Reference · compliance dates
What changed, when, and who it affects
The dates that actually shape a quality, compliance or HR manager's calendar: when working-time records became mandatory in Spain, when ISO 27001:2013 certificates expired, since when audits run against IFS Food v8. Every entry links to the official text that sets the date.
What this page is for
Half an hour of any quality manager's week goes on answering 'since when is this mandatory?' or 'when does our certificate against the old edition expire?'. This page gathers those dates in one place, each with the official text that sets it, and works out on its own which are already in force and which are still pending. It is not legal advice: it tells you where to start looking.
-
Pending
Directiva (UE) 2022/2464 y Directiva (UE) 2025/794
Second wave of sustainability reporting
After the two-year postponement approved by Directive (EU) 2025/794, large undertakings not previously covered by the non-financial reporting directive report on financial year 2027, published from 2028 onwards. The date shown here marks that start, not a specific deadline day.
Who it affects: Large undertakings brought into the CSRD in the second wave
Official text · EUR-Lex -
Pending
Reglamento (UE) 2024/1689
High-risk AI built into regulated products
The extended deadline falls due for high-risk systems that are safety components of products already covered by harmonised Union legislation, such as machinery or medical devices.
Who it affects: Manufacturers of regulated products embedding AI as a safety component
Official text · EUR-Lex -
In force
Reglamento (UE) 2024/1689
Obligations for high-risk AI systems
The obligations for the bulk of high-risk systems under the European AI Regulation become applicable: technical documentation, activity logging, risk management and effective human oversight.
Who it affects: Anyone developing or using AI in recruitment, performance appraisal or task allocation
Official text · EUR-Lex -
In force
RD 1007/2023 y RD 254/2025
Verifactu for the remaining taxpayers
Those not paying corporate income tax must use invoicing software compliant with the regulation, producing chained, tamper-evident records.
Who it affects: Self-employed and entities outside corporate income tax that issue invoices
Official text · BOE-A-2023-24840 -
In force
Directiva (UE) 2023/970
Transposition deadline for pay transparency
The deadline falls for Member States to bring the pay transparency directive into national law: salary information in recruitment, the right to know pay levels and the duty to report on the pay gap.
Who it affects: Every employer, with reinforced obligations above 100 and 250 people
Official text · EUR-Lex -
In force
RD 1007/2023 y RD 254/2025
Verifactu for corporate income taxpayers
Corporate income taxpayers must invoice using compliant software that generates a chained invoicing record for every invoice issued.
Who it affects: Companies issuing invoices, save for the exceptions in the regulation itself
Official text · BOE-A-2023-24840 -
In force
ISO 15189:2022
End of the ISO 15189 transition
Accreditations granted against the 2012 edition expire. The 2022 edition aligns the standard with ISO/IEC 17025 and absorbs point-of-care testing, previously covered by the withdrawn ISO 22870.
Who it affects: Accredited medical laboratories
Official text · ISO -
In force
ISO/IEC 27001:2022
End of the ISO 27001 transition
Certificates issued against ISO 27001:2013 cease to be valid. The 2022 edition reorganised Annex A into 93 controls grouped in four themes and added eleven new controls.
Who it affects: Organisations certified in information security
Official text · ISO -
In force
Reglamento (UE) 2024/1689
Obligations for general-purpose AI models
Transparency and documentation obligations start to apply to providers of general-purpose models.
Who it affects: Providers of general-purpose AI models and anyone embedding them in a product
Official text · EUR-Lex -
In force
Directiva (UE) 2019/882
Accessibility requirements for products and services
The accessibility requirements of the European Accessibility Act apply to the products and services covered, including e-commerce and certain digital services.
Who it affects: Companies offering consumers the products and services within the directive
Official text · EUR-Lex -
In force
Reglamento (UE) 2024/1689, art. 5
Prohibited AI practices
The article 5 prohibitions become applicable, among them inferring the emotions of people in the workplace save for narrowly defined medical or safety exceptions.
Who it affects: Any organisation using AI on its workforce
Official text · EUR-Lex -
In force
Reglamento (UE) 2022/2554 (DORA)
Digital operational resilience in finance
The digital operational resilience regulation applies, with obligations on ICT risk management, incident reporting and oversight of critical technology providers.
Who it affects: Financial entities and their technology providers
Official text · EUR-Lex -
In force
Directiva (UE) 2022/2555 (NIS2)
NIS2 transposition deadline
The deadline falls for Member States to transpose the cybersecurity directive, which widens the sectors covered and tightens risk management and incident reporting duties.
