Reg. 2025/1535 enters into force | Delegated & Implementing Acts | [Reg. (EU) 2025/1535](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202501535&ref=sorena.io) |
| 2025-11-28 | Implementing Reg. 2025/2392 adopted | Delegated & Implementing Acts | [Reg. (EU) 2025/2392](https://eur-lex.europa.eu/eli/reg_impl/2025/2392/oj/eng?ref=sorena.io) |
| 2025-12-01 | Implementing Reg. 2025/2392 published in OJ | Delegated & Implementing Acts | [OJ L 2025/2392](https://eur-lex.europa.eu/eli/reg_impl/2025/2392/oj/eng?ref=sorena.io) |
| 2025-12-11 | Delegated act on CSIRT notification delays | Delegated & Implementing Acts | [Art. 16(2)](https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation?ref=sorena.io#:~:text=11%20December%202025%20%20%20Delegated%20act%20on%20CSIRTs%20withholding%20notifications) |
| 2025-12-11 | Delegated act record published on EUR-Lex | Delegated & Implementing Acts | [C(2025) 8407](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=PI_COM%3AC(2025)8407&ref=sorena.io) |
| 2025-12-21 | Implementing Reg. 2025/2392 enters into force | Delegated & Implementing Acts | [Reg. (EU) 2025/2392](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202502392&ref=sorena.io#:~:text=This%20Regulation%20shall%20enter%20into%20force%20on%20the%20twentieth%20day) |
| 2026-03-03 | Draft CRA guidance published for feedback | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/news/commission-publishes-feedback-draft-guidance-assist-companies-applying-cyber-resilience-act?ref=sorena.io) |
| 2026-03-31 | Feedback closes on draft CRA guidance | Commission Deliverables | [Source](https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/16959-Draft-Commission-guidance-on-the-Cyber-Resilience-Act_en?ref=sorena.io) |
| 2026-06-11 | Chapter IV applies: notified bodies | Conformity Assessment | [Art. 35-51](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io#:~:text=However%2C%20Article%2014%20shall%20apply%20from%2011%20September%202026%20and%20Chapter%20IV%20(Articles%2035%20to%2051)%20shall%20apply%20from%2011%20June%202026) |
| 2026-06-11 | Notified bodies listed on NANDO/SMCS (as they are designated) | Conformity Assessment | [Source](https://digital-strategy.ec.europa.eu/en/policies/cra-conformity-assessment?ref=sorena.io#:~:text=Once%20a%20conformity%20assessment%20body%20has%20become%20a%20notified%20body%20it%20will%20be%20published%20on%20the%20NANDO%20website) |
| 2026-09-11 | Vulnerability reporting obligations apply | Vulnerability Reporting | [Art. 14](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io#:~:text=Article%2014%20shall%20apply%20from%2011%20September%202026) |
| 2026-09-11 | CRA reporting deadlines (24h / 72h / 14d / 1 month) | Vulnerability Reporting | [Source](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?ref=sorena.io) |
| 2026-09-11 | Open-source software stewards: reporting obligations apply (conditional) | Vulnerability Reporting | [Art. 24(3), Art. 14](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847&ref=sorena.io#:~:text=The%20obligations%20laid%20down%20in%20Article%2014(1)%20shall%20apply%20to%20open%2Dsource%20software%20stewards) |
| 2026-09-11 | Single Reporting Platform operational by this date | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?ref=sorena.io#:~:text=The%20Single%20Reporting%20Platform%20will%20be%20operational%20by%2011%20September%202026) |
| 2027-12-11 | CRA applies in full | Applicability | [Art. 71(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io#:~:text=This%20Regulation%20shall%20apply%20from%2011%20December%202027) |
| 2027-12-11 | Legacy products: substantial modification rule | Applicability | [Source](https://digital-strategy.ec.europa.eu/en/policies/cra-summary?ref=sorena.io) |
| 2027-12-11 | Economic operators obligations apply (importers, distributors, authorised representatives) | Applicability | [Arts. 18-21](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847&ref=sorena.io#:~:text=Article%2019) |
| 2027-12-11 | Open-source software stewards: Article 24 obligations apply | Applicability | [Art. 24(1)-(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847&ref=sorena.io#:~:text=Open%2Dsource%20software%20stewards%20shall%20put%20in%20place%20and%20document%20in%20a%20verifiable%20manner) |
| 2029-12-10 | End of initial 5-year delegation period (unless extended) | Delegated & Implementing Acts | [Art. 61(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=sorena.io#:~:text=shall%20be%20conferred%20on%20the%20Commission%20for%20a%20period%20of%20five%20years%20from%2010%20December%202024) |

**Event details:**

- **2021-09-15 - CRA announced in State of the Union**: President von der Leyen announces the CRA in the State of the Union address: 'including legislation on common standards under a new European Cyber Resilience Act.'
- **2021-09-16 - Commission explainer on the CRA (quotes SOTEU speech)**: Commission explainer page published the day after SOTEU highlights the CRA and quotes the speech's CRA passage.
- **2022-03-16 - CRA public consultation**: Commission launches CRA public consultation, open 16 March to 25 May 2022.
- **2022-09-15 - CRA Commission proposal published**: Commission presents the CRA proposal COM(2022) 454 final.
- **2023-06-08 - CRA Council general approach**: Council reaches its 'general approach' (negotiating mandate) on the CRA at the JHA Council meeting.
- **2023-07-19 - CRA Council common position**: Member States agree a common position on security requirements for digital products.
- **2023-07-19 - EP ITRE Committee adopts report**: EP ITRE Committee adopts its report/position on the CRA.
- **2023-09-01 - Parliament enters interinstitutional negotiations**: Parliament confirms its committee decision to enter interinstitutional (trilogue) negotiations in September 2023.
- **2023-11-30 - CRA political agreement reached**: Council and Parliament reach provisional political agreement on the CRA.
- **2023-12-01 - Parliament press release on political agreement**: European Parliament press release on the agreement reached with the Council to boost digital products security.
