Guides · Updated August 2026
The deadlines that ask for documents, not statements.
Fourteen dates, from June 2026 to December 2027, plus the two AI Act dates that rest on the same documents. For each one: the rule, what you need to have in hand when someone knocks, the note that tells the story and the solution that covers it.
One difference decides the outcome of an inspection: between what an organisation does and what it can show it has done. The deadlines collected here all belong to the second kind — they ask for a dated document, not a statement of intent.
Many of them ask different parties for the same material. The Cyber Resilience Act requires a single technical documentation, but only for products with digital elements that are also high-risk AI systems within the meaning of art. 12 and that are covered by other Union acts requiring technical documentation (art. 31(3)). For everyone else the overlap is not a duty but an economy: anyone rewriting manuals for January 2027 is already working on the binder that December will need.
-
ACN cloud rules: the transitional tolerance is over
- Rule
- Regulation on digital infrastructure and cloud services for public administration, ACN directorial decree no. 21007/24 of 27 June 2024 (notice in Official Gazette no. 163 of 13 July 2024), art. 11(4) and (10)
- Who it concerns
- Public administrations and bodies handling critical or strategic data.
What you need to have
- The classification of data and digital services into ordinary, critical and strategic, with the reasoning written next to it (art. 3). Where data falls inside the National Cybersecurity Perimeter or the NIS duties, the class is set by law.
- A check of the supplier’s qualification level in the ACN catalogue, not in the brochure: at least QC2 for critical data, QC3 or QC4 for strategic data (art. 17).
- A remediation plan for whatever is out of place: what moves, where, by when, who signs.
For strategic data, Annex 2 adds a jurisdictional constraint: any access request by a non-EU entity must be reported to ACN and granted only after explicit authorisation by the administration.
-
Cyber Resilience Act: the reporting duty
- Rule
- Regulation (EU) 2024/2847, art. 14
- Who it concerns
- Manufacturers of products with digital elements — connected or connectable hardware and software — including products already on the market.
What you need to have
- A channel for receiving vulnerability reports and a coordinated disclosure policy, with a named owner and a triage that works.
- The software bill of materials for your products: without knowing what is inside, no report can be made in time.
- The notification path rehearsed at least once: early warning within 24 hours, notification within 72, final report within 14 days of the corrective or mitigating measure being made available for actively exploited vulnerabilities and within one month of the 72-hour notification for severe incidents (Art. 14(2) and (4)). The two final deadlines run from different starting points, and the 72-hour notification calls for «general information, where available», not a complete picture.
The clock starts when the manufacturer “becomes aware” of the problem: the real constraint is the ability to notice, not the notification itself. On 27 July 2026 the Commission approved the content of the draft communication carrying its guidance on applying the regulation (C(2026) 5252 and annex), for now available in English only: formal adoption will come when all language versions are ready, and only from that moment will the guidance apply. On the substance, it clarifies the scope — remote data processing solutions and free and open source software included —, what counts as a substantial modification, how the support period is determined and how the reporting and risk assessment obligations are met. It is not binding and it does not move 11 September: it is what you write your choices against. Two points in the annex change the scope of the work. First: the duty also covers products placed on the market before 11 December 2027 (art. 69(3)) and stays in force after the support period ends, while the vulnerability handling duties in Annex I, Part II, do not apply in those cases. Second: there is no retroactive reporting — a vulnerability whose active exploitation you already knew about before 11 September 2026 need not be notified, but if the exploitation happens, or you become aware of it, after that date the duty applies.
-
Data Act: product data accessible by design
- Rule
- Regulation (EU) 2023/2854 (Data Act), art. 3(1), applicable under art. 50, third paragraph
- Who it concerns
- Manufacturers of connected products and providers of related services placing them on the Union market after that date; by extension, whoever buys those products and puts them into service.
What you need to have
- The design put in writing: product data and related service data, including the metadata needed to interpret and use them, accessible to the user by default “easily, securely, free of charge, in a comprehensive, structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly” (art. 3(1)).
- The pre-contractual information of art. 3(2), points (a) to (d): the type, format and estimated volume of data the product can generate; whether it generates them continuously and in real time; whether it stores them on-device or on a remote server, and for how long; how the user may access, retrieve or erase them, with which technical means, under what conditions of use and at what quality of service.
