Compliance Calendar

Regulatory Compliance Deadlines — 2026–2028 Calendar for Regulated Teams

Key enforcement dates for EU AI Act, DORA, NIS2, FDA QMSR, EU CRA, and revised Product Liability Directive. Plan your terminology governance before auditors arrive.

Last verified: 22 June 2026. All dates below are cited inline against official sources (EUR-Lex, European Commission, Council of the EU, US Federal Register).

Upcoming Deadlines

Every date below is a moment when regulators, auditors, or enforcement bodies expect your organization to be compliant. Terminology governance is part of that readiness — controlled definitions, approval workflows, and audit trails take weeks to build, not days.

In force (already applied)

Date Regulation What Happened Terminology Impact
Jan 17, 2025 (In force) DORAReg. (EU) 2022/2554 DORA applied from this date to in-scope financial entities and their ICT third-party providers. [Source: EIOPA] ICT risk management, vendor oversight, and incident reporting terminology must be standardized
Oct 17, 2024 (In force) NIS2Dir. (EU) 2022/2555 National transposition deadline (passed; NIS1 repealed as from 18 October 2024; several Member States are still finalising national implementing laws). [Source: EC Digital Strategy] Cybersecurity governance terminology must reflect national transposition wording
Feb 2, 2026 (In force) FDA QMSR 21 CFR Part 820 amended to the Quality Management System Regulation, harmonised with ISO 13485:2016. [Source: Federal Register, 89 FR 7496] MedTech manufacturers: terminology must align with ISO 13485

Upcoming (not yet applied)

Date Regulation What Happens Terminology Impact
Aug 2, 2026 EU AI ActReg. (EU) 2024/1689 AI Office enforcement powers for providers of the most advanced general-purpose AI models enter into application. Parliament says most AI Act provisions still start on this date, while the Omnibus approval delays watermarking/marking obligations for AI-generated content to 2 December 2026, pending formal Council adoption. [Sources: AI Act Service Desk Article 50, EC Digital Strategy, European Parliament] GPAI documentation, transparency notices, and synthetic-content labels need controlled wording
Sep 11, 2026 Cyber Resilience Act (CRA)Reg. (EU) 2024/2847 Mandatory reporting obligations apply: actively exploited vulnerabilities and severe incidents in products with digital elements. [Source: EC Digital Strategy] New terminology for vulnerability disclosure and incident reporting processes
Dec 2, 2026 EU AI Act / AI Omnibus Political agreement sets this date for new Article 5 prohibitions and for providers of AI systems that generate synthetic audio, image, video, or text content placed on the market before 2 August 2026 to comply with Article 50(2). Pending formal adoption. [Sources: Council of the EU, Council doc. 10599/26] Teams need shared definitions for prohibited AI uses, synthetic content, watermarking, and disclosure language
Dec 9, 2026 Revised PLDDir. (EU) 2024/2853 Product Liability Directive transposition deadline. Software (including SaaS) is brought within scope of the EU product liability regime; reworked no-fault liability rules apply to products placed on the market after this date. [Source: EC Single Market] Software vendors face no-fault liability for defects; defect, damage, and producer terminology must be documented
Aug 2, 2027 EU AI ActReg. (EU) 2024/1689 General-purpose AI models placed on the EU market before 2 August 2025 must comply with the AI Act from this date. [Source: AI Act Service Desk] Legacy model documentation, downstream provider notices, and copyright-policy terminology need current definitions
Dec 2, 2027 EU AI Act / AI Omnibus Under the Commission and Council AI Omnibus timeline, Chapter III high-risk obligations for Annex III systems apply from this date: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, asylum, border control, justice, and democratic processes. [Sources: EC Digital Strategy, Council of the EU] Article 3 definitions must be consistent across risk management, data governance, logging, human oversight, and instructions for use
Dec 11, 2027 Cyber Resilience Act (CRA)Reg. (EU) 2024/2847 Full applicability: essential cybersecurity requirements for products with digital elements, conformity assessment, CE marking. [Source: EC Digital Strategy] Security-by-design, vulnerability-handling, and SBOM terminology must be documented
Aug 2, 2028 EU AI Act / AI Omnibus Under the Commission and Council AI Omnibus timeline, high-risk AI systems integrated into regulated products under Annex I apply from this date. [Sources: EC Digital Strategy, Council of the EU] Product technical files, conformity assessment records, and safety-component terminology must align with AI Act Article 3
AI Omnibus status: This calendar reflects official Commission and Council communications after the 7 May 2026 political agreement and European Parliament approval on 16 June 2026. Parliament says formal Council adoption is still needed before the Omnibus changes enter into force; verify the final Official Journal text before making legal decisions.

Recurring Compliance Cycles

Beyond fixed regulatory deadlines, these frameworks impose ongoing audit cycles. Each audit is a moment when your terminology governance will be examined.

Framework Cycle Typical Audit Period Terminology Impact
SOC 2 Type II Annual Rolling 12-month observation Security terminology must be consistent across all controls documentation
ISO 27001 3-year certification + annual surveillance Varies by registrar ISMS terminology must match Clause 3 definitions
ISO 13485 3-year certification + annual surveillance Varies by notified body Quality terminology must align with Clause 3
FDA inspections Unannounced, risk-based Any time All controlled vocabulary must be current and approved
HIPAA Annual risk assessment Self-assessed + OCR investigations PHI-related terminology must be standardized

Why Terminology Governance Cannot Wait

Building a compliant terminology system takes 2–4 weeks. Auditor findings take months to remediate. The math is simple — prepare now or explain later.

Controlled vocabulary is not a nice-to-have. It is the foundation that every policy document, every risk register, every incident report, and every compliance attestation relies on. When definitions are inconsistent, everything built on top of them is inconsistent — and auditors will find the cracks.

Every deadline on this calendar is a moment when an auditor might ask to see your controlled vocabulary, who approved the definitions, and when. If that evidence is not at hand, expect a finding.

The deadlines above are statutory dates or official EU implementation timelines. After they pass, non-compliance can carry real consequences: fines, enforcement actions, market access restrictions, and reputational damage. The time to build your terminology governance framework is before the deadline, not after the audit finding.

Start Preparing Now

Install Compliance Glossary and build your controlled vocabulary before the next deadline arrives.

Evaluate in Confluence View Security Whitepaper

Related Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

EU AI Act Terminology Governance — how to implement Article 3 definitions across your organization

Pharma Terminology Management — controlled vocabulary for pharmaceutical and life sciences teams

FinTech Compliance Terminology — regulatory terminology for financial services and payment companies

DORA Terminology Guide — ICT risk management vocabulary for financial entities

NIS2 Terminology Guide — cybersecurity governance terminology for essential and important entities

FDA Terminology Management — 43 terms for pharma & medtech, 21 CFR Part 11 aligned

SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards

Security Whitepaper — architecture, data handling, and security controls

Last updated: 22 June 2026. We update this calendar as regulations evolve. Bookmark this page.