- **2024-03-12 - Parliament plenary adoption**: European Parliament adopts the CRA in plenary: 517 in favour, 12 against, 78 abstentions.
- **2024-10-10 - CRA Council formal adoption**: Council formally adopts the Cyber Resilience Act.
- **2024-10-23 - EU Cyber Resilience Act date**: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 (Cyber Resilience Act) is signed.
- **2024-11-20 - CRA published in Official Journal**: CRA published in the Official Journal of the European Union (OJ L 2024/2847, 20.11.2024).
- **2024-12-05 - Corrigendum: editorial title fix**: First corrigendum: corrects '(EU) No 2019/1020' to '(EU) 2019/1020' in the regulation title.
- **2024-12-10 - CRA entry into force**: CRA enters into force on the 20th day following OJ publication (20 Nov + 20 days = 10 Dec 2024).
- **2024-12-10 - Delegated powers conferred (5-year period begins)**: Delegation of power to the Commission is conferred for a period of five years from 10 December 2024, with tacit extensions unless opposed.
- **2025-02-03 - Standardisation request M/606 adopted**: Commission adopts CRA standardisation request M/606 containing 41 standards. Accepted by CEN, CENELEC, and ETSI on 3 April 2025.
- **2025-04-03 - M/606 officially accepted by CEN-CENELEC**: CEN-CENELEC officially accepted the CRA standardisation request on 3 April 2025.
- **2025-07-02 - Corrigendum: Art. 64(10) cross-reference**: Corrigendum fixes Article 64(10): 'paragraphs 3 to 9' corrected to 'paragraphs 2 to 9'.
- **2025-07-29 - Delegated Reg. 2025/1535 adopted**: Commission excludes most L-category vehicle products from CRA scope (exception for L1e pedal-designed). OJ publication 29 Oct 2025; enters into force 20 days later.
- **2025-10-03 - Corrigendum: Annex I language fix**: Corrigendum fixes FR/HU language wording in Annex I, Part I, paragraph 2, point (c).
- **2025-10-17 - Corrigendum: Art. 67 numbering**: Corrigendum fixes numbering reference in Article 67: '69' corrected to '72'.
- **2025-10-29 - Delegated Reg. 2025/1535 published in OJ**: Delegated Regulation (EU) 2025/1535 is published in the Official Journal on 29 October 2025.
- **2025-11-18 - Delegated Reg. 2025/1535 enters into force**: Delegated Regulation (EU) 2025/1535 enters into force on the twentieth day following its OJ publication.
- **2025-11-28 - Implementing Reg. 2025/2392 adopted**: Commission adopts technical descriptions for Annex III/IV product categories (important and critical products). OJ publication 1 Dec 2025; enters into force 20 days later.
- **2025-12-01 - Implementing Reg. 2025/2392 published in OJ**: Implementing Regulation (EU) 2025/2392 is published in the Official Journal on 1 December 2025.
- **2025-12-11 - Delegated act on CSIRT notification delays**: Commission adopts delegated act specifying terms and conditions for delaying dissemination of vulnerability notifications by CSIRTs under Article 16(2).
- **2025-12-11 - Delegated act record published on EUR-Lex**: EUR-Lex record for the Commission delegated act concerning Article 16(2) conditions for CSIRTs delaying dissemination to other CSIRTs.
- **2025-12-21 - Implementing Reg. 2025/2392 enters into force**: Implementing Regulation (EU) 2025/2392 enters into force on the twentieth day following its OJ publication.
- **2026-03-03 - Draft CRA guidance published for feedback**: Commission publishes draft CRA guidance for stakeholder feedback, clarifying scope, remote data processing, free and open-source software, support periods, and interplay with other EU law.
- **2026-03-31 - Feedback closes on draft CRA guidance**: The stakeholder feedback period on the Commission's draft CRA guidance closes on 31 March 2026.
- **2026-06-11 - Chapter IV applies: notified bodies**: CRA Chapter IV (Articles 35-51) on notification of conformity assessment bodies begins to apply.
- **2026-06-11 - Notified bodies listed on NANDO/SMCS (as they are designated)**: From the Chapter IV applicability date, conformity assessment bodies can be notified under the CRA framework and, once notified, will appear in the Commission's NANDO/SMCS notified bodies list for the CRA.
- **2026-09-11 - Vulnerability reporting obligations apply**: Article 14 (vulnerability and incident reporting) applies. Manufacturers must report actively exploited vulnerabilities and severe incidents via ENISA's Single Reporting Platform.
- **2026-09-11 - CRA reporting deadlines (24h / 72h / 14d / 1 month)**: From the Article 14 applicability date, incident/vulnerability notifications follow operational time limits (early warning within 24 hours of awareness; full notification within 72 hours; final report timelines depending on case, such as 14 days or 1 month).
- **2026-09-11 - Open-source software stewards: reporting obligations apply (conditional)**: Open-source software stewards are subject to Article 14(1) (and, where applicable, Article 14(3) and (8)) to the extent they are involved in development, from the date Article 14 applies.
- **2026-09-11 - Single Reporting Platform operational by this date**: Commission states ENISA's Single Reporting Platform (SRP) will be operational by 11 September 2026 to support CRA vulnerability and incident reporting.
- **2027-12-11 - CRA applies in full**: General application date: the CRA applies in full from 11 December 2027.
- **2027-12-11 - Legacy products: substantial modification rule**: Products placed on the EU market before 11 December 2027 are subject to CRA product requirements only if, from that date, they undergo a substantial modification; reporting obligations still apply from the earlier reporting applicability date.
- **2027-12-11 - Economic operators obligations apply (importers, distributors, authorised representatives)**: From the general CRA application date, authorised representatives, importers, and distributors must comply with their CRA obligations; in certain cases (e.g., own-branding or substantial modification) importers/distributors are treated as manufacturers.
- **2027-12-11 - Open-source software stewards: Article 24 obligations apply**: Open-source software stewards must have a verifiable cybersecurity policy for secure development and vulnerability handling, and cooperate with market surveillance authorities (subject to CRA scope).