- The line between accessible data and trade secrets, drawn before the first request: which data stay out, under which protection measures and on what basis. Confidentiality is protected by the Regulation, but it is not a shortcut for refusing access.
- The placing-on-the-market date of every model in the catalogue. The duty does not look at the installed base: it looks at what is placed on the market after 12 September 2026, product by product.
This is the only Data Act deadline measured on the product rather than on the contract. The Regulation has applied since 12 September 2025 (art. 50, second paragraph), but not all of it at once: the third paragraph defers the duty in art. 3(1) alone and ties it to placing on the market, while the sixth paragraph pushes the application of Chapter IV to 12 September 2027 for certain contracts concluded on or before 12 September 2025. For buyers it is the lever: from that date access to data is not a concession to be negotiated, it is a design requirement the supplier must already have met.
-
RENTRI: penalties start on missing waste manifests
- Rule
- Legislative Decree no. 152 of 3 April 2006, art. 258, paragraphs 10 and 10-bis
- Who it concerns
- Entities and businesses already registered with RENTRI and required to transmit waste manifests (FIR) digitally: the three registration windows under art. 13 of Ministerial Decree no. 59 of 4 April 2023 have all now closed, the last one by mid-February 2026.
What you need to have
- For every load transmitted to RENTRI since registration, proof the manifest came back complete: the penalty covers missing or incomplete transmission of manifest data, not only its absence.
- A list of manifests still open, by plant, with the name of whoever has to close them before the transitional tolerance ends.
- Proof that registration itself happened within the art. 13 windows: the penalty for missing or irregular registration (art. 258, paragraph 10, first sentence) has no tolerance under paragraph 10-bis and is already fully in force.
Paragraph 10-bis is a “first application” rule: it suspends, rather than cancels, the penalty for missing or incomplete manifests until 15 September 2026, while leaving the penalty for missing or irregular registration already active. The fine set by paragraph 10 runs from five hundred to two thousand euros for non-hazardous waste and from one thousand to three thousand for hazardous waste; it drops to a third if registration happens within sixty days of the deadline (paragraph 11).
-
NEWS-D: Italy’s drug early-warning regulation enters into force
- Rule
- Italy: DPCM 7 July 2026, no. 156 (Official Gazette, General Series no. 204 of 3 September 2026), implementing Article 14-bis of Presidential Decree 309/1990
- Who it concerns
- First- and second-level NEWS-D collaborating centres: public, private and university clinical and forensic toxicology laboratories, forensic medicine institutes, emergency units, poison control centres, police laboratories, and private bodies seeking recognition by an act of the head of the Department.
What you need to have
- The criterion that triggers a report, applicable without having to look it up elsewhere. The quantitative one (Article 6, paragraph 4) is measured against the averages «riportate nella più recente relazione al Parlamento sui dati relativi allo stato delle tossicodipendenze in Italia» — *reported in the most recent report to Parliament on the state of drug addiction in Italy*; the qualitative one covers substances «sequestrate con frequenza atipica rispetto a una specifica zona geografica o mai sequestrate a livello nazionale o unionale» (paragraph 3, letter d). Neither figure sits inside the laboratory.
- The two reporting clocks kept apart: without delay for the qualitative criterion, at least monthly and in aggregate form for the quantitative one (Article 7). Other collaborating centres report without delay in every case.
- The minimum fields of the form under Article 8, which change with the type of sample: date and province of the seizure for a non-biological sample, date and region of the poisoning or death for a biological one. The same event changes geographical grain depending on who records it.
- For private laboratories seeking recognition as second-level centres: standardised procedures to ensure the quality, traceability and comparability of analyses, and participation in external or inter-laboratory quality schemes (Article 21, paragraph 3), plus the minimum requirements in Annex I to the Ministry of Health decree of 23 June 2025 (Article 22), on which the ISS may run sample checks.
- Clearance from the judicial authority, where deemed necessary, before reporting data originating from seizures under Article 73 of the consolidated act or from investigative activity (Article 19, paragraph 2).
