Our own servers in Europe · GDPR · Support in your language

Reference · compliance dates

What changed, when, and who it affects

The dates that actually shape a quality, compliance or HR manager's calendar: when working-time records became mandatory in Spain, when ISO 27001:2013 certificates expired, since when audits run against IFS Food v8. Every entry links to the official text that sets the date.

What this page is for

Half an hour of any quality manager's week goes on answering 'since when is this mandatory?' or 'when does our certificate against the old edition expire?'. This page gathers those dates in one place, each with the official text that sets it, and works out on its own which are already in force and which are still pending. It is not legal advice: it tells you where to start looking.

Content reviewed on

How to read this
Ordered from most recent to oldest. The status is computed by comparing each date with the day the page loads, so anything marked pending genuinely is.
  1. Pending

    Directiva (UE) 2022/2464 y Directiva (UE) 2025/794

    Second wave of sustainability reporting

    After the two-year postponement approved by Directive (EU) 2025/794, large undertakings not previously covered by the non-financial reporting directive report on financial year 2027, published from 2028 onwards. The date shown here marks that start, not a specific deadline day.

    Who it affects: Large undertakings brought into the CSRD in the second wave

    Official text · EUR-Lex
  2. Pending

    Reglamento (UE) 2024/1689

    High-risk AI built into regulated products

    The extended deadline falls due for high-risk systems that are safety components of products already covered by harmonised Union legislation, such as machinery or medical devices.

    Who it affects: Manufacturers of regulated products embedding AI as a safety component

    Official text · EUR-Lex
  3. In force

    Reglamento (UE) 2024/1689

    Obligations for high-risk AI systems

    The obligations for the bulk of high-risk systems under the European AI Regulation become applicable: technical documentation, activity logging, risk management and effective human oversight.

    Who it affects: Anyone developing or using AI in recruitment, performance appraisal or task allocation

    Official text · EUR-Lex
  4. In force

    RD 1007/2023 y RD 254/2025

    Verifactu for the remaining taxpayers

    Those not paying corporate income tax must use invoicing software compliant with the regulation, producing chained, tamper-evident records.

    Who it affects: Self-employed and entities outside corporate income tax that issue invoices

    Official text · BOE-A-2023-24840
  5. In force

    Directiva (UE) 2023/970

    Transposition deadline for pay transparency

    The deadline falls for Member States to bring the pay transparency directive into national law: salary information in recruitment, the right to know pay levels and the duty to report on the pay gap.

    Who it affects: Every employer, with reinforced obligations above 100 and 250 people

    Official text · EUR-Lex
  6. In force

    RD 1007/2023 y RD 254/2025

    Verifactu for corporate income taxpayers

    Corporate income taxpayers must invoice using compliant software that generates a chained invoicing record for every invoice issued.

    Who it affects: Companies issuing invoices, save for the exceptions in the regulation itself

    Official text · BOE-A-2023-24840
  7. In force

    ISO 15189:2022

    End of the ISO 15189 transition

    Accreditations granted against the 2012 edition expire. The 2022 edition aligns the standard with ISO/IEC 17025 and absorbs point-of-care testing, previously covered by the withdrawn ISO 22870.

    Who it affects: Accredited medical laboratories

    Official text · ISO
  8. In force

    ISO/IEC 27001:2022

    End of the ISO 27001 transition

    Certificates issued against ISO 27001:2013 cease to be valid. The 2022 edition reorganised Annex A into 93 controls grouped in four themes and added eleven new controls.

    Who it affects: Organisations certified in information security

    Official text · ISO
  9. In force

    Reglamento (UE) 2024/1689

    Obligations for general-purpose AI models

    Transparency and documentation obligations start to apply to providers of general-purpose models.

    Who it affects: Providers of general-purpose AI models and anyone embedding them in a product

    Official text · EUR-Lex
  10. In force

    Directiva (UE) 2019/882

    Accessibility requirements for products and services

    The accessibility requirements of the European Accessibility Act apply to the products and services covered, including e-commerce and certain digital services.

    Who it affects: Companies offering consumers the products and services within the directive

    Official text · EUR-Lex
  11. In force

    Reglamento (UE) 2024/1689, art. 5

    Prohibited AI practices

    The article 5 prohibitions become applicable, among them inferring the emotions of people in the workplace save for narrowly defined medical or safety exceptions.