- **2029-12-10 - End of initial 5-year delegation period (unless extended)**: The initial five-year period for the Commission's delegated powers runs until 10 December 2029, subject to tacit extensions unless opposed.

## EU Data Act Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2020-02-19 | European data strategy announced | Legislative History | [Source](https://ec.europa.eu/commission/presscorner/detail/en/ip_20_273?ref=sorena.io) |
| 2021-03-25 | Parliament urges a Data Act | Legislative History | [Source](https://www.europarl.europa.eu/doceo/document/TA-9-2021-0098_EN.pdf?ref=sorena.io) |
| 2021-05-28 | Inception impact assessment opened | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022PC0068&ref=sorena.io) |
| 2021-06-03 | Public consultation on the Data Act | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022PC0068&ref=sorena.io) |
| 2021-09-29 | Impact assessment submitted to RSB | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022PC0068&ref=sorena.io) |
| 2021-12-13 | Revised impact assessment submitted to RSB | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022PC0068&ref=sorena.io) |
| 2022-01-21 | Regulatory Scrutiny Board positive opinion | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022PC0068&ref=sorena.io) |
| 2022-02-14 | Impact assessment package published | Legislative History | [Source](https://digital-strategy.ec.europa.eu/en/library/impact-assessment-report-and-support-studies-accompanying-proposal-data-act?ref=sorena.io) |
| 2022-02-23 | Commission proposal published | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022PC0068&ref=sorena.io) |
| 2022-05-04 | EDPB and EDPS joint opinion | Legislative History | [Source](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2022-06-15 | European Economic and Social Committee opinion | Legislative History | [Source](https://data.consilium.europa.eu/doc/document/ST-15213-2023-INIT/en/pdf?ref=sorena.io) |
| 2022-06-30 | Committee of the Regions opinion | Legislative History | [Source](https://data.consilium.europa.eu/doc/document/ST-15213-2023-INIT/en/pdf?ref=sorena.io) |
| 2022-09-05 | European Central Bank opinion | Legislative History | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52022AB0030&ref=sorena.io) |
| 2023-02-09 | Parliament ITRE report adopted | Legislative History | [Source](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-data-act?ref=sorena.io) |
| 2023-03-14 | Parliament negotiating mandate adopted | Legislative History | [Source](https://www.europarl.europa.eu/news/en/press-room/20230310IPR77226/data-act-meps-back-new-rules-for-fair-access-to-and-use-of-industrial-data?ref=sorena.io) |
| 2023-03-24 | Council general approach agreed | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2023/03/24/data-act-member-states-agree-common-position-on-fair-access-to-and-use-of-data/?ref=sorena.io) |
| 2023-06-27 | Political agreement reached | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2023/06/27/data-act-council-and-parliament-strike-a-deal-on-fair-access-to-and-use-of-data/?ref=sorena.io) |
| 2023-07-14 | Council undertaking letter | Legislative History | [Source](https://data.consilium.europa.eu/doc/document/ST-15213-2023-INIT/en/pdf?ref=sorena.io) |
| 2023-11-09 | European Parliament position adopted | Legislative History | [Source](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2023-11-27 | Council decision adopted | Legislative History | [Source](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2023-12-13 | Regulation adopted (Data Act) | Legislative History | [Source](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2023-12-22 | Data Act published in the Official Journal | Official Publication | [Source](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2024-01-11 | Data Act enters into force | Official Publication | [Art. 50](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2024-01-11 | Reduced switching charges period | Cloud Switching | [Art. 29(2)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2024-01-11 | Data Act delegated powers conferred on the Commission | Commission Deliverables | [Art. 45(2), 45(6)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2024-01-11 | Other EU data-sharing law alignment window | Applicability | [Art. 44(1)](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2024-09-06 | Data Act FAQs published (v1.0) | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2024-09-13 | Data Act FAQs updated (v1.1) | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2024-12-09 | Data Act Official Journal corrigendum published | Official Publication | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202490790&ref=sorena.io) |
| 2025-02-03 | Data Act FAQs updated (v1.2) | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2025-07-01 | Commission standardisation request (European Trusted Data Framework) | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2025-07-07 | CEN and CENELEC accept Mandate M/614 | Standardisation | [Art. 33; Mandate M/614](https://www.cencenelec.eu/news-events/news/2025/brief-news/2025-07-11-data-act-standardization-request/?ref=sorena.io) |
| 2025-09-12 | Data Act applies | Applicability | [Art. 50](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | Chapter II access and data-use scope starts | Applicability | [Ch. II; Arts. 3-5; Art. 4(13)](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2025-09-12 | Chapter III and IV transition rules start | Applicability | [Art. 50](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | Member States notify penalty rules | Member State Duties | [Art. 40(2)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | Article 41 pre-application deadline boundary | Commission Deliverables | [Art. 41](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | Data Act FAQs updated (v1.3) | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2025-09-12 | Vehicle-data guidance page published | Commission Deliverables | [Ch. II](https://digital-strategy.ec.europa.eu/en/library/guidance-vehicle-data-accompanying-data-act?ref=sorena.io) |
| 2025-09-12 | Cloud switching process clocks apply | Cloud Switching | [Art. 25](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | B2G exceptional-need response clocks apply | Applicability | [Art. 18(2)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | Interoperability repository mechanism applies | Cloud Switching | [Arts. 30(3), 35(8)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-12 | Smart-contract requirements apply | Applicability | [Art. 36](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2025-09-15 | Vehicle-data guidance published in the Official Journal | Commission Deliverables | [Source](https://eur-lex.europa.eu/eli/C/2025/5026/oj/eng?ref=sorena.io) |
| 2025-11-19 | Model terms and cloud clauses published | Commission Deliverables | [Art. 41](https://digital-strategy.ec.europa.eu/en/library/draft-recommendation-non-binding-model-contractual-terms-data-access-and-use-and-non-binding?ref=sorena.io) |