The regulation does not establish NEWS-D: the system has existed since 1 January 2025 under Article 14-bis of the consolidated act on narcotics, inserted by Article 1, paragraph 243 of the budget law of 30 December 2024, no. 207, whose paragraph 6 gave ninety days for the implementing decree. The deadline fell on 1 April 2025 and the DPCM is dated 7 July 2026: 462 days later. Two things stay open past 18 September. First, the permanent operator has not been chosen — Article 23 has the ISS run the system pending completion of the selection procedure under Article 11. Second, ownership of the data splits in two: Article 24 leaves the reporting centre the data in its own report, but makes the data loaded into the dedicated IT device, intended for output documents, shared with the Department. Whoever reports does not lose the data, but no longer controls it alone.
-
ICT census: public bodies declare what is in the machine room
- Rule
- Article 33-septies(1-ter) of Decree-Law 179/2012; AgID survey opened on 22 July 2026
- Who it concerns
- Central and local public administrations required to answer the questionnaire on their ICT estate. For schools and universities AgID has said the deadline will be announced later: 30 September is not a universal cut-off.
What you need to have
- A real inventory of systems, applications and services in operation, stating where they run and who manages them: it is the basis for every answer, and almost nobody has it ready.
- The classification of data and services under the ACN cloud regulation, which uses the same framework and the same categories.
- The final declaration of completeness and accuracy, signed by the legal representative or the digital transition officer: you sign for figures that must be verifiable.
Anyone who has never taken the inventory signs for figures they do not know. And that inventory is the same map security needs: your exposed surface is the part you can list.
-
NIS2: the baseline security measures, evidenced
- Rule
- Italian Legislative Decree 138 of 4 September 2024, arts. 23, 24 and 29, with the deadline set by art. 42(1)(c) and by ACN determination 379907/2025
- Who it concerns
- Essential and important entities in the first wave: registered between December 2024 and February 2025, they received their listing notification from 12 April 2025 onwards.
What you need to have
- Board minutes: approval of the risk management measures, supervision of their implementation, evidence of the training received by senior management (art. 23).
- An up-to-date risk analysis on the organisation’s real systems, plus inventories of systems, configurations, known vulnerabilities and staff with access.
- A register of critical suppliers and contracts with security clauses: existing contracts need not be amended immediately, but new contracts, renewals and extensions incorporate them. The ACN FAQs updated on 24 July 2026 (MSB.13-MSB.19) clarify that requirements need only be set for supplies with a potential security impact, and that not every baseline measure has to be pushed onto the supplier — but the tailoring has to be justified in writing, and that justification is itself a document to hold.
- Business continuity and disaster recovery plans that have been tested, not only written, and a staff training register.
- Incident notification procedures actually rehearsed: early warning to CSIRT Italia within 24 hours, full notification within 72, final report within one month. For the first wave the art. 25 notification duty has been in force since January 2026: October adds the measures, not the notification.
- Evidence that access control, encryption and network segmentation are active — not the policy that prescribes them.
The deadline is not the same for everyone: it runs eighteen months from the receipt of each entity’s own listing notification (ACN determination 379907/2025, art. 3), and those notifications started going out on 12 April 2025 — so the date has to be worked out entity by entity, within the October 2026 that ACN indicates. For entities listed for the first time in 2026 the deadline is 31 July 2027, with the notification duty running from 1 January 2027 (ACN determination 127434/2026, art. 1). On 11 August 2026 ACN published a new FAQ section, MVE.1 to MVE.5, on monitoring, supervision and enforcement, with MVE.3 covering the checks and inspections of art. 36. The distinction is set by the decree itself: art. 36(2) provides that «nei confronti dei soggetti importanti, i poteri di verifica e ispettivi si applicano unicamente qualora l’Autorità nazionale competente NIS acquisisca o riceva elementi di prova, indicazioni o informazioni che suggeriscano possibili violazioni del presente decreto» — against important entities the powers apply only where the authority has evidence or indications of possible breaches. For essential entities that limit does not apply: the check can come first, and it comes on documents that must already exist by then.
-
Annual landfill guarantees: the decree is converted, or it falls retroactively
- Rule
- Italian Decree-Law 154 of 28 August 2026, art. 1, replacing art. 208(11)(g) of Legislative Decree 152 of 3 April 2006; conversion deadline under Article 77, third paragraph, of the Constitution
- Who it concerns
- Companies admitted to extraordinary administration under Decree-Law 347 of 23 December 2003 — which requires at least five hundred employees for a year and debts of no less than three hundred million euros — running at least one plant declared of national strategic interest under art. 1 of Decree-Law 207 of 3 December 2012, a status conferred by decree of the Prime Minister and presupposing at least two hundred employees for at least a year. A narrow field, drawn by two cross-references rather than by a list.
