Law & Compliance · 2026-09-16 · 14 min read

EU Deadlines at the End of 2026: Six Dates to 20 January, Two Already Past — and None of Them Asks How Big Your Company Is

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

Four months remain until 20 January 2027. Within those four months sit five EU deadlines that reach the mid-market directly — and behind two more, which have been history since last week, the obligations keep running. The stretch between 11 September 2026 and 20 January 2027 is the densest run of European regulatory dates any business year has contained this decade. The risk sits less in the date than in the reading: every one of these deadlines attaches to a product, a turnover figure or a function. None asks how big your company is.

This piece puts the seven dates on one page, in the order they arrive: what actually changes, who it hits and which task follows from it. Each passage links to the full analysis we published on that subject. The framing here is the one for a managing director who has to decide what they carry personally and what they hand off.

The two deadlines that already passed last week

On 11 September the reporting duty of the Cyber Resilience Act went live. Manufacturers of products with digital elements now report actively exploited vulnerabilities and severe security incidents through the Single Reporting Platform operated by ENISA, which went into operation the same day: early warning within 24 hours, notification within 72 hours, final report no later than 14 days after a corrective measure is available, and within one month for severe incidents. Two sharpeners are missing from most summaries. The duty covers products sold years ago — the cut-off sits in the regulation, not in your shipping date. And the manufacturer in law is whoever places the product on the market under their own name: a company that has an app or a portal developed externally and ships it under its own brand reports itself, not the contractor. What can be settled by contract is who detects, analyses and writes — not who is legally obliged. The full analysis is in our piece on the CRA reporting duty.

One day later, on 12 September, the most reported obligation of the Data Act began — and the most frequently misread. Article 3(1) requires connected products to be built so that their data is accessible by default, easily, securely and free of charge. The deadline only covers products placed on the market after it; the installed base stays outside. What has applied to the installed base for a year, though, is Article 4: where a user cannot take data directly from a connected product, they have been able to demand it on simple request since September 2025 — free of charge, machine-readable, without undue delay. That duty has been running unnoticed for twelve months, and it is the one through which the first request arrives. The details are in the Data Act analysis.

The shared point of the two September dates: a passed deadline does not lower the risk, it changes the question. Before the date it was whether you are prepared. After it, whether the process works. Anyone who has never practised registering on the ENISA platform or answering a data request is practising now, under time pressure.

The calendar up to 20 January

Five dates are still ahead of you, two are already running. The order is the order in the calendar:

DateWhat happensWho it hits
11 Sep 2026CRA reporting duty in force (24 h / 72 h / final report)Manufacturers of products with digital elements — including long-sold ones
12 Sep 2026Data Act design duty (Art. 3(1))Manufacturers of newly marketed connected products
20 Oct 2026Machinery Regulation Art. 50: states notify penalty rulesNo company duty — the day the cost of a breach becomes visible
2 Dec 2026AI Act transition period ends (Art. 50(2))Providers of AI systems marketed before 2 August 2026; in practice, your tool vendors
9 Dec 2026New product liability: software becomes a productAnyone placing software on the market after the date
1 Jan 2027E-invoicing issuing obligationCompanies with 2026 total turnover above 800,000 euros
20 Jan 2027Machinery Regulation applies in full; directive repealedManufacturers, importers, dealers — and anyone who modifies machinery

20 October 2026: the deadline that triggers no duty, but a number

The 20th of October is the only date in this list that demands nothing from your company — and still one of the important ones. Article 50 of the Machinery Regulation applies from that day, and its second paragraph obliges the member states to notify the Commission of their penalty rules. What a breach of the regulation actually costs in Germany is, until then, a provision without a number. From late October it becomes visible.

In practice: anyone with a machine or an assembly in the pipeline for 2027 should read the German penalty rules once they are published, rather than when the first contractual partner asks about them. The details are in our analysis of the Machinery Regulation.

2 December 2026: the deadline that ends at your provider, not at you

On 2 December the transition period for the machine-readable marking of AI-generated content ends. Article 50(2) of the AI Act requires the outputs of generative systems to be technically marked as AI-generated; for systems that were on the market before 2 August 2026, the Digital Omnibus allowed time until that date. The duty sits with the provider of the system, not with you as the user.

The day matters to you through a side condition: it decides whether the tools in your stack deliver in time. The question — does your generator mark its outputs as machine-readable, and from when — belongs in an email to your providers this week, not in the November meeting. Do not confuse it with what already applies: the disclosure duties of Article 50(1), that your chatbot identifies itself as AI, for instance, have been running since 2 August, and those are yours, not the provider's. The separation is in our piece on the marking obligations.