| 2025-11-19 | Data Union Strategy frames Data Act support package | Commission Deliverables | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52025DC0835&ref=sorena.io) |
| 2025-12-16 | Data Act Legal Helpdesk launched | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/news/commission-launches-data-act-legal-helpdesk?ref=sorena.io) |
| 2026-01-22 | Data Act FAQs updated (v1.4) | Commission Deliverables | [Source](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-frequently-asked-questions-about-data-act?ref=sorena.io) |
| 2026-01-30 | Data Act reasonable-compensation guidelines consultation | Commission Deliverables | [Art. 9](https://digital-strategy.ec.europa.eu/en/consultations/data-act-commission-seeks-feedback-draft-guidelines-reasonable-compensation?ref=sorena.io) |
| 2026-03-01 | Data catalogue technical specification deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2026-03-19 | 2026 Union standardisation work programme published | Standardisation | [Arts. 30, 35; Art. 33](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AC_202601695&ref=sorena.io) |
| 2026-06-01 | Trusted Data Transactions Part 1 deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2026-09-01 | Semantic assets technical specification deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2026-09-01 | Common European Data Spaces maturity model deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2026-09-12 | Connected product access-by-design obligations | Applicability | [Art. 3(1), Art. 50](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2026-11-01 | Trusted Data Transactions Part 2 deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2027-01-12 | Switching charges prohibited | Cloud Switching | [Art. 29(1)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2027-03-01 | Internal data governance quality framework deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2027-05-01 | Trusted Data Transactions Part 3 deadline | Standardisation | [Art. 33; Mandate M/614](https://ec.europa.eu/transparency/documents-register/api/files/C(2025)4135_1/de00000001072897?rendition=false&ref=sorena.io) |
| 2027-09-12 | Chapter IV extends to older contracts | Applicability | [Art. 50](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |
| 2028-09-12 | Commission evaluation reports due | Commission Deliverables | [Art. 49(1), 49(2)](https://eur-lex.europa.eu/eli/reg/2023/2854/oj/eng?ref=sorena.io) |

**Event details:**

- **2020-02-19 - European data strategy announced**: The Commission announces the European data strategy, the policy programme that later leads to the Data Governance Act, Data Act, data spaces work, and the EU single market for data.
- **2021-03-25 - Parliament urges a Data Act**: The European Parliament resolution on a European strategy for data urges the Commission to present a Data Act to encourage greater and fairer data flows across B2B, B2G, G2B and G2G settings.
- **2021-05-28 - Inception impact assessment opened**: The Data Act proposal records that an Inception Impact Assessment was published on the Better Regulation portal on 28 May 2021 and left open for feedback for four weeks.
- **2021-06-03 - Public consultation on the Data Act**: The Commission runs the Data Act public online consultation from 3 June 2021 to 3 September 2021, covering B2B, B2G, consumer empowerment, cloud switching, database rights, smart contracts, and international safeguards.
- **2021-09-29 - Impact assessment submitted to RSB**: The Data Act proposal records that the impact assessment was submitted to the Regulatory Scrutiny Board on 29 September 2021, before a later revised submission.
- **2021-12-13 - Revised impact assessment submitted to RSB**: The Data Act proposal records a second impact-assessment submission to the Regulatory Scrutiny Board on 13 December 2021, preceding the Board's positive opinion with reservations.
- **2022-01-21 - Regulatory Scrutiny Board positive opinion**: The Data Act proposal records that the Regulatory Scrutiny Board issued a positive opinion subject to reservations on 21 January 2022 after two impact-assessment submissions.
- **2022-02-14 - Impact assessment package published**: The Commission publishes the impact assessment report, executive summary, Regulatory Scrutiny Board opinion, and support studies accompanying the Data Act proposal.
- **2022-02-23 - Commission proposal published**: The Commission publishes COM(2022) 68 final, the proposal for a Regulation on harmonised rules on fair access to and use of data (Data Act).
- **2022-05-04 - EDPB and EDPS joint opinion**: The final Regulation records that the European Data Protection Board and European Data Protection Supervisor delivered Joint Opinion 2/2022 on the Data Act proposal on 4 May 2022.
- **2022-06-15 - European Economic and Social Committee opinion**: The Parliament legislative text cites the European Economic and Social Committee opinion of 15 June 2022 in the Data Act legislative file.
- **2022-06-30 - Committee of the Regions opinion**: The Parliament legislative text cites the Committee of the Regions opinion of 30 June 2022 in the Data Act legislative file.
- **2022-09-05 - European Central Bank opinion**: The European Central Bank adopts its opinion on the Data Act proposal on 5 September 2022; the opinion is later published in the Official Journal on 19 October 2022.
- **2023-02-09 - Parliament ITRE report adopted**: The European Parliament ITRE committee adopts its Data Act report, moving the file toward plenary negotiating-mandate approval.
- **2023-03-14 - Parliament negotiating mandate adopted**: The European Parliament adopts its negotiating mandate on the Data Act before trilogue negotiations with the Council.
- **2023-03-24 - Council general approach agreed**: Member States agree the Council common position on fair access to and use of data under the proposed Data Act.
- **2023-06-27 - Political agreement reached**: The Council and Parliament reach a provisional political agreement on the Data Act; the Commission press release welcoming the agreement is dated 28 June 2023.
- **2023-07-14 - Council undertaking letter**: The Parliament legislative text records the Council representative's 14 July 2023 undertaking to approve Parliament's position, clearing the path for adoption under the ordinary legislative procedure.
- **2023-11-09 - European Parliament position adopted**: The Regulation records the European Parliament position of 9 November 2023 in the legislative history footnote.
- **2023-11-27 - Council decision adopted**: The Regulation records the Council decision of 27 November 2023 in the legislative history footnote.
- **2023-12-13 - Regulation adopted (Data Act)**: Regulation (EU) 2023/2854 is adopted and signed in Strasbourg.
- **2023-12-22 - Data Act published in the Official Journal**: Regulation (EU) 2023/2854 is published in the Official Journal (OJ L, 2023/2854, 22.12.2023).
