Radar

    Regulatory radar

    What changed in the instruments that land in scope, who it affects, and what it asks of a program.

    Weekly scan · published as it happens

    01Entries

    Each entry is one dated change, checked against the publisher's own text rather than a summary of it, with the primary source linked.

    Subscribe by RSS

    Framework
    Track

    10 of 10

    2026

    Regulation (EU) 2024/1689

    EU AI Act: high-risk dates deferred, two prohibitions added

    The Digital Omnibus on AI moves the high-risk obligations to December 2027 and August 2028, and adds two prohibited practices from December 2026.

    Affected
    Providers and deployers of AI systems on the EU market, and providers of general-purpose AI models.
    Action
    Re-plan the high-risk conformity work against the split timetable, and screen the model estate against the two new prohibitions before 2 December 2026.

    Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of 24 July 2026. It entered into force on the third day following that publication .

    The amendment splits the high-risk timetable in two. Obligations for systems classified as high-risk under Article 6(2) now apply from 2 December 2027. Those classified under Article 6(1) follow on 2 August 2028 .

    The general application date of 2 August 2026 stands, and the general-purpose AI model chapter has applied since 2 August 2025. The prohibitions in Article 5 have applied since 2 February 2025. Other parts did move. Articles 102 to 110 apply from 27 July 2026. A generative system placed on the market before 2 August 2026 has until 2 December 2026 to meet the Article 50(2) marking duty .

    Two practices were added to that prohibition list: AI systems that generate or manipulate intimate imagery of an identifiable person without that person's explicit consent, and systems that generate child sexual abuse material. Each is caught where the generation is the intended purpose, or a reasonably foreseeable outcome the system has no adequate safeguard against. Both apply from 2 December 2026 .

    A deferral is not a repeal. Classification, technical documentation and supplier evidence still have to exist by the new dates. The gap between the Article 6(2) and Article 6(1) tracks also means one product estate can now carry two different deadlines.

    References

    Primary source

    Directive (EU) 2022/2557

    CER Directive: Swedish bill proposes entry into force on 1 January 2027

    Sweden's bill implementing the critical entities resilience directive was laid before the Riksdag on 14 July 2026, proposing effect from 1 January 2027.

    Affected
    Operators of essential services in the sectors the directive covers, where those operations sit in Sweden.
    Action
    Assume identification as a critical entity is coming, and start the all-hazards risk assessment the directive requires rather than waiting for the designation letter.

    Directive (EU) 2022/2557 required Member States to adopt and publish implementing measures by 17 October 2024 and to apply them from 18 October 2024 . Sweden did not meet that date.

    The Swedish Government laid its implementing bill, prop. 2025/26:303, before the Riksdag on 14 July 2026. It proposes a new act on the resilience of critical operators, with the act and the related amendments entering into force on 1 January 2027 . Until that date the directive has no Swedish implementing act behind it.

    That leaves a two-track position worth naming in a risk register. The cybersecurity half of the same December 2022 package, Directive (EU) 2022/2555, already has Swedish law behind it: the Cybersecurity Act took effect on 15 January 2026. The physical-resilience half will not, for another quarter or more.

    The practical read is that the underlying obligations are stable even where the national instrument is not. Identification as a critical entity, an all-hazards risk assessment, resilience measures and incident notification are directive-level duties, and the drafting window is the cheapest time to build them.

    References

    Primary source

    Regulation (EU) 2024/2847

    Cyber Resilience Act: manufacturer reporting starts on 11 September 2026

    Article 14 applies from 11 September 2026, ahead of full application on 11 December 2027, and it reaches products already placed on the market.

    Affected
    Manufacturers of products with digital elements placed on the EU market, including products placed there before 11 December 2027.
    Action
    Stand up the 24-hour and 72-hour notification path, with its two final-report clocks, to the coordinating CSIRT and ENISA before 11 September 2026, and rehearse it once.

    The Cyber Resilience Act applies in stages. Chapter IV, Articles 35 to 51, has applied since 11 June 2026, which is what allows conformity assessment bodies to be notified. Article 14 applies from 11 September 2026, and the rest of the Regulation from 11 December 2027 .

    Article 14 is the reporting article. A manufacturer must notify an actively exploited vulnerability, and a severe incident affecting the security of the product. Both go to the CSIRT designated as coordinator and to ENISA at the same time, through the single reporting platform. The clock is an early warning within 24 hours and a fuller notification within 