9 December 2026: from when an undelivered update creates liability

On 9 December software becomes a product. Article 4 of Directive (EU) 2024/2853 counts it expressly among the items for which liability is strict — and Article 11(2) switches off, for one case, the defence on which nearly every software-liability discussion used to end: that the product was sound when placed on the market. Where the defectiveness results from a missing update necessary to maintain safety, and that lies within the manufacturer's control, the shipping state no longer exculpates. Article 4(5)(b) defines control as the ability to supply updates — not their exercise.

The limits are just as concrete: only a natural person can claim; recoverable damage covers personal injury, property damage outside exclusively professional use, and the destruction of non-professional data. Pure B2B damage stays outside — but every licence you newly grant after the deadline counts as newly placed on the market, and every substantial modification restarts the ten-year period. From December, whether you still ship a security update for an old version is no longer a support decision but a liability decision. The full reading is in the piece on product liability.

1 January 2027: e-invoicing hangs on a number being created right now

The issuing obligation for e-invoices starts on 1 January 2027 for every German-established business whose 2026 total turnover exceeds 800,000 euros. The decisive part is the figure, and it is not the one in your accounts: section 19(2) UStG measures total turnover by consideration actually received — the inflow, not the invoicing — and expressly leaves out supplies of fixed assets. Anyone who sold a machine or a company car in 2026 carries the proceeds in the profit calculation, not in this figure. Within a corridor of about ten percent around the threshold, that decides whether your deadline is January 2027 or January 2028.

Two reliefs are regularly overlooked. Below the threshold you may keep invoicing on paper or in another format until the end of 2027, provided the recipient consents. And anyone transmitting invoices by EDI has until the end of 2027 regardless of turnover — the most practically important transitional rule for suppliers with grown EDI links, set out in section 27(38) UStG. From 1 January 2028 the obligation applies to everyone. The question for your tax adviser — what is our total turnover under section 19(2) — is answered in minutes and belongs in this September. The details are in the e-invoicing piece.

20 January 2027: the regulation replaces the directive — with no transition

On 20 January Machinery Directive 2006/42/EC is repealed, and Regulation (EU) 2023/1230 applies in full. There is no grace period; the cut-off attaches to the individual machine. Whatever was lawfully placed on the market before stays under the directive and is never re-assessed. What is new is that software expressly counts as a safety component — with two qualifiers missing from most summaries: the component must be placed on the market separately, and it must not be required for the product itself to function. Control software inseparable from the machine is therefore not a standalone safety component; a separately sold safety module is.

The second change sits in Article 18: anyone who makes a substantial modification counts as the manufacturer — with all obligations, on sole responsibility. Article 3(16) defines substantial through three cumulative elements, and the third filters out most updates: a change that requires no new guards and no new stability measures is not substantial. The regulation does not turn your maintenance department into a manufacturer; it captures rebuilding a machine into something its maker never intended — and that rebuilding can consist of software alone. What to do concretely is in the Machinery Regulation analysis.

The obligations without a calendar date that run anyway

Beside the seven dates, three regimes run without a deadline. The most visible is NIS2: by 30 June 2026, 17,729 entities had registered with the BSI, while the legislator budgeted for around 30,000. The gap sits almost entirely among the important entities — the size band from 50 employees, to which Annex 2 of the BSIG expressly assigns mechanical engineering. For management, two provisions decide: section 38 places the implementation and supervision of the measures on the management level and requires its own regular training; and the supply-chain clause pushes the questionnaires of regulated customers down to suppliers sitting far below every threshold. The details are in the NIS2 analysis.

The second running duty is the AI-literacy obligation of Article 4 of the AI Act — in force since February 2025, and it reaches you whether or not you have sanctioned any AI, because deploying in the sense of the regulation is using it within your area of responsibility. In a company where two-thirds of the workforce work around the policy, that is not a clause for the stack but one for training; the figures are in the piece on shadow AI. And since 2 August the right to an explanation under Article 86 applies: affected persons can demand a clear explanation where an AI-supported decision significantly affects them — the Omnibus postponed the high-risk duties, not this chapter.

Across all seven deadlines and three running duties the same pattern repeats: none of them asks how big your company is. They attach to a product, a turnover figure, a function or the question of who decides. That is also why they are so regularly misclassified in the mid-market — filed as a topic for a corporate legal department instead of for your own week.

What belongs on your desk this week

Most of the implementation behind these deadlines is delegable — the classification is not. Concretely, three tasks sit in this September week and need no specialist department:

TaskAddressed toDeadline behind it
Get the 2026 total turnover under section 19(2)Your tax adviser1 January 2027 (e-invoicing)
Ask providers in writing about machine-readable markingYour AI and software vendors2 December 2026 (AI Act Art. 50(2))
Assign two responsibilities in writing: who decides whether a modification is substantial, and who files under the CRAInternal20 January 2027 (Machinery Regulation) and continuously (CRA)

The rest of the list is calendar work: list the products going to market after 20 January; check whether an Annex 2 activity and fifty employees coincide in your house; settle who answers a Data Act request. This article is the map — each linked analysis contains the individual steps. If you take one thing: between today and 20 January there is no voluntary commitment and no recommendation. These are deadlines, and they apply.