- **2024-01-11 - Data Act enters into force**: The Data Act enters into force on the twentieth day following publication in the Official Journal.
- **2024-01-11 - Reduced switching charges period**: From 11 January 2024 to 12 January 2027, providers of data processing services may impose only reduced switching charges for the switching process.
- **2024-01-11 - Data Act delegated powers conferred on the Commission**: The Commission receives delegated powers for an indeterminate period from 11 January 2024; delegated acts are subject to a three-month Parliament/Council objection period, extendable by three months.
- **2024-01-11 - Other EU data-sharing law alignment window**: Union data-sharing obligations in force on or before 11 January 2024 remain unaffected; for Union data rules entering into force between 11 January 2024 and 12 September 2025, the Commission FAQ explains that best efforts should be made to align them with the Data Act.
- **2024-09-06 - Data Act FAQs published (v1.0)**: The Commission publishes Frequently Asked Questions about the Data Act to support implementation; the FAQ version history records version 1.0 on 6 September 2024.
- **2024-09-13 - Data Act FAQs updated (v1.1)**: The Commission FAQ version history records Data Act FAQ version 1.1 on 13 September 2024.
- **2024-12-09 - Data Act Official Journal corrigendum published**: A corrigendum to Regulation (EU) 2023/2854 is published in the Official Journal; the timeline note records it as an editorial numbering correction with no substantive obligation change.
- **2025-02-03 - Data Act FAQs updated (v1.2)**: The Commission FAQ version history records Data Act FAQ version 1.2 on 3 February 2025.
- **2025-07-01 - Commission standardisation request (European Trusted Data Framework)**: Commission Implementing Decision C(2025) 4135 issues Mandate M/614 to CEN, CENELEC and ETSI for European Trusted Data Framework deliverables supporting Data Act Article 33.
- **2025-07-07 - CEN and CENELEC accept Mandate M/614**: CEN and CENELEC accept the Commission standardisation request on the European Trusted Data Framework; the public acceptance notice is posted on 11 July 2025.
- **2025-09-12 - Data Act applies**: The Data Act applies from 12 September 2025, making the main access, use, B2G, cloud switching, interoperability, smart-contract, database-right, enforcement, and transitional rules operational unless a provision has a different timing rule.
- **2025-09-12 - Chapter II access and data-use scope starts**: Commission FAQs explain that Chapter II covers only data generated or collected after the Data Act enters into application, that access can be direct or indirect, and that data holders need a contract with users to use readily available data from 12 September 2025.
- **2025-09-12 - Chapter III and IV transition rules start**: Chapter III applies to data-availability obligations under Union or national law that enter into force after 12 September 2025, and Chapter IV applies to data-sharing contracts concluded after 12 September 2025.
- **2025-09-12 - Member States notify penalty rules**: Member States must notify the Commission of penalties rules and measures by 12 September 2025 and notify later amendments without delay.
- **2025-09-12 - Article 41 pre-application deadline boundary**: Article 41 requires the Commission, before 12 September 2025, to develop and recommend non-binding model contractual terms on data access and use and non-binding standard contractual clauses for cloud computing contracts; the later publication event records the actual 19 November 2025 publication.
- **2025-09-12 - Data Act FAQs updated (v1.3)**: The Commission FAQ version history records Data Act FAQ version 1.3 on 12 September 2025, aligned with the general application date.
- **2025-09-12 - Vehicle-data guidance page published**: The Commission publishes guidance on vehicle data accompanying the Data Act on the Digital Strategy site, focusing on Chapter II access rules in the automotive context.
- **2025-09-12 - Cloud switching process clocks apply**: Chapter VI switching contracts must support the Article 25 process limits: two-month maximum notice, 30-calendar-day mandatory transition, 14-working-day notice if technically unfeasible, any alternative transition capped at seven months, and at least 30 calendar days for data retrieval.
- **2025-09-12 - B2G exceptional-need response clocks apply**: Data holders must decline or seek modification without undue delay and no later than five working days for public-emergency requests or 30 working days for other exceptional-need requests.
- **2025-09-12 - Interoperability repository mechanism applies**: From the general application date, the Article 30(3) and 35(8) repository mechanism is in force; for non-IaaS data processing services, the 12-month compatibility clock starts only after common specifications or harmonised-standard references are published in the central Union standards repository through implementing acts.
- **2025-09-12 - Smart-contract requirements apply**: Vendors of applications using smart contracts for automated execution of data-sharing agreements must meet Article 36 essential requirements and EU declaration of conformity duties from the general application date.
- **2025-09-15 - Vehicle-data guidance published in the Official Journal**: Commission Communication C/2025/5026 on vehicle data accompanying the Data Act is published in the Official Journal on 15 September 2025.
- **2025-11-19 - Model terms and cloud clauses published**: The Commission publishes non-binding Model Contractual Terms for data access and use and Standard Contractual Clauses for cloud computing contracts to help parties implement the Data Act.
- **2025-11-19 - Data Union Strategy frames Data Act support package**: The Commission's Data Union Strategy is issued as COM(2025) 835 final and describes the Data Act support package, including model contracts, standard cloud clauses, reasonable-compensation guidance, trade-secret guidance, and a legal helpdesk.
- **2025-12-16 - Data Act Legal Helpdesk launched**: The Commission launches the Data Act Legal Helpdesk to support stakeholders with practical implementation questions; the helpdesk page states that replies are aimed within 15 working days.
- **2026-01-22 - Data Act FAQs updated (v1.4)**: The Commission publishes Data Act FAQ version 1.4 dated 22 January 2026.
- **2026-01-30 - Data Act reasonable-compensation guidelines consultation**: The Commission opens targeted feedback on draft guidelines for calculating reasonable compensation under Article 9, with feedback due by 20 February 2026 and a webinar held on 10 February 2026.
- **2026-03-01 - Data catalogue technical specification deadline**: Mandate M/614 sets the deadline for technical specification(s) on a data catalogue implementation framework.
