Back to Publications
Regulatory Brief · CRA

Five EU Regulations, One Timeline — What Binds and When

31 July 2026By NexCyber Editorial CRA

CRA, NIS2, DORA, the AI Act and RED land on different dates. Two have already passed. The single timeline every EU product team should be working from.

The short answer

Most compliance plans treat "EU regulation" as one deadline. It is five instruments landing on different dates, and two of them have already passed.

2 February 2025    AI Act — prohibited practices (Article 5) and AI literacy      PASSED
1 August   2025    RED Article 3(3) — connected radio equipment                   PASSED
17 October 2024    NIS2 — national transposition deadline                         PASSED
17 January 2025    DORA — applies in full                                         PASSED
2 August   2026    AI Act — general application, Annex III high-risk systems
11 September 2026  CRA — reporting obligations (Article 14)
11 December 2027   CRA — main obligations
2 August   2027    AI Act — high-risk under Annex I sectoral legislation

Four are already in force. The two nearest futures are six weeks and thirteen months away.

The practical consequence is not urgency in general — it is that the first thing to bind is almost never the thing teams prepare first.

---

What has already passed, and is being missed anyway

AI Act Article 5 — since February 2025

The eight prohibited practices carry the highest penalty ceiling in EU digital regulation: EUR 35 000 000 or 7 % of total worldwide annual turnover, whichever is higher.

Two of the eight arrive inside bought software — emotion inference in the workplace, and biometric categorisation inferring sensitive attributes. An interview-analysis tool that scores candidate enthusiasm. A contact-centre feature reporting agent sentiment. Neither arrives labelled as an AI project.

A prohibited practice cannot be remediated by documentation. It is the only tier where the answer is stopping.

RED Article 3(3) — since August 2025

Delegated Regulation (EU) 2022/30 activated cybersecurity requirements for internet-connected radio equipment. The date was deferred once, from August 2024. That deferral is over.

It is missed for a structural reason: it is not a new law. It is an addition to a directive manufacturers have complied with for years, so there was no new instrument to notice — only a change in what the existing CE marking now attests.

NIS2 — transposition due October 2024

NIS2 is a Directive. It does not bind you directly; the national transposition of each Member State where you operate does, and those texts differ. Several transpositions arrived late, which created a false impression that the regime was not yet live.

It arrives commercially before it arrives legally — through Article 21(2)(d), which makes in-scope entities answerable for their suppliers' security. Most companies meet NIS2 as a procurement questionnaire.

DORA — since January 2025

Applies in full to EU financial entities, and reaches their technology providers through mandatory contractual requirements. If you sell to EU financial institutions, DORA is already in your contracts whether or not you are a financial entity.

---

What binds next

2 August 2026 — AI Act general application

Annex III high-risk systems, and the Article 50 transparency duties. Thirteen months of preparation compressed into whatever remains.

The obligations most often discovered late are the deployer ones — human oversight assigned to someone with authority, logs kept, workers informed, and for defined cases a fundamental rights impact assessment before first use. That assessment cannot be written afterwards with any credibility.

11 September 2026 — CRA Article 14

Six weeks away. Reporting obligations for actively exploited vulnerabilities and severe incidents, on a 24-hour / 72-hour / final-report sequence.

It precedes the rest of the CRA by fifteen months, and almost every plan treats the two dates as one. A manufacturer not yet subject to the full essential requirements can already owe the reporting duty.

11 December 2027 — CRA in full

Essential requirements, conformity assessment, CE marking covering cybersecurity, and the support period — at least five years of free security updates unless the expected lifetime is shorter.

The constraint here is not the deadline, it is the queue. Products in Annex III class II or Annex IV need a third-party assessment, and notified body availability close to December 2027 is the scarcest resource in the whole programme.

---

The one thing this timeline should change

Sequence by what binds first, not by what feels largest.

The CRA is the biggest programme, so teams start there and work toward December 2027 — and miss the September 2026 reporting duty sitting fifteen months earlier. The AI Act feels distant, so nobody screens for Article 5, which has been enforceable for eighteen months.

what teams prepare first   the largest programme
what binds first           the smallest, cheapest obligation

The obligations that bind soonest are also the cheapest to meet. A named notifying owner. A published vulnerability contact. A written threshold for "actively exploited". A dated screening against Article 5. None of these require a notified body, a certification, or a budget line — and each closes a live exposure.

---

Where the five overlap

Building the evidence once is what separates a compliance cost from a reusable asset:

  • An SBOM answers CRA Annex I Part II, and the supply-chain question NIS2 customers ask.
  • A coordinated vulnerability disclosure policy is required by the CRA, expected under NIS2 Article 21(2)(e), and requested in almost every procurement questionnaire.
  • An incident runbook with named owners serves CRA Article 14, NIS2 Article 23 and DORA reporting — different reporters, different subjects, one process.

What does not transfer is the obligation itself. Producing an SBOM does not make you CRA-compliant; it satisfies a requirement each instrument states in its own terms, and each judges against its own criteria.

---

Check your position across all five — free

  • [Free applicability assessment](/assess) — which of the five reach you, and which obligations follow
  • [Compliance responsibility mapper](/resources/responsibility-mapper) — a RACI by role
  • [Penalty calculator](/resources/penalty-calculator) — exposure on your own turnover

No account, no sales call to unlock the result.

---

Further reading

One evidence set across five EU regulationsWhat is the Cyber Resilience ActWhat is NIS2What is the EU AI ActWhat is DORARED Article 3(3) for connected devices

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Dates reflect the instruments as published; NIS2 binds through national transposition, and delegated acts, harmonised standards and guidance continue to be adopted. Verify against the current texts and the Official Journal, and consult your competent authority or a qualified adviser.*