What you need to have
- The financial guarantee actually in place, with its start and end dates: from 29 August 2026 it may be annual even where the authorisation runs longer, but no landfill activity may take place without a guarantee in force.
- The day-by-day match between the periods the guarantee covers and the days on which waste was actually landfilled: this is the one figure no single corporate system holds in full, because the dates sit in one place — the policy, treasury — and the disposals in another, in registers and consignment notes.
- The authorisation in force and its term, to measure the gap between the period authorised and the period covered.
- The Prime Ministerial decree declaring the plant of national strategic interest, and the extraordinary administration measures: together they carry the rule’s very applicability.
- Someone watching the conversion: if the law does not arrive within the term, the annual regime falls away retroactively, and the days covered by it alone have to be revisited.
The date is not written in the decree: it is our own calculation. Article 77, third paragraph, of the Constitution provides that «I decreti perdono efficacia sin dall’inizio, se non sono convertiti in legge entro sessanta giorni dalla loro pubblicazione» — *decrees lose effect from the outset if they are not converted into law within sixty days of their publication*. The decree was published in Gazzetta Ufficiale no. 199 of 28 August 2026 and is in force from 29 August; sixty days from publication falls on 27 October 2026. What makes the deadline operational rather than academic: art. 14 of Legislative Decree 36 of 13 January 2003, untouched by the decree, requires the post-closure guarantee to be held for at least thirty years. Thirty years of obligation served by one-year instruments, and compliance stops being a one-off act and becomes a property to be evidenced day by day.
-
Tracking pixels in email: consent and notice, in writing
- Rule
- Italian Data Protection Authority, measure no. 284 of 17 April 2026 — guidelines on the use of tracking pixels in email communications, published in Official Gazette no. 98 of 29 April 2026
- Who it concerns
- Anyone placing tracking pixels in email: controllers sending marketing and newsletters, email service providers, operators of bulk email platforms.
What you need to have
- A notice stating that the message carries a pixel, what it records and for what purpose: the general notice on your website does not cover email tracking.
- Consent collected before sending, under art. 122 of the Italian Privacy Code and arts. 4(11) and 7 GDPR: it may be encompassed within consent to receiving promotional communications, but only if the request is “framed neutrally and without pressure” and the notice names the pixel.
- Withdrawal made possible in granular form too (art. 7(3) GDPR): someone who wants the newsletter must be able to refuse the tracking without giving up the newsletter.
- The data protection by design and by default measures required by art. 25 GDPR, non-sequential identifiers and separated data layers included.
- A map of who processes this data on your behalf: the pixel belongs to the sending platform, but the roles have to be defined case by case under the accountability principle (art. 5(2) GDPR), weighing art. 26 on joint controllership too — read the contract before the deadline, not after.
The period does not run from the date of the measure. The guidelines set “un termine pari a sei mesi dal momento della loro pubblicazione nella Gazzetta Ufficiale della Repubblica italiana entro il quale i soggetti tenuti dovranno conformarvisi” — six months from publication in the Official Gazette. Publication was on 29 April 2026, so the date is 29 October 2026. The work needed is not technical but a matter of choice: decide which metrics you actually need and drop the rest, because every open recorded without consent is processing without a legal basis.
-
Product liability: documentation as a defence
- Rule
- Directive (EU) 2024/2853
- Who it concerns
- Anyone placing on the market, or integrating, software and AI systems in a product or service under their own brand.
What you need to have
- Technical documentation of the product, producible on a court order: whoever fails to produce it, or produces it incomplete, opens the door to the presumption of defectiveness.
- Decision logs and a trace of human control over critical actions: that is what allows you to show what the system decided and why.
- Contracts with model and platform suppliers stating who provides the evidence in any proceedings, and within what timeframe.