Frequently asked questions about the EU deadlines

Which EU deadlines apply to mid-sized companies between September 2026 and January 2027?

Seven dates: since 11 September 2026 the Cyber Resilience Act reporting duty has applied to manufacturers of products with digital elements (early warning within 24 hours, notification within 72 hours). Since 12 September the Data Act design duty applies to connected products newly placed on the market. On 20 October member states must notify the Commission of their Machinery Regulation penalty rules — not a company obligation, but the day from which the cost of a breach becomes visible. On 2 December the transition period for machine-readable marking of AI-generated content ends. On 9 December software comes under product liability. On 1 January 2027 the e-invoicing issuing obligation starts for companies with more than 800,000 euros of 2026 total turnover. And on 20 January 2027 the Machinery Regulation applies in full, with no transition period.

Are we covered by the Cyber Resilience Act if we only run a website?

A website alone is not a product with digital elements and falls outside the reporting duty. Covered are manufacturers of products with digital elements — hardware, software and their combinations whose purpose includes connection to a network. What counts is who places the product on the market under their own name: a company that has an app or portal developed externally and ships it under its own brand is the manufacturer in law, the development partner is not. And the duty also covers products sold years ago, because it attaches to the product, not the shipping date.

What ends on 2 December 2026 in the AI Act?

The transition period for machine-readable marking under Article 50(2): systems that were on the market before 2 August 2026 must mark their output as AI-generated from that day. The duty sits with the provider of the system, not with users. It matters to you anyway because it decides whether the tools in your stack mark in time — put the question to your providers in writing now. Distinct from that is Article 50(1), the disclosure towards persons: it has applied since 2 August 2026 and is yours when you run a chatbot or an AI phone agent, for example.

Do we have to issue e-invoices from 1 January 2027?

Yes, if your 2026 total turnover exceeded 800,000 euros — measured under section 19(2) UStG, meaning actually received consideration and excluding fixed-asset disposals, not the revenue line in your accounts. Below that you may keep invoicing on paper or in another electronic format until the end of 2027 with the recipient’s consent. Anyone transmitting by EDI under Recommendation 94/820/EC has until the end of 2027 regardless of turnover. From 1 January 2028 the issuing obligation applies without those exceptions.

Does the management carry personal liability for these duties?

In one place, yes: section 38 BSIG puts the implementation and supervision of NIS2 risk-management measures on the management bodies and requires their own regular training — only the doing can be delegated, not the oversight. Under product liability the company is liable, but the decision to leave a known vulnerability without an update is a liability decision from 9 December. For the CRA, the Data Act and e-invoicing the company carries the duty; what stays on your desk is the named responsibility, not the technology.

Does the Machinery Regulation apply to our installed base?

The cut-off applies per machine: whatever was lawfully placed on the market before 20 January 2027 stays under the directive and never needs re-assessment. It looks different for substantial modifications: anyone who rebuilds a machine so that a new risk arises and guards or stability measures become necessary counts as the manufacturer of the modified machine under Article 18. An update foreseen by the manufacturer already fails the first of the three criteria in Article 3(16); a freely programmed rebuild of the control system can meet all three.

What is the first step if we want to start this week?

Three emails, none of them to an external consultant: to your tax adviser, a request for your 2026 total turnover under section 19(2); to your AI and software providers, the question whether and from when their outputs are marked as machine-readable; and internally, a written assignment of two responsibilities — who decides whether a change to a machine or software is substantial, and who triggers the 24-hour report when a vulnerability is actively exploited. Anyone with time after that lists the products to be placed on the market after 20 January.

Sources, status and note: All provisions were checked verbatim against the regulation texts, retrieved on 16 September 2026: the Cyber Resilience Act (EU) 2024/2847 for Article 14 and the reporting deadlines; the ENISA announcement and the Single Reporting Platform page for the platform status since 11 September 2026; the Data Act (EU) 2023/2854 for Articles 3 and 4 and the staggered application dates; the AI Act (EU) 2024/1689 together with the Digital Omnibus for Articles 4, 50 and 86 and the 2 December transition; the Product Liability Directive (EU) 2024/2853 for Articles 4, 5, 6 and 11; the Machinery Regulation (EU) 2023/1230 and the Machinery Directive 2006/42/EC for Articles 3, 18, 50 and 54; section 19(2) and section 27(38) UStG plus the BMF e-invoicing FAQ for the turnover threshold and the transition rules; and the BSI pages NIS-2 in Zahlen, section 38 BSIG and Annex 2 BSIG for the registration figures and the management duties. This article is an analysis, not legal advice.