Compliance calendar

Every regulatory deadline and milestone we track, in one place. Each date links to the analysis behind it.

Next: DPDP Act: Consent managers on 13 Nov 2026

10 upcoming · 18 past

Coming up

  1. In 44 days

    DPDP Act: Consent managers

    Rule 4: registration and obligations of consent managers.

  2. In 2 months

    EU AI Act: Marking deadline for existing generative AI

    Systems on the market before 2 Aug 2026.

  3. In 6 months

    ISO 9001: Accreditation bodies ready

    Latest date for accreditation bodies to assess against the 2026 edition.

  4. In 8 months

    DPDP Act: Core obligations apply

    Notice, consent, security, breach reporting and Rule 16 (research standards).

  5. In 8 months

    DPDP Act: Core obligations apply

    Rules 3, 5 to 16, 22 and 23.

  6. In 15 months

    EU Cyber Resilience Act: Full application

    Essential cybersecurity requirements and conformity assessment apply.

  7. In 18 months

    ISO 9001: Initial certifications to 2026 only

  8. In 37 months

    ISO 9001: Transition ends

    Remaining 2015 certificates are no longer valid.

2026

  1. 19 days ago

    EU Cyber Resilience Act: Article 14 reporting applies

    EU Cyber Resilience Act: Article 14 reporting obligations apply; ENISA's Single Reporting Platform goes live

  2. 59 days ago

    EU AI Act: Article 50 transparency applies

    EU AI Act: Article 50 transparency obligations apply

  3. 2 months ago

    EU AI Act: Digital Omnibus, Regulation (EU) 2026/1744, enters into force and postpones high-risk deadlines

2025

  1. 11 months ago

    DPDP Rules notified

    Data Protection Board provisions in force.

  2. 11 months ago

    DPDP Act: Rules notified; Board provisions apply

    DPDP Rules, 2025 notified; Data Protection Board provisions in force

  3. 11 months ago

    ISO 27001: 2013 certificates expire

    Any certificate not transitioned is withdrawn or cancelled.

  4. 14 months ago

    EU AI Act: General-purpose AI model obligations

  5. 17 months ago

    ISO/IEC 42005:2025 published: guidance for AI system impact assessments

  6. 21 months ago

    DORA: Applies to financial entities

    DORA applies to in-scope financial entities

2024

  1. 22 months ago

    The Cyber Resilience Act enters into force

    EU Cyber Resilience Act: CRA enters into force

  2. 24 months ago

    NIS2: Transposition deadline for member states

  3. 2 years ago

    ISO 27001: Last initial audits against 2013

    Certification bodies stop initial and recertification audits to the 2013 edition (IAF MD 26).

2023

  1. 3 years ago

    ISO/IEC 42001:2023 published as the first certifiable AI management system standard

2022

  1. 4 years ago

    DORA: Published in the Official Journal

Dates come from the regulations, standards and regulator publications cited in each linked article. Check the source before relying on a date.