The Italian delegation sits in law 36 of 17 March 2026, Annex A, point 4; the detailed legislative decree has not been published yet, but the draft exists. The Council of Ministers approved it on a preliminary reading on 4 August 2026 and on 7 August it was transmitted to Parliament as Government Act no. 434, assigned to the II Justice Committee with the opinion due by 16 September 2026. Under art. 31(1) of law 234/2012 the deadline was 9 August 2026 — four months before the European one; because the parliamentary opinion falls due after that date, the three-month extension in art. 31(3) applied, and the delegation now expires on 9 November 2026. The European deadline does not move in any case.
-
Data Act: switching charges for cloud providers fall away
- Rule
- Regulation (EU) 2023/2854 (Data Act), art. 29(1) and (2), with the definition in art. 2(36)
- Who it concerns
- Providers of data processing services — cloud and edge — and their customers, businesses and public bodies alike.
What you need to have
- The price list rewritten: “From 12 January 2027, providers of data processing services shall not impose any switching charges on the customer for the switching process” (art. 29(1)). Until that day only reduced charges are allowed, and they may not exceed the costs directly linked to the switching process incurred by the provider (paragraphs 2 and 3).
- The pre-contractual information of art. 29(4): standard service fees, early-termination penalties and the reduced switching charges applicable during the transitional period, given to the prospective customer before signature and made available in a dedicated section of the website (paragraph 6).
- The warning under art. 29(5) where it applies: which services involve switching that is highly complex or costly, or impossible without significant interference with the data architecture.
- For the customer: a measure of what leaving costs today, service by service — data egress charges are expressly covered — and the invoice line that cannot exist after 12 January 2027.
The scope of the ban sits in the definition, not in the article: “switching charges” are charges other than standard service fees or early-termination penalties, imposed for the actions mandated by the Regulation when switching to another provider’s system or to on-premises infrastructure, “including data egress charges” (art. 2(36)). Ordinary service fees stay; the toll for leaving does not. One boundary has to be read before relying on it, though: art. 31(1) takes art. 29 out of play for data processing services “of which the majority of main features has been custom-built to accommodate the specific needs of an individual customer”, provided they are “not offered at broad commercial scale via the service catalogue of the provider”. Between now and January there is time to turn that ban into a written clause rather than a dispute.
-
Machinery Regulation: the manual decides the CE marking
- Rule
- Regulation (EU) 2023/1230, which repeals Machinery Directive 2006/42/EC on the same date
- Who it concerns
- Manufacturers of machinery and partly completed machinery, importers and distributors placing products on the Union market.
What you need to have
- Instructions for use compliant with Annex III, point 1.7.4: manufacturer identification, description, intended use and reasonably foreseeable misuse, assembly, commissioning, use, maintenance, residual risks.
- The language set by the member state of use, easily understood by end users; a free paper copy within one month if the buyer asks for it at the time of purchase; safety information always on paper for non-professional users.
- If the instructions are digital only: availability online for the whole expected lifetime of the machine and in any case for at least ten years from placing on the market, even if the manufacturer ceases trading in the meantime.
- The requirements on protection against corruption and on the safety of control systems (Annex III, points 1.1.9 and 1.2.1), with additional requirements for machinery with self-evolving behaviour or logic.
Without compliant instructions there is no valid declaration of conformity; without the declaration there is no CE marking. It is not a penalty that arrives after an inspection: it blocks you on the day you place the machine on the market.
-
Data centres: the annual sustainability report
- Rule
- Directive (EU) 2023/1791, art. 12, and Delegated Regulation (EU) 2024/1364, art. 3(1)
- Who it concerns
- Owners and operators of data centres in the Union with an installed information technology power demand of at least 500 kW: enterprise, colocation and co-hosting.
What you need to have
- The 2026 calendar-year figures, measured and not estimated: total energy consumption and the consumption of the IT equipment alone, water and potable water input, reused waste heat and its temperature, renewable energy split between guarantees of origin, power purchase agreements and on-site generation (Annex II, point 1).
- The register of measurement points and measuring devices, which Annex II requires you to keep for at least ten years: it is what shows where the reported numbers come from.
- The ICT capacity of servers and storage equipment at the end of the reporting year (Annex II, point 2). For colocation data centres the allowance in art. 3(3) only covered the first two reporting periods: it is gone by now.
- The public-facing part: art. 12 of the directive requires the Annex VII information to be made public, except what is covered by trade secrecy — and which part that is has to be decided and written down beforehand, not in front of an inspection.