- **2026-03-19 - 2026 Union standardisation work programme published**: The 2026 annual Union work programme for European standardisation is published and lists planned Data Act-related work on Articles 30 and 35 cloud interoperability and switching/porting, plus quality-data work linked to the European Trusted Data Framework.
- **2026-06-01 - Trusted Data Transactions Part 1 deadline**: Mandate M/614 sets the deadline for harmonised standards on Trusted Data Transactions Part 1: terminology, concepts and mechanisms.
- **2026-09-01 - Semantic assets technical specification deadline**: Mandate M/614 sets the deadline for technical specification(s) on an implementation framework for semantic assets.
- **2026-09-01 - Common European Data Spaces maturity model deadline**: Mandate M/614 sets the deadline for technical specification(s) on a maturity model for Common European Data Spaces.
- **2026-09-12 - Connected product access-by-design obligations**: The Article 3(1) obligation applies to connected products and related services placed on the market after 12 September 2026.
- **2026-11-01 - Trusted Data Transactions Part 2 deadline**: Mandate M/614 sets the deadline for harmonised standards on Trusted Data Transactions Part 2: trustworthiness requirements.
- **2027-01-12 - Switching charges prohibited**: From 12 January 2027, providers of data processing services must not impose any switching charges on customers for the switching process.
- **2027-03-01 - Internal data governance quality framework deadline**: Mandate M/614 sets the deadline for the European standard on a quality framework for internal data governance.
- **2027-05-01 - Trusted Data Transactions Part 3 deadline**: Mandate M/614 sets the deadline for harmonised standards on Trusted Data Transactions Part 3: interoperability requirements.
- **2027-09-12 - Chapter IV extends to older contracts**: Chapter IV applies from 12 September 2027 to contracts concluded on or before 12 September 2025 if they are of indefinite duration or due to expire at least 10 years from 11 January 2024.
- **2028-09-12 - Commission evaluation reports due**: By 12 September 2028, the Commission must submit the general Regulation evaluation report and a second report assessing Articles 23-31 and Articles 34-35, including pricing and data-processing-service diversity with a focus on SME providers.

## AU Cyber Security Act Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2021-12-02 | SLACI Act 2021 commences (SOCI reforms  -  tranche 1) | SOCI Act Context | [Source](https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/slacip-bill-2022?ref=sorena.io) |
| 2021-12-15 | SLACIP Bill exposure-draft consultation window | Policy & Consultation | [Source](https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/slacip-bill-2022?ref=sorena.io) |
| 2022-02-04 | SLACIP Bill exposure-draft: final Town Hall held | Policy & Consultation | [Source](https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/slacip-bill-2022?ref=sorena.io) |
| 2022-02-10 | SLACIP Bill introduced and referred to PJCIS | Legislative Process | [Source](https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/slacip-bill-2022?ref=sorena.io) |
| 2022-03-25 | PJCIS advisory report published (SLACIP Bill) | Legislative Process | [Source](https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/slacip-bill-2022?ref=sorena.io) |
| 2022-04-01 | SLACIP Act 2022 made (Federal Register date) | SOCI Act Context | [Source](https://www.legislation.gov.au/Details/C2022A00033?ref=sorena.io) |
| 2022-04-02 | SLACIP Act 2022 comes into effect (SOCI reforms  -  tranche 2) | SOCI Act Context | [Source](https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/slacip-bill-2022?ref=sorena.io) |
| 2022-04-08 | SOCI Application Rules (LIN 22/026) come into effect | SOCI Act Context | [Source](https://www.legislation.gov.au/F2022L00562/2022-04-06/text/original/word?ref=sorena.io) |
| 2022-07-07 | Telecommunications assets: Cyber Reporting compliance date (Telecommunications Act context) | SOCI Act Context | [Source](https://www.homeaffairs.gov.au/reports-and-pubs/files/draft-risk-management-program-guidance.pdf?ref=sorena.io#:~:text=Cyber%20Reporting%20from%207%20July%202022) |
| 2022-09-09 | Protected Information guidance (consultation draft v1) | Guidance (Non-binding) | [Source](https://www.homeaffairs.gov.au/reports-and-pubs/files/protected-information-guidance-material.PDF?ref=sorena.io#:~:text=As%20at%209%20September%202022) |
| 2022-10-05 | RMP Rules consultation window (SOCI reforms) | Policy & Consultation | [Source](https://www.homeaffairs.gov.au/reports-and-pubs/files/draft-risk-management-program-guidance.pdf?ref=sorena.io#:~:text=from%205%20October%202022%20-%2018%20November%202022) |
| 2022-10-07 | Telecommunications assets: Register compliance date (Telecommunications Act context) | SOCI Act Context | [Source](https://www.homeaffairs.gov.au/reports-and-pubs/files/draft-risk-management-program-guidance.pdf?ref=sorena.io#:~:text=Register%20from%207%20October%202022) |
| 2022-11-03 | Draft Risk Management Program Guidance (consultation draft v2) | Guidance (Non-binding) | [Source](https://www.homeaffairs.gov.au/reports-and-pubs/files/draft-risk-management-program-guidance.pdf?ref=sorena.io#:~:text=As%20at%2003%20November%202022) |
| 2023-02-16 | CIRMP Rules (LIN 23/006) as made (F2023L00112) | SOCI Act Context | [Source](https://www.legislation.gov.au/F2023L00112/asmade/text?ref=sorena.io) |
| 2023-02-27 | Australian Cyber Security Strategy consultation window | Policy & Consultation | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2023-11-22 | Smart device standards: Impact Analysis published | Policy & Consultation | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2023-12-19 | Cyber Security legislative reforms consultation window | Policy & Consultation | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2024-10-09 | Cyber Security Bill 2024 second reading speech (House of Representatives) | Legislative Process | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2024-11-25 | Cyber Security Bill 2024 second reading speech (Senate) | Legislative Process | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2024-11-29 | Cyber Security Act 2024 receives Royal Assent | Cyber Security Act 2024 | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2024-11-30 | Cyber Security Act 2024 commences: Parts 1, 4, 6 and 7 | Commencement & Application | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2024-12-16 | Draft Cyber Security Act Rules consultation window | Policy & Consultation | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2025-02-27 | Cyber Security Act Rules are made (dated) | Subordinate Rules (2025) | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2025-03-03 | CIRB Rules registered (F2025L00277) | Subordinate Rules (2025) | [Source](https://www.legislation.gov.au/Details/F2025L00277?ref=sorena.io) |