Who it affects: Essential and important entities in the listed sectors, and their supply chain
Official text · EUR-Lex -
In force
Reglamento (UE) 2024/1689
The AI Regulation enters into force
The European artificial intelligence regulation enters into force, with staggered application by system type over the following three years.
Who it affects: Providers and deployers of AI systems in the European Union
Official text · EUR-Lex -
In force
Reglamento (UE) 2024/1183
eIDAS 2 enters into force
The revision of the electronic identification regulation enters into force, keeping the three signature levels and creating the European Digital Identity Wallet.
Who it affects: Anyone issuing or accepting electronic signatures across borders
Official text · EUR-Lex -
In force
FSSC 22000 v6
Audits mandatory against version 6
The transition from version 5.1 of the food safety certification scheme ends, built on ISO 22000 and the sector prerequisite programmes.
Who it affects: Companies certified in FSSC 22000
Official text · Foundation FSSC -
In force
Amd 1:2024
Climate change in management system standards
ISO publishes the amendment adding to clauses 4.1 and 4.2 of ISO 9001, 14001, 45001, 27001 and the rest the duty to consider whether climate change is a relevant issue for the organisation and its interested parties.
Who it affects: Every organisation certified against an ISO management system standard
Official text · ISO -
In force
Ley 2/2023
Whistleblowing channel in companies of 50 to 249
The extended deadline falls for companies with between fifty and 249 people to have an internal reporting channel, with acknowledgement within seven days and a reply within three months.
Who it affects: Companies with 50 to 249 employees
Official text · BOE-A-2023-4513 -
In force
IFS Food v8
Audits mandatory against version 8
From this date no audit is carried out against version 7. Version 8 reinforces food safety culture, food fraud and on-site verification, and keeps the KO requirements.
Who it affects: Companies certified in IFS Food
Official text · IFS Management GmbH -
In force
BRCGS Food Safety, edición 9
Audits begin against issue 9
Audits start against the issue published in August 2022, with its fundamental requirements and its grading system.
Who it affects: Companies certified in BRCGS
Official text · BRCGS -
In force
Real Decreto 311/2022
New Spanish National Security Framework
The royal decree regulating the ENS is published, repealing RD 3/2010, with basic, medium and high categories and specific compliance profiles.
Who it affects: The Spanish public sector and the private entities serving it
Official text · BOE-A-2022-7191 -
In force
Reglamento (UE) 2017/745 (MDR)
The medical devices regulation applies
The MDR applies, with reinforced requirements on clinical evaluation, post-market surveillance and unique device identification through the UDI system.
Who it affects: Manufacturers, importers and distributors of medical devices
Official text · EUR-Lex -
In force
Real Decreto-ley 8/2019
Working-time records become mandatory
The duty comes into force to record daily the specific start and end time of the whole workforce, keeping it for four years at the disposal of the worker, their representatives and the Labour Inspectorate.
Who it affects: Every employer with employed staff in Spain
Official text · BOE-A-2019-3481 -
In force
Reglamento (UE) 2016/679 (RGPD)
The General Data Protection Regulation applies
The GDPR applies, with the record of processing activities, breach notification within seventy-two hours and fines of up to twenty million euros or four per cent of global turnover.
Who it affects: Every organisation processing personal data in the European Union
Official text · EUR-Lex
Does any of these dates catch you on the back foot?
We'll show you the module running with data similar to yours.
Keep exploring
Related pages
Legal requirements, tracked one by one
Register the legal requirements that apply to you, get an alert when the regulation changes, and…
The terms, stated precisely
What nonconformity, documented information, geofence, MTBF, advanced signature or certified digitisation…
Your management system stops being a folder
Living documentation, planned audits, non-conformities with an owner, and indicators that calculate…
Learn quality standards and BPM concepts without leaving the platform
Chapter-by-chapter guides on every ISO standard and sector protocol, plus the process management (BPM)…
Entry-into-force dates and regulatory transitions
This regulatory calendar gathers the entry-into-force dates and end-of-transition deadlines that affect a management system: editions of ISO standards, food safety protocols, employment and tax obligations, and European regulations on cybersecurity and artificial intelligence.
Each entry states the rule that sets the date and links to its official text in the Spanish BOE, in EUR-Lex or at the body owning the protocol, so verification does not depend on this page but on the source.