Kilde › The compliance deadline radar: 2026–20…

The compliance deadline radar: 2026–2028, verified at the source

Current to 12 September 2026 · updates land in the changelog.

One page, every regulatory fuse we track — EU and Hong Kong, 2026 through 2028 — each row verified against the instrument's own text before it earns a place here. Dates are the product: this page exists so you learn about a deadline while there is still time to act on it. Changes land in the updates feed (RSS).

Upcoming

2026-09-27EmpCo: twelve banned green-claims practices apply confirmed
Directive (EU) 2024/825 inserts twelve per-se banned practices into the UCPD blacklist: generic environmental claims, offset-based neutrality claims, self-awarded badges, and seven durability/software practices. The date is fixed and does not slide with late national transposition. All EmpCo guides.
~2026-10-30CRA: first harmonised standards expected in the OJ estimate
The first CRA harmonised standards are currently expected to be cited around this date — the event that opens the Class I self-assessment route. The timeline has already slipped once; until citation, Class I products effectively need a third party. Conformity routes by class.
2026-12-02AI Act: marking deadline for pre-August systems confirmed
Generative AI systems placed on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking duty from this date (Omnibus Regulation (EU) 2026/1744). Systems placed on or after 2 August 2026 had no runway; the other Article 50 duties have applied since August. Exactly what the transition covers.
2026-12-09New Product Liability Directive: the switch date confirmed
Directive (EU) 2024/2853 applies to products placed on the market or put into service after 9 December 2026 — with 'product' expressly including software and digital manufacturing files — while Member States must transpose by the same date and the 1985 directive is repealed with effect from it. Verified verbatim at EUR-Lex (CELEX 32024L2853). Free and open-source software outside a commercial activity is carved out. Guides cluster in preparation. Tracked in updates.
2026-12-11CRA: conformity-assessment-body chapter applies confirmed
The machinery for notifying conformity-assessment bodies starts one year ahead of full application — the milestone that lets notified bodies stand up before the 2027 rush. The full CRA timeline.
2026-12-31SWIFT CSP: 2026 attestation window closes confirmed
The annual KYC-SA attestation against CSCF v2026 (26 mandatory + 6 advisory controls, control 2.4 newly mandatory) must be submitted and approved by year end. Counterparties see status colour-coded; supervisors hold real-time access. Window, roles, consequences.
~2026-Q4CRA: certification delegated act for critical products expected estimate
The delegated act that can mandate European cybersecurity certification for Annex IV critical products (security boxes, smart meter gateways, smartcards/secure elements) sits on the Commission's slate for late 2026. What certification-where-mandated means.
2027-12-02AI Act: Annex III high-risk obligations apply confirmed
The Omnibus moved the Annex III high-risk compliance date to 2 December 2027 (and Annex I products to 2 August 2028). Article 50 transparency was untouched by these delays — it has applied since August 2026. High-risk guides planned. The duties already live.
2027-12-11CRA: full application confirmed
The complete obligation set for products placed on the market: Annex I essential requirements, conformity assessment and CE marking, technical documentation, support-period duties — and the penalties chapter squarely in force. The 2027 requirements, mapped.
2028-08-02AI Act: Annex I high-risk products confirmed
The second high-risk wave under the Omnibus schedule: products under Annex I sectoral legislation reach their AI Act compliance date. Role analysis that carries over.
~2028SWIFT CSCF: legacy back-office flows tentatively mandatory announced — not in force
Control 2.4's remaining advisory slice — legacy direct back-office flows — is tentatively slated to become mandatory around the v2028 framework. Announced direction, not in force; the flow inventory built for 2026 is the asset that makes 2028 a non-event. Control 2.4, the wedge.

Recently switched on

How rows earn their place

A date appears here only once we have verified it at the source — the Official Journal text, the operator's own published mechanics, or our audited research files. Estimates are labeled as estimates and carry their slip history; announced-but-not-in-force items say so. When a row's status changes, the change is dated in the updates feed rather than silently edited.

Quick answers

What is the next major EU compliance deadline?
11 September 2026 — the Cyber Resilience Act's Article 14 reporting duty (24-hour early warning, 72-hour notification), covering the whole in-scope installed base. It is followed by EmpCo's green-claims blacklist on 27 September 2026.
When does the new EU Product Liability Directive apply?
Directive (EU) 2024/2853 applies to products placed on the market or put into service after 9 December 2026 — with software expressly included as a product — and Member States must transpose by the same date.
How are these dates verified?
Against the instrument's own text (EUR-Lex verbatim reads) or the operator's published mechanics, recorded in audited research files with a verification date. Estimates and announced items are labeled as such.

General information only — not legal advice. Every row and entry traces to an in-house verified source: our audited product research files (checked against primary sources on the stated dates) or same-day verbatim reads of the Official Journal text at EUR-Lex. Status labels are load-bearing: confirmed = in the instrument's text; estimate = published timeline that can slip; announced = stated intent, not in force. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com