| 2025-03-03 | Ransomware Payment Reporting Rules registered (F2025L00278) | Subordinate Rules (2025) | [Source](https://www.legislation.gov.au/Details/F2025L00278?ref=sorena.io) |
| 2025-03-04 | Smart Devices Rules registered; Part 1 commences (F2025L00276) | Subordinate Rules (2025) | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2025-03-27 | Smart device standards: Supplementary Explanatory Statement registered | Policy & Consultation | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2025-04-03 | CIRMP Rules: as-made version end date (superseded) | SOCI Act Context | [Source](https://www.legislation.gov.au/F2023L00112/asmade/text?ref=sorena.io) |
| 2025-04-04 | SOCI Application Rules: April 2025 compilation/version date | SOCI Act Context | [Source](https://www.legislation.gov.au/F2022L00562/2022-04-06/text/original/word?ref=sorena.io) |
| 2025-05-29 | Cyber Security Act 2024 Part 3 commences: ransomware payment reporting backstop date | Commencement & Application | [Part 3; s.27](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2025-05-29 | Ransomware Payment Reporting Rules commence (F2025L00278) (aligned to Part 3) | Commencement & Application | [Source](https://www.legislation.gov.au/Details/F2025L00278?ref=sorena.io) |
| 2025-05-29 | Cyber Security Act 2024 Part 5 commences: Cyber Incident Review Board backstop date | Commencement & Application | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2025-05-29 | CIRB Rules commence (F2025L00277) (aligned to Part 5) | Commencement & Application | [Source](https://www.legislation.gov.au/Details/F2025L00277?ref=sorena.io) |
| 2025-11-29 | Cyber Security Act 2024 Part 2 commences: smart device security standards framework backstop date | Commencement & Application | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2026-01-28 | Cyber Security Act 2024 compiled version: replaced authorised version registered | Cyber Security Act 2024 | [Source](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |
| 2026-03-04 | Smart Devices Rules substantive obligations commence (Part 2 and Schedule 1) | Commencement & Application | [Source](https://www.legislation.gov.au/Details/F2025L00276?ref=sorena.io) |
| 2027-12-01 | Cyber Security Act 2024 statutory review can begin (PJCIS) | Statutory Review | [s.88](https://www.legislation.gov.au/Details/C2024A00098?ref=sorena.io) |

**Event details:**

- **2021-12-02 - SLACI Act 2021 commences (SOCI reforms  -  tranche 1)**: Home Affairs describes the Security Legislation Amendment (Critical Infrastructure) Act 2021 (SLACI Act) as the first tranche of reforms to the SOCI Act, commencing from 2 December 2021.
- **2021-12-15 - SLACIP Bill exposure-draft consultation window**: Home Affairs records an exposure-draft consultation period for the SLACIP Bill and accompanying draft Explanatory Document running from 15 December 2021 until Tuesday 1 February 2022.
- **2022-02-04 - SLACIP Bill exposure-draft: final Town Hall held**: Home Affairs notes a final Town Hall was held on 4 February 2022 following the closure of submissions on the SLACIP Bill exposure draft.
- **2022-02-10 - SLACIP Bill introduced and referred to PJCIS**: Home Affairs records that the Minister for Home Affairs introduced the SLACIP Bill to Parliament and referred it to the Parliamentary Joint Committee on Intelligence and Security (PJCIS) on 10 February 2022.
- **2022-03-25 - PJCIS advisory report published (SLACIP Bill)**: Home Affairs notes that the PJCIS published its advisory report on the SLACIP Bill on 25 March 2022.
- **2022-04-01 - SLACIP Act 2022 made (Federal Register date)**: The Federal Register of Legislation entry for the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (C2022A00033) shows a date of 1 April 2022 (as-made Act entry).
- **2022-04-02 - SLACIP Act 2022 comes into effect (SOCI reforms  -  tranche 2)**: Home Affairs records that the Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (SLACIP Act) came into effect on 2 April 2022.
- **2022-04-08 - SOCI Application Rules (LIN 22/026) come into effect**: Draft Risk Management Program Guidance states that the Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022 came into effect on 8 April 2022, outlining asset classes required to comply with Mandatory Cyber Incident Reporting and certain Register reporting requirements.
- **2022-07-07 - Telecommunications assets: Cyber Reporting compliance date (Telecommunications Act context)**: Draft Risk Management Program Guidance notes that telecommunications assets comply with Cyber Reporting from 7 July 2022 under the Telecommunications Act 1997.
- **2022-09-09 - Protected Information guidance (consultation draft v1)**: Protected Information Guidance Material for industry is marked as a consultation draft (v1) and states it is current "as at 9 September 2022".
- **2022-10-05 - RMP Rules consultation window (SOCI reforms)**: Draft Risk Management Program Guidance states the consultation period for the draft risk management program (RMP) rules was 45 days, from 5 October 2022 to 18 November 2022.
- **2022-10-07 - Telecommunications assets: Register compliance date (Telecommunications Act context)**: Draft Risk Management Program Guidance notes that telecommunications assets comply with the Register from 7 October 2022 under the Telecommunications Act 1997.
- **2022-11-03 - Draft Risk Management Program Guidance (consultation draft v2)**: Draft Risk Management Program Guidance is marked as a consultation draft (v2) and states it is current "as at 03 November 2022".
- **2023-02-16 - CIRMP Rules (LIN 23/006) as made (F2023L00112)**: Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 appear on the Federal Register of Legislation as an as-made version dated 16 February 2023 (F2023L00112).
