Compliance calendar
Every regulatory deadline and milestone we track, in one place. Each date links to the analysis behind it.
10 upcoming · 18 past
Coming up
- In 44 days
DPDP Act: Consent managers
Rule 4: registration and obligations of consent managers.
- In 2 months
EU AI Act: Marking deadline for existing generative AI
Systems on the market before 2 Aug 2026.
- In 6 months
ISO 9001: Accreditation bodies ready
Latest date for accreditation bodies to assess against the 2026 edition.
- In 8 months
DPDP Act: Core obligations apply
Notice, consent, security, breach reporting and Rule 16 (research standards).
- In 8 months
DPDP Act: Core obligations apply
Rules 3, 5 to 16, 22 and 23.
- In 14 months
EU AI Act: Annex III high-risk obligations
- In 15 months
EU Cyber Resilience Act: Full application
Essential cybersecurity requirements and conformity assessment apply.
- In 18 months
ISO 9001: Initial certifications to 2026 only
- In 22 months
EU AI Act: Annex I product-embedded AI
- In 37 months
ISO 9001: Transition ends
Remaining 2015 certificates are no longer valid.
2026
- 14 days ago
ISO 9001:2026 published
- 19 days ago
EU Cyber Resilience Act: Article 14 reporting applies
EU Cyber Resilience Act: Article 14 reporting obligations apply; ENISA's Single Reporting Platform goes live
- 59 days ago
EU AI Act: Article 50 transparency applies
EU AI Act: Article 50 transparency obligations apply
- 2 months ago
EU AI Act: Digital Omnibus, Regulation (EU) 2026/1744, enters into force and postpones high-risk deadlines
2025
- 11 months ago
DPDP Rules notified
Data Protection Board provisions in force.
- 11 months ago
DPDP Act: Rules notified; Board provisions apply
DPDP Rules, 2025 notified; Data Protection Board provisions in force
- 11 months ago
ISO 27001: 2013 certificates expire
Any certificate not transitioned is withdrawn or cancelled.
- 14 months ago
EU AI Act: General-purpose AI model obligations
- 17 months ago
ISO/IEC 42005:2025 published: guidance for AI system impact assessments
- 20 months ago
EU AI Act: Prohibited practices apply
- 21 months ago
DORA: Applies to financial entities
DORA applies to in-scope financial entities
2024
- 22 months ago
The Cyber Resilience Act enters into force
EU Cyber Resilience Act: CRA enters into force
- 2 years ago
ISO 27001: Last initial audits against 2013
Certification bodies stop initial and recertification audits to the 2013 edition (IAF MD 26).
2023
- 3 years ago
ISO/IEC 42001:2023 published as the first certifiable AI management system standard
- 4 years ago
DORA entered into force
DORA: Entered into force
2022
- 4 years ago
DORA: Published in the Official Journal
- 4 years ago
ISO/IEC 27001:2022 published
Dates come from the regulations, standards and regulator publications cited in each linked article. Check the source before relying on a date.