The duty is annual, and reporting goes through the national system where the member state hosting the data centre has set one up, otherwise straight to the European database. The threshold is measured on installed IT power, not on floor area: a single equipment room can cross it. If you keep your systems at a provider you are not the obliged party, but those same figures are worth writing into the contract.
-
Pay transparency: the first report on the gap
- Rule
- Italian Legislative Decree 96 of 7 May 2026, art. 9(9) (deadlines and frequency) and art. 9(8) (the 100-employee threshold); arts. 10 and 11
- Who it concerns
- Companies with at least 250 employees, reporting annually, and companies between 150 and 249, with the same first deadline and then every three years. Between 100 and 149 the start is 7 June 2031.
What you need to have
- The categories of workers doing equal work or work of equal value, defined by the company with criteria set down in writing.
- The calculation of mean and median pay, quartile composition and variable component, for each category.
- Objective and gender-neutral criteria for grading and progression, written before a gap has to be justified: above 5% in a category, if the gap is not justified on those criteria and is not corrected within six months of the pay report, a joint assessment with workers’ representatives is triggered (art. 10).
- The processing register and access restricted to pay-equality purposes only (art. 11).
One duty has been active since 7 June 2026, with no size threshold: art. 7 gives every worker the right to ask in writing for average pay levels by gender, with an answer due within two months, and bans clauses preventing workers from disclosing their own pay.
-
NIS: the categorised list of activities and services
- Rule
- Italian Legislative Decree 138 of 4 September 2024, art. 30(1), with art. 42(2) and ACN determination no. 155238/2026
- Who it concerns
- Essential and important entities on the Italian NIS register, public and private.
What you need to have
- The list of every activity carried out and every service provided, internally and externally, sorted into the ten macro-areas of the ACN model, each with its name, description and relevance category: high, medium, low or minimal impact.
- The written assessment behind every departure from the default. The relevance category pre-assigned to a macro-area can be changed, but only on your own assessment of the impact a compromise would have, and that assessment has to be kept: it is the document you will be asked for, not the category itself.
- Alignment with classifications already done: an entity that has classified its data and services under art. 3 of ACN’s cloud regulation uses that model instead of this one, and the two classifications have to stay consistent over time. Activities and services falling under the national cybersecurity perimeter are assigned the “high impact” category automatically and are not listed here.
- Submission through the Agency’s digital platform inside the window: it opens on 1 May and closes on 30 June, and it does not reopen.
The duty is annual — from 1 May to 30 June each year — and applies from calendar year 2026: the first window closed on 30 June 2026, this is the next one. It is not a paper exercise. The relevance category measures the impact that compromising an activity or a service would have on the organisation’s ability to deliver the activities and services that bring it inside the NIS perimeter, and it is expressly instrumental to the security measures of art. 24(1): that is where you decide how deeply each piece has to be protected. Anyone arriving in May without an up-to-date inventory fills in from memory a document that then constrains their own measures.
-
Data Act: unfair terms catch up with old contracts
- Rule
- Regulation (EU) 2023/2854 (Data Act), Chapter IV — art. 13 —, applicable under art. 50, sixth paragraph
- Who it concerns
- Enterprises that unilaterally imposed terms on data access and use on another enterprise, and the enterprises that had those terms imposed on them.
What you need to have
- The selection of contracts caught: those concluded on or before 12 September 2025, provided they are of indefinite duration or due to expire at least ten years from 11 January 2024, that is no earlier than 11 January 2034 (art. 50, sixth paragraph). Other earlier contracts stay out.
- A term-by-term re-reading against the test in art. 13: a unilaterally imposed term is unfair where its use “grossly deviates from good commercial practice in data access and use, contrary to good faith and fair dealing” (paragraph 3). Paragraph 4 lists the terms that are unfair in any event, paragraph 5 those presumed to be unfair.
- The consequence written beside each one: an unfair term “shall not be binding” on the enterprise it was imposed on (paragraph 1). You need to know in advance which pieces of the contract fall away and what stands.
- Renegotiation started in good time where the term is yours: after 12 September 2027 it is not defended, it is lost.
This is the deadline nobody diarises, because it asks for no filing: it asks you to know what your contracts, signed years ago, actually say. Chapter IV already applies to contracts concluded after 12 September 2025; on 12 September 2027 the same rules reach the existing stock, but only long relationships — of indefinite duration or expiring no earlier than 11 January 2034. Whoever imposed the terms has little more than a year to rewrite them; whoever accepted them, to learn which ones will fall.
-
DORA register of information: annual submission to the Bank of Italy by 15 March
- Rule
- Regulation (EU) 2022/2554, Article 28(3) and (9); Implementing Regulation (EU) 2024/2956; Bank of Italy communication of 13 February 2026
- Who it concerns
- Financial entities under Article 2 of Regulation (EU) 2022/2554 supervised by the Bank of Italy
What you need to have
- The complete list of contractual arrangements for ICT services provided by third parties, maintained and updated at entity level and on a sub-consolidated and consolidated basis, as Article 28(3) requires.
- The distinction, arrangement by arrangement, between ICT services supporting critical or important functions and all the others: a risk qualification, not a technical classification.
- Each provider’s position in the supply chain: Article 2 of the implementing regulation always assigns «1» to the direct provider and a higher number to every subcontractor further downstream.
- Only those subcontractors effectively underpinning services that support critical or important functions: the filter sits in Article 3(2)(b), and applying it presumes you already know which functions are critical.
- A valid and active LEI, or an EUID, for every subcontractor in the register: Article 3(6) puts that on the financial entity, which must obtain it through the direct provider.
The date is not in the European regulation, which sets only the annual cadence: the Bank of Italy fixed it in its communication of 13 February 2026 — submission by 15 March each year, with 31 December of the previous year as the reference date, through the INFOSTAT platform. The first collection took place in April 2025.
-
CBAM: the first annual declaration covers the whole of 2026, if the threshold was crossed
- Rule
- Regulation (EU) 2023/956, Article 6(1) and Article 2a, as replaced by Regulation (EU) 2025/2083; Annex VII, point 1; application dates in Article 36(2)
- Who it concerns
- Importers of cement, iron and steel, aluminium, fertilisers, electricity and hydrogen from third countries, and the indirect customs representatives acting for importers not established in the Union
What you need to have
- The cumulative net mass imported over the calendar year, aggregated across all CN codes and per importer: the Annex VII threshold is 50 tonnes and is measured neither per consignment nor per supplier.
- The specific embedded emissions of each good, which originate in the third-country producer’s installation: Annex IV, point 2, wants an installation-specific value, and without it only the default values remain, as a rule more costly.
- The customs declaration for every consignment, which often sits with the freight forwarder or the indirect customs representative rather than in the company.
- The forecast made in advance: Article 5(1b) asks for the authorisation application from whoever expects to cross the threshold, not from whoever already has.
- The awareness that crossing is retroactive: whoever exceeds the threshold answers for all embedded emissions in all goods imported in that calendar year, including the months already closed.
The date is written, not calculated: Article 6(1) provides “By 30 September of each year, and for the first time in 2027 for the year 2026”. By the same date Article 22(1) also requires the surrender of certificates.
-
Cyber Resilience Act: technical file and software bill of materials
- Rule
- Regulation (EU) 2024/2847, arts. 13, 28, 30, 31 and 32, Annexes I and VII
- Who it concerns
- Manufacturers of products with digital elements placed on the Union market.
What you need to have
- The technical documentation of art. 31 with the minimum content of Annex VII, per product family and updated version by version: general description, architecture, vulnerability handling, risk assessment, standards applied, test reports.
- The software bill of materials in a commonly used, machine-readable format, covering at least the top-level dependencies (Annex I, part II, point 1).
- A support period determined and justified: at least five years (art. 13(8)), with the information used to set it inside the file.
- Conformity assessment, EU declaration of conformity and CE marking, in that order. The file and the declaration stay available to the authorities for at least ten years from placing on the market, or for the support period if longer.
- The bill of materials classified as a confidential document before the first reasoned request: who sees it, through which channel you transmit it, where it is stored.
For the “important” products of Annex III and the “critical” ones of Annex IV, the file leaves the company and lands on the desk of a notified body.
-
Packaging Regulation (PPWR): the general obligations are applicable
- Rule
- Regulation (EU) 2025/40, arts. 15-20, 38-39, 44-45, 71
- Who it concerns
- Manufacturers, importers, distributors and fulfilment service providers placing or making packaging available on the EU market; producers subject to extended producer responsibility in each Member State where they first sell.
What you need to have
- The EU declaration of conformity (art. 39) and the technical documentation of Annex VII, drawn up before placing on the market (art. 15(2)) and kept for five years for single-use packaging, ten for reusable, from the date of placing on the market (art. 15(3)).
- The proof behind every sustainability requirement claimed: substances of concern and PFAS (art. 5), recyclability (art. 6), recycled content (art. 7), minimisation (art. 10) — each one “demonstrated in the technical documentation” of Annex VII, article by article.
- The producer’s registration in the national register of each Member State where it first places packaging or packaged products on the market (art. 44), a precondition for extended producer responsibility (art. 45); distributors must check it before making the packaging available (art. 19(2)).
The regulation repeals Directive 94/62/EC from 12 August 2026 (art. 70) and applies from that date (art. 71), except art. 67(5), which applies from 12 February 2029. Many detailed requirements carry their own, later dates: the harmonised label from 12 August 2028 (art. 12), recyclability thresholds from 1 January 2030 and 1 January 2038 (art. 6), minimum recycled content from 1 January 2030 and 1 January 2040 (art. 7), minimisation from 1 January 2030 (art. 10). Penalties are set by the Member States by 12 February 2027 (art. 68): the regulation itself fixes no amounts.
-
DataMatrix on medicines: the old seal can no longer substitute
- Rule
- Legislative Decree No. 10 of 6 February 2025, Art. 13(4), (6) and (9) (transposing Delegated Regulation (EU) 2016/161)
- Who it concerns
- Manufacturers, wholesalers, pharmacies and healthcare facilities handling medicinal products subject to the unique-identifier regime.
What you need to have
- Proof that the unique identifier (DataMatrix) is applied and activated on every pack from the production line onwards, no longer replaceable by the State Mint’s pharmaceutical seal.
- The log of authenticity checks and deactivations along the chain — manufacturer, wholesaler, pharmacy — required by Articles 7 and 10 of the decree.
- Reconciliation between systems that today do not talk to each other: the national repository, the central database, the National Health Card System and pharmacy systems.
The stabilisation period runs from 9 February 2025 to 8 February 2027 (Art. 13(4)): until then the identifier may be replaced by the old seal (paragraph 6). From 9 February 2027 the Article 10 penalties become fully applicable again (paragraph 9), from €10,000 to €140,000 per batch depending on the breach. An Osservatorio GIMBE Report No. 4/2026 found, as of 8 June 2026, four of the decree’s nine implementing measures still not adopted.
-
Battery passport: the electronic file becomes mandatory
- Rule
- Regulation (EU) 2023/1542, Art. 77
- Who it concerns
- Anyone placing on the market, or putting into service, LMT batteries, industrial batteries with a capacity greater than 2 kWh, and electric vehicle batteries.
What you need to have
- The battery model’s material composition — chemistry, hazardous substances, critical raw materials — as it stands in the bill of materials, ready for Annex XIII, point 1(b).
- The carbon footprint declaration per manufacturing plant (Art. 7) and, for operators above EUR 40 million in net turnover, the annual public report on the due-diligence policy for critical raw materials (Arts. 48, 51 and 52), verified by a notified body.
- State-of-health data and durability parameters for the individual battery, already held in the on-board management system since 18 August 2024 (Art. 14), and a new, linked passport for every battery that is repaired, reconditioned or given a second life (Art. 77(7)).
The regulation is directly applicable, with no transposing decree. The passport introduces no new data: it brings together, in one file accessible via QR code, data the regulation already requires elsewhere — data that today still sits scattered across PLM, the environmental office, procurement and the on-board management system. Penalties are set by the Member States by 18 August 2025 (Art. 93): not verified against a primary source for Italy, nor is the national market surveillance authority.
Two dates that ask for no new documents, but presuppose them.
On 2 December 2027 the obligations on Annex III high-risk AI systems apply; on 2 August 2028 those on systems embedded in already regulated products, the Machinery Regulation included. The full calendar, with the Italian dates attached to it, sits in the other guide.
AI Act: every deadline, in order
The first step
Operational from week one.
A real use case, on your data, in production. Then it grows, week after week.
It starts with a session with our engagement expert. Your data stays yours, always.