Kortave
Back to Kortave

[ Regulation Radar ]

Every EU deadline.
One feed.

Real-time tracking of 10 EU regulations — from GDPR to the Cyber Resilience Act. 72-hour alerts when enforcement changes.

Click any card for details

GDPR

General Data Protection Regulation

Data subject rights automation & DPA enforcement cycle.

Next milestone
Jan 31 each year
Enforcement active
EU AI Act

EU Artificial Intelligence Act

High-risk AI system obligations & GPAI model compliance.

Full enforcement countdown
00d
00h
00m
00s
Phased rollout
NIS2

NIS2 Directive

Network & information security obligations across critical sectors.

EU implementation deadline
Oct 17 2024
Active
DORA

Digital Operational Resilience Act

Digital operational resilience for financial entities.

Full application since
Jan 17 2025
Enforcement active
CRA

Cyber Resilience Act

Mandatory cybersecurity requirements for all products with digital elements.

Full compliance by
00d
00h
00m
00s
Phased rollout
Data Act

EU Data Act

Rules for access to and use of data generated by connected products.

Applicable since
Sep 12 2025
Active
DSA

Digital Services Act

Content moderation, transparency, and systemic risk obligations for platforms.

Full application since
Feb 17 2024
Enforcement active
DMA

Digital Markets Act

Obligations for designated "gatekeepers" of core platform services.

Enforcement began
Mar 7 2024
Enforcement active
ePrivacy

ePrivacy Regulation

Successor to the Cookie Directive — governing electronic communications privacy.

Legislative status
Council negotiations
Pending adoption
CSRD

Corporate Sustainability Reporting Directive

Mandatory ESG reporting under European Sustainability Reporting Standards.

First reports (large cos) for
FY 2024 → filed 2025
Phased rollout

[ Enforcement Timeline ]

What's coming next

Jan 17 2025DORA

DORA becomes fully applicable

All financial entities must meet ICT risk management, incident reporting, and third-party oversight requirements.

Mar 2025EU AI Act

GPAI model obligations apply

General-purpose AI model providers must comply with transparency, documentation, and copyright obligations.

Sep 12 2025Data Act

EU Data Act becomes applicable

IoT manufacturers must provide users access to generated data; B2B data-sharing fairness rules take effect.

Feb 2026CRA

CRA reporting obligations begin

Manufacturers of products with digital elements must begin vulnerability reporting to ENISA.

Aug 2 2026EU AI Act

Full enforcement for high-risk AI

High-risk AI systems in Annex III must be compliant or face market withdrawal and fines up to €35M.

Jan 2027NIS2

Cross-border incident reporting matures

Harmonised EU-wide significant incident reporting standards fully operational across all member states.

Aug 11 2027CRA

CRA full compliance deadline

All products with digital elements must carry CE marking demonstrating CRA conformity.

2027DORA

TLPT first cycle deadline

Threat-Led Penetration Testing mandatory first cycle must be completed by significant financial entities.

Get 72-hour alerts

Kortave monitors DPA enforcement actions and legislative amendments. Get notified before they affect your business.

No spam. Covers GDPR, EU AI Act, NIS2, DORA, CRA, Data Act.

[ What we track ]

Get protected now →Read our compliance blog →

KORTAVE — EU COMPLIANCE INTELLIGENCE · 10 REGULATIONS TRACKED