- **2023-02-27 - Australian Cyber Security Strategy consultation window**: Smart Devices Rules Explanatory Statement references the Australian Government consultation on the 2023-2030 Australian Cyber Security Strategy running from 27 February 2023 to 15 April 2023.
- **2023-11-22 - Smart device standards: Impact Analysis published**: Impact Analysis Addendum for smart device standards states that the Department of Home Affairs published an Impact Analysis on mandatory security standards and an industry-led voluntary cyber security labelling scheme on 22 November 2023.
- **2023-12-19 - Cyber Security legislative reforms consultation window**: Smart Devices Rules Explanatory Statement records that, on 19 December 2023, the Minister released the "Australian Cyber Security Strategy: Cyber Security Legislative Reforms Consultation Paper" and that consultation remained open until 1 March 2024.
- **2024-10-09 - Cyber Security Bill 2024 second reading speech (House of Representatives)**: The Act records that the Minister's second reading speech was made in the House of Representatives on 9 October 2024.
- **2024-11-25 - Cyber Security Bill 2024 second reading speech (Senate)**: The Act records that the Minister's second reading speech was made in the Senate on 25 November 2024.
- **2024-11-29 - Cyber Security Act 2024 receives Royal Assent**: Cyber Security Act 2024 (No. 98, 2024) receives Royal Assent on 29 November 2024.
- **2024-11-30 - Cyber Security Act 2024 commences: Parts 1, 4, 6 and 7**: Commencement table: Part 1 (and provisions not otherwise covered), Part 4 (coordination of significant cyber security incidents), and Parts 6-7 (regulatory powers and miscellaneous) commence the day after Royal Assent (30 November 2024).
- **2024-12-16 - Draft Cyber Security Act Rules consultation window**: Explanatory Statements record that the draft Rules package was published on the Department's website on 16 December 2024 and closed for submissions on 14 February 2025.
- **2025-02-27 - Cyber Security Act Rules are made (dated)**: The three Cyber Security Act Rules instruments are dated 27 February 2025 (Smart Devices Rules; Cyber Incident Review Board Rules; Ransomware Payment Reporting Rules). Registration dates follow in early March 2025.
- **2025-03-03 - CIRB Rules registered (F2025L00277)**: Cyber Security (Cyber Incident Review Board) Rules 2025 are registered on 3 March 2025. The instrument commences later of the day after registration and the commencement of Act Part 5.
- **2025-03-03 - Ransomware Payment Reporting Rules registered (F2025L00278)**: Cyber Security (Ransomware Payment Reporting) Rules 2025 are registered on 3 March 2025. The instrument commences later of the day after registration and the commencement of Act Part 3.
- **2025-03-04 - Smart Devices Rules registered; Part 1 commences (F2025L00276)**: Cyber Security (Security Standards for Smart Devices) Rules 2025 are registered on 4 March 2025. The instrument's commencement table provides that Part 1 commences on registration, while Part 2 and Schedule 1 have a delayed commencement (4 March 2026).
- **2025-03-27 - Smart device standards: Supplementary Explanatory Statement registered**: The smart device standards Impact Analysis (Supplementary Explanatory Statement) is an authorised version registered on 27 March 2025 in connection with F2025L00276.
- **2025-04-03 - CIRMP Rules: as-made version end date (superseded)**: The Federal Register of Legislation page for F2023L00112 shows the as-made version dated 16 February 2023 and indicates it is superseded, with the as-made version running until 3 April 2025.
- **2025-04-04 - SOCI Application Rules: April 2025 compilation/version date**: The Federal Register metadata for the SOCI Application Rules references an April 2025 compilation (F2025C00404) and links to a 4 April 2025 version in the legislation history/amendment history.
- **2025-05-29 - Cyber Security Act 2024 Part 3 commences: ransomware payment reporting backstop date**: Commencement table provides for commencement by proclamation, with an automatic commencement if not commenced within 6 months of Royal Assent. The published commencement table includes 29 May 2025 as the backstop date for Part 3. Part 3 imposes the 72-hour ransomware payment reporting obligation for reporting business entities; the 2025 Rules specify (among other details) the $3 million turnover threshold and report content requirements.
- **2025-05-29 - Ransomware Payment Reporting Rules commence (F2025L00278) (aligned to Part 3)**: Commencement clause: the whole instrument commences later of the day after registration and the commencement of Act Part 3; the backstop commencement date for Part 3 is 29 May 2025.
- **2025-05-29 - Cyber Security Act 2024 Part 5 commences: Cyber Incident Review Board backstop date**: Commencement table provides for commencement by proclamation, with an automatic commencement if not commenced within 6 months of Royal Assent. The published commencement table includes 29 May 2025 as the backstop date for Part 5.
- **2025-05-29 - CIRB Rules commence (F2025L00277) (aligned to Part 5)**: Commencement clause: the whole instrument commences later of the day after registration and the commencement of Act Part 5; the backstop commencement date for Part 5 is 29 May 2025.
- **2025-11-29 - Cyber Security Act 2024 Part 2 commences: smart device security standards framework backstop date**: Commencement table provides for commencement by proclamation, with an automatic commencement if not commenced within 12 months of Royal Assent. The published commencement table includes 29 November 2025 as the backstop date for Part 2 (security standards for smart devices).
- **2026-01-28 - Cyber Security Act 2024 compiled version: replaced authorised version registered**: The Act text indicates a replaced authorised version was registered on 28 January 2026 (compiled version reference).
- **2026-03-04 - Smart Devices Rules substantive obligations commence (Part 2 and Schedule 1)**: Commencement table: Part 2 and Schedule 1 of the Smart Devices Rules commence on 4 March 2026 (12-month delayed commencement). This is when the mandatory security standards, statement-of-compliance requirements (including 5-year retention period), and defined support-period rules take effect for covered products.
- **2027-12-01 - Cyber Security Act 2024 statutory review can begin (PJCIS)**: The Parliamentary Joint Committee on Intelligence and Security may review the operation, effectiveness and implications of the Act, so long as it begins the review as soon as practicable after 1 December 2027.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/regulatory-universal-timelines