    Who it affects: Any organisation using AI on its workforce

    Official text · EUR-Lex
  12. In force

    Reglamento (UE) 2022/2554 (DORA)

    Digital operational resilience in finance

    The digital operational resilience regulation applies, with obligations on ICT risk management, incident reporting and oversight of critical technology providers.

    Who it affects: Financial entities and their technology providers

    Official text · EUR-Lex
  13. In force

    Directiva (UE) 2022/2555 (NIS2)

    NIS2 transposition deadline

    The deadline falls for Member States to transpose the cybersecurity directive, which widens the sectors covered and tightens risk management and incident reporting duties.

    Who it affects: Essential and important entities in the listed sectors, and their supply chain

    Official text · EUR-Lex
  14. In force

    Reglamento (UE) 2024/1689

    The AI Regulation enters into force

    The European artificial intelligence regulation enters into force, with staggered application by system type over the following three years.

    Who it affects: Providers and deployers of AI systems in the European Union

    Official text · EUR-Lex
  15. In force

    Reglamento (UE) 2024/1183

    eIDAS 2 enters into force

    The revision of the electronic identification regulation enters into force, keeping the three signature levels and creating the European Digital Identity Wallet.

    Who it affects: Anyone issuing or accepting electronic signatures across borders

    Official text · EUR-Lex
  16. In force

    FSSC 22000 v6

    Audits mandatory against version 6

    The transition from version 5.1 of the food safety certification scheme ends, built on ISO 22000 and the sector prerequisite programmes.

    Who it affects: Companies certified in FSSC 22000

    Official text · Foundation FSSC
  17. In force

    Amd 1:2024

    Climate change in management system standards

    ISO publishes the amendment adding to clauses 4.1 and 4.2 of ISO 9001, 14001, 45001, 27001 and the rest the duty to consider whether climate change is a relevant issue for the organisation and its interested parties.

    Who it affects: Every organisation certified against an ISO management system standard

    Official text · ISO
  18. In force

    Ley 2/2023

    Whistleblowing channel in companies of 50 to 249

    The extended deadline falls for companies with between fifty and 249 people to have an internal reporting channel, with acknowledgement within seven days and a reply within three months.

    Who it affects: Companies with 50 to 249 employees

    Official text · BOE-A-2023-4513
  19. In force

    IFS Food v8

    Audits mandatory against version 8

    From this date no audit is carried out against version 7. Version 8 reinforces food safety culture, food fraud and on-site verification, and keeps the KO requirements.

    Who it affects: Companies certified in IFS Food

    Official text · IFS Management GmbH
  20. In force

    BRCGS Food Safety, edición 9

    Audits begin against issue 9

    Audits start against the issue published in August 2022, with its fundamental requirements and its grading system.

    Who it affects: Companies certified in BRCGS

    Official text · BRCGS
  21. In force

    Real Decreto 311/2022

    New Spanish National Security Framework

    The royal decree regulating the ENS is published, repealing RD 3/2010, with basic, medium and high categories and specific compliance profiles.

    Who it affects: The Spanish public sector and the private entities serving it

    Official text · BOE-A-2022-7191
  22. In force

    Reglamento (UE) 2017/745 (MDR)

    The medical devices regulation applies

    The MDR applies, with reinforced requirements on clinical evaluation, post-market surveillance and unique device identification through the UDI system.

    Who it affects: Manufacturers, importers and distributors of medical devices

    Official text · EUR-Lex
  23. In force

    Real Decreto-ley 8/2019

    Working-time records become mandatory

    The duty comes into force to record daily the specific start and end time of the whole workforce, keeping it for four years at the disposal of the worker, their representatives and the Labour Inspectorate.

    Who it affects: Every employer with employed staff in Spain

    Official text · BOE-A-2019-3481
  24. In force

    Reglamento (UE) 2016/679 (RGPD)

    The General Data Protection Regulation applies

    The GDPR applies, with the record of processing activities, breach notification within seventy-two hours and fines of up to twenty million euros or four per cent of global turnover.

    Who it affects: Every organisation processing personal data in the European Union

    Official text · EUR-Lex

Does any of these dates catch you on the back foot?

We'll show you the module running with data similar to yours.

Request a demo

Entry-into-force dates and regulatory transitions

This regulatory calendar gathers the entry-into-force dates and end-of-transition deadlines that affect a management system: editions of ISO standards, food safety protocols, employment and tax obligations, and European regulations on cybersecurity and artificial intelligence.

Each entry states the rule that sets the date and links to its official text in the Spanish BOE, in EUR-Lex or at the body owning the protocol, so verification does not depend on this page but on the source.