Compliance deadlines

What is coming, and when

The dates that actually bite a small organisation, with what each one means and who it applies to. Every date links to the authority that set it, so you can check us rather than trust us.

Next deadline

EU Cyber Resilience Act

Reporting obligations begin: an actively exploited vulnerability in your product must be reported to ENISA within 24 hours of becoming aware of it.

Regulation (EU) 2024/2847, Article 14
40days11 September 2026

Ahead of you 2

11 September 2026in 40 days
EU Cyber Resilience Act

Reporting obligations begin: an actively exploited vulnerability in your product must be reported to ENISA within 24 hours of becoming aware of it.

Applies toAnyone placing a product with digital elements on the EU market, including software sold or distributed there. It reaches far beyond EU-based companies.
If you are wrongUp to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.

Twenty-four hours is not a process you can invent on the day. You need to know who decides it is reportable, who files it, and where the evidence lives, before the clock starts.

Source: Regulation (EU) 2024/2847, Article 14
11 December 2027in 496 days
EU Cyber Resilience Act

Full application: the essential cybersecurity requirements and conformity assessment apply to products placed on the market.

Applies toThe same manufacturers, for every product placed on the EU market from that date.
If you are wrongUp to EUR 15 million or 2.5% of worldwide annual turnover.

This is a product-engineering obligation, not a paperwork one. Secure development, a vulnerability handling process, and a software bill of materials take longer to build than the time you will feel you have.

Source: Regulation (EU) 2024/2847, Article 71

Already in force 3

These have arrived. If your last assessment predates them, the gap is not theoretical.

In forcecontinuous
UAE Personal Data Protection Law

In force. Federal Decree-Law No. 45 of 2021 governs the processing of personal data in the UAE.

Applies toOrganisations processing personal data of individuals in the UAE, wherever the organisation itself is based.

The obligations that bite an SMB first are the unglamorous ones: knowing what personal data you hold, being able to answer a data subject within the period the law allows, and having somewhere for a breach notification to start from.

Source: Federal Decree-Law No. 45 of 2021 (UAE Data Office)
31 October 2025275 days ago
ISO/IEC 27001

The transition period from ISO/IEC 27001:2013 to the 2022 revision ended. Certificates against the 2013 version are no longer valid.

Applies toAny organisation holding, or seeking, ISO 27001 certification.

If you are starting ISO 27001 now, you are starting on the 2022 Annex A: 93 controls in four themes, not the old 114 in fourteen. Any guidance you find that says otherwise is out of date.

Source: IAF MD 26, transition requirements
31 March 2025489 days ago
PCI DSS v4.0

The future-dated requirements became mandatory. Every v4.0 requirement previously described as best practice is now assessed.

Applies toAny organisation that stores, processes or transmits cardholder data.

If your last assessment predates this, the gap is not theoretical. The future-dated items are the demanding ones: targeted risk analyses, authenticated scanning, and stricter authentication.

Source: PCI Security Standards Council, PCI DSS v4.0.1
Not sure which of these reach you?

That is the first thing we work out. An assessment tells you where you stand against the ones that actually apply, and what to do first.

Create your company profile →