Key enforcement dates for EU AI Act, DORA, NIS2, FDA QMSR, EU CRA, and revised Product Liability Directive. Plan your terminology governance before auditors arrive.
Last verified: 22 June 2026. All dates below are cited inline against official sources (EUR-Lex, European Commission, Council of the EU, US Federal Register).
Every date below is a moment when regulators, auditors, or enforcement bodies expect your organization to be compliant. Terminology governance is part of that readiness — controlled definitions, approval workflows, and audit trails take weeks to build, not days.
| Date | Regulation | What Happened | Terminology Impact |
|---|---|---|---|
| Jan 17, 2025 (In force) | DORA — Reg. (EU) 2022/2554 | DORA applied from this date to in-scope financial entities and their ICT third-party providers. [Source: EIOPA] | ICT risk management, vendor oversight, and incident reporting terminology must be standardized |
| Oct 17, 2024 (In force) | NIS2 — Dir. (EU) 2022/2555 | National transposition deadline (passed; NIS1 repealed as from 18 October 2024; several Member States are still finalising national implementing laws). [Source: EC Digital Strategy] | Cybersecurity governance terminology must reflect national transposition wording |
| Feb 2, 2026 (In force) | FDA QMSR | 21 CFR Part 820 amended to the Quality Management System Regulation, harmonised with ISO 13485:2016. [Source: Federal Register, 89 FR 7496] | MedTech manufacturers: terminology must align with ISO 13485 |
| Date | Regulation | What Happens | Terminology Impact |
|---|---|---|---|
| Aug 2, 2026 | EU AI Act — Reg. (EU) 2024/1689 | AI Office enforcement powers for providers of the most advanced general-purpose AI models enter into application. Parliament says most AI Act provisions still start on this date, while the Omnibus approval delays watermarking/marking obligations for AI-generated content to 2 December 2026, pending formal Council adoption. [Sources: AI Act Service Desk Article 50, EC Digital Strategy, European Parliament] | GPAI documentation, transparency notices, and synthetic-content labels need controlled wording |
| Sep 11, 2026 | Cyber Resilience Act (CRA) — Reg. (EU) 2024/2847 | Mandatory reporting obligations apply: actively exploited vulnerabilities and severe incidents in products with digital elements. [Source: EC Digital Strategy] | New terminology for vulnerability disclosure and incident reporting processes |
| Dec 2, 2026 | EU AI Act / AI Omnibus | Political agreement sets this date for new Article 5 prohibitions and for providers of AI systems that generate synthetic audio, image, video, or text content placed on the market before 2 August 2026 to comply with Article 50(2). Pending formal adoption. [Sources: Council of the EU, Council doc. 10599/26] | Teams need shared definitions for prohibited AI uses, synthetic content, watermarking, and disclosure language |
| Dec 9, 2026 | Revised PLD — Dir. (EU) 2024/2853 | Product Liability Directive transposition deadline. Software (including SaaS) is brought within scope of the EU product liability regime; reworked no-fault liability rules apply to products placed on the market after this date. [Source: EC Single Market] | Software vendors face no-fault liability for defects; defect, damage, and producer terminology must be documented |
| Aug 2, 2027 | EU AI Act — Reg. (EU) 2024/1689 | General-purpose AI models placed on the EU market before 2 August 2025 must comply with the AI Act from this date. [Source: AI Act Service Desk] | Legacy model documentation, downstream provider notices, and copyright-policy terminology need current definitions |
| Dec 2, 2027 | EU AI Act / AI Omnibus | Under the Commission and Council AI Omnibus timeline, Chapter III high-risk obligations for Annex III systems apply from this date: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, asylum, border control, justice, and democratic processes. [Sources: EC Digital Strategy, Council of the EU] | Article 3 definitions must be consistent across risk management, data governance, logging, human oversight, and instructions for use |
| Dec 11, 2027 | Cyber Resilience Act (CRA) — Reg. (EU) 2024/2847 | Full applicability: essential cybersecurity requirements for products with digital elements, conformity assessment, CE marking. [Source: EC Digital Strategy] | Security-by-design, vulnerability-handling, and SBOM terminology must be documented |
| Aug 2, 2028 | EU AI Act / AI Omnibus | Under the Commission and Council AI Omnibus timeline, high-risk AI systems integrated into regulated products under Annex I apply from this date. [Sources: EC Digital Strategy, Council of the EU] | Product technical files, conformity assessment records, and safety-component terminology must align with AI Act Article 3 |
Beyond fixed regulatory deadlines, these frameworks impose ongoing audit cycles. Each audit is a moment when your terminology governance will be examined.
| Framework | Cycle | Typical Audit Period | Terminology Impact |
|---|---|---|---|
| SOC 2 Type II | Annual | Rolling 12-month observation | Security terminology must be consistent across all controls documentation |
| ISO 27001 | 3-year certification + annual surveillance | Varies by registrar | ISMS terminology must match Clause 3 definitions |
| ISO 13485 | 3-year certification + annual surveillance | Varies by notified body | Quality terminology must align with Clause 3 |
| FDA inspections | Unannounced, risk-based | Any time | All controlled vocabulary must be current and approved |
| HIPAA | Annual risk assessment | Self-assessed + OCR investigations | PHI-related terminology must be standardized |
Building a compliant terminology system takes 2–4 weeks. Auditor findings take months to remediate. The math is simple — prepare now or explain later.
Controlled vocabulary is not a nice-to-have. It is the foundation that every policy document, every risk register, every incident report, and every compliance attestation relies on. When definitions are inconsistent, everything built on top of them is inconsistent — and auditors will find the cracks.
Every deadline on this calendar is a moment when an auditor might ask to see your controlled vocabulary, who approved the definitions, and when. If that evidence is not at hand, expect a finding.
The deadlines above are statutory dates or official EU implementation timelines. After they pass, non-compliance can carry real consequences: fines, enforcement actions, market access restrictions, and reputational damage. The time to build your terminology governance framework is before the deadline, not after the audit finding.
Install Compliance Glossary and build your controlled vocabulary before the next deadline arrives.
Evaluate in Confluence View Security WhitepaperCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
EU AI Act Terminology Governance — how to implement Article 3 definitions across your organization
Pharma Terminology Management — controlled vocabulary for pharmaceutical and life sciences teams
FinTech Compliance Terminology — regulatory terminology for financial services and payment companies
DORA Terminology Guide — ICT risk management vocabulary for financial entities
NIS2 Terminology Guide — cybersecurity governance terminology for essential and important entities
FDA Terminology Management — 43 terms for pharma & medtech, 21 CFR Part 11 aligned
SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards
Security Whitepaper — architecture, data handling, and security controls
Last updated: 22 June 2026. We update this calendar as regulations evolve. Bookmark this page.