EU Cybersecurity Regulations Timeline

Fourteen different legal acts affecting cybersecurity for product manufacturers are in different stages of introduction across the European Union. Here, Amanita Security maintains a list of the different legal acts, their status within the legislative process, and the currently expected dates from which they will be applicable to organisations. Don’t forget to bookmark this page to track future updates !

Before diving into the list, however, it is important to understand the difference in terminology between two distinct dates, the date on which the regulation entered into force, and the date on which it becomes applicable.

The entry into force date is the moment at which a legal act becomes legally valid and binding. This can be a date specified in the legal act, or in absence thereof, on the twentieth day following its publication in the official journal.
The date of application is the moment at which the legal act becomes applicable and must be followed.

Legislative ActCurrent StatusEntry into forceDate of application
General Data Protection (GDPR)Fully Applicable04-05-201625-05-2018
Medical DevicesPartially Applicable25-05-20172017-2027
In-Vitro Medical DevicesPartially Applicable25-05-20172017-2027
Approval and market surveillance for motor vehiclesPartially Applicable04-07-20182018-2026
Common rules in the field of Civil AviationFully Applicable11-09-20182019-2023
Type approval requirements for motor vehiclesPartially Applicable05-01-20202022-2027
Updated Radio Equipment DirectiveEntered into Force01-02-202201-08-2025
NIS 2 DirectiveEntered into Force16-01-20232027-2028
Digital Operational Resilience Act (DORA)Entered into Force16-01-20232023-2029
General Product SafetyEntered into Force12-06-20232023-2029
Machinery RegulationEntered into Force19-07-20232023-2032
Data ActEntered into Force11-01-20242024-2028
Common Criteria Cybersecurity CertificationEntered into Force27-02-202427-02-2025
Cyber Resilience ActIn preparationundefinedundefined

Article last updated: 13th of September 2024
Amanita Security specializes in guiding manufacturers through these complex cybersecurity requirements. Get in touch to discuss how we can help you be compliant in time.

Get in touch