2026 is one of the densest years on record for EU compliance, with obligations landing across cybersecurity, data, AI, sustainability and financial services, several of them reshaped mid-year by the Commission's simplification drive. This is a reference desk of the EU compliance deadlines 2026 that actually matter, organised by regulation, with every date checked against the current legal position rather than the original texts.
A note on timing: this article is written in mid-August 2026, so a few dates below have already passed this year and are flagged as such. They are kept in because a full-year view of EU regulation deadlines is more useful than a list that quietly drops anything before today.
Quick reference: the 2026 deadline table
| Date | Regulation | What's due | Who it affects |
|---|---|---|---|
| 16 Feb – 13 Mar 2026 | DORA | Register of Information submission window (limited scope in 2026) | Financial entities in scope |
| 1 Jul 2026 (passed) | MiCA | Transitional / grandfathering period ends | Crypto-asset service providers |
| 27 Jul 2026 (passed) | EU AI Act | Digital Omnibus enters into force; high-risk deadlines deferred | AI providers and deployers |
| 2 Aug 2026 (passed) | EU AI Act | Article 50 transparency obligations apply | Providers/deployers of generative and interactive AI |
| 11 Sep 2026 | Cyber Resilience Act | Vulnerability and incident reporting begins | Manufacturers of products with digital elements |
| 12 Sep 2026 | Data Act | Data-access-by-design for newly placed connected products | Makers of connected products and related services |
| 30 Dec 2026 | EUDR | Application date for large and medium operators | Operators/traders in listed commodities |
| Throughout 2026 | NIS2 | National transposition laws entering into force | Essential and important entities |
| Reporting in 2026 | CSRD | Wave 1 reports on financial year 2025 | Large public-interest entities already in scope |
| 2 Dec 2027 | EU AI Act | High-risk (Annex III) obligations, deferred | High-risk AI providers and deployers |
EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) phases in over several years, and 2026 was meant to be its biggest step. It was, but not in the way originally planned. The Digital Omnibus (politically agreed on 7 May 2026 and in force since 27 July 2026) deferred the headline high-risk obligations.
Two dates still landed on schedule. Since 2 August 2026, the Article 50 transparency duties apply: users must be told when they are interacting with an AI system, AI-generated synthetic audio, image, video and text must be labelled, and deepfakes must be disclosed. And the earlier milestones remain live: prohibited practices and AI-literacy duties (from 2 February 2025) and general-purpose AI (GPAI) provider obligations (from 2 August 2025).
The deferral matters most for high-risk systems. Obligations for stand-alone Annex III high-risk systems are now pushed to 2 December 2027 (from the original 2 August 2026), and AI embedded in regulated products under Annex I moves to 2 August 2028. Separately, GPAI models placed on the market before 2 August 2025 must reach full compliance by 2 August 2027, when their grandfathering window closes. If you track the AI Act, re-baseline your internal deadlines against the Omnibus. Several dates you may have locked in during 2025 have moved.
NIS2
The NIS2 Directive (Directive (EU) 2022/2555) raised cybersecurity risk-management and incident-reporting obligations for essential and important entities across a wide sweep of sectors. Because it is a directive, it binds through national transposing laws rather than applying directly.
The transposition deadline was 17 October 2024, and many member states missed it. By mid-2026 the picture is one of catch-up: roughly 22 of 27 member states had adopted transposing legislation, with a handful (reported in May 2026 as including France, Ireland, Luxembourg, the Netherlands and Spain) still finalising. The practical 2026 deadline is therefore jurisdiction-specific: your obligations crystallise as each relevant member state's law enters into force, and the Commission's infringement proceedings have been pushing the laggards to complete during 2025 and 2026. If you operate cross-border, track transposition country by country rather than assuming a single EU-wide switch-on date.
CSRD
The Corporate Sustainability Reporting Directive was significantly reshaped by the "stop-the-clock" measure and the wider Omnibus simplification package. The final Omnibus directive (Directive (EU) 2026/470) was published in February 2026, with member states required to transpose by March 2027.
For 2026, the split matters. Wave 1 companies (large public-interest entities already in scope) continue reporting, filing on financial year 2025 during 2026. Wave 2 companies, large non-listed undertakings that expected to report in 2026 on FY2025 data, received a two-year delay and are now due to report in 2028 on FY2027. For most Wave 2 organisations, 2026 is a preparation year, not a reporting year. Confirm which wave you fall into before assuming a filing obligation this year.
DORA
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025, so for financial entities 2026 is about sustaining and evidencing compliance rather than standing it up. The obligations are continuous: ICT risk management, incident reporting, digital operational resilience testing (including threat-led penetration testing for larger entities) and ICT third-party risk management.
The concrete 2026 date is the annual Register of Information exercise. National competent authorities collected registers of ICT third-party arrangements over a window running roughly 16 February to 13 March 2026, consolidating and submitting to the European Supervisory Authorities by 31 March. The 2026 run was narrower in scope than the first: only a limited set of entities were required to submit, and those with no changes could simply confirm last year's position. The Register remains the primary lens regulators use to map digital dependencies and designate Critical Third-Party Providers, so keep it current year-round, not just at submission time.
Cyber Resilience Act
The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024 and phases in toward full application on 11 December 2027 (conformity assessment and CE marking). Two milestones fall in 2026.
The provisions on notifying conformity assessment bodies began applying on 11 June 2026. The bigger one is 11 September 2026, when the Article 14 reporting obligations begin: manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, on a 24-hour early-warning, 72-hour notification and 14-day final-report cadence. Crucially, these reporting duties are not limited to new launches: they extend to legacy products already on the EU market. Manufacturers should have detection, classification and reporting procedures operational before the September date.
MiCA
The Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) brought crypto-asset service providers (CASPs) and stablecoin issuers into a harmonised EU regime. Stablecoin (asset-referenced and e-money token) rules applied from 30 June 2024 and CASP rules from 30 December 2024.
The pivotal 2026 date has just passed: the transitional "grandfathering" period ended on 1 July 2026. Firms that were lawfully providing crypto-asset services under national regimes before 30 December 2024 could continue during this window while their MiCA authorisation was pending, but that runway is now closed, and some member states (Germany and France among them) applied shorter windows. From 1 July 2026, providing crypto-asset services to EU clients requires MiCA authorisation; reliance on prior national regimes is no longer available.
Others worth tracking
EU Data Act (Regulation (EU) 2023/2854). Applicable since 12 September 2025, the Data Act adds a design obligation on 12 September 2026: connected products and related services placed on the market after that date must, by default, make relevant data easily, securely and directly accessible to users, free of charge where relevant and technically feasible. Member states are still standing up national enforcement frameworks and designating competent authorities.
EU Deforestation Regulation (EUDR, Regulation (EU) 2023/1115). After a further postponement, the application date for large and medium operators and traders is now 30 December 2026, with micro and small operators given until 30 June 2027. In-scope businesses dealing in listed commodities (cattle, cocoa, coffee, oil palm, rubber, soya and wood, and their derived products) need due-diligence and geolocation data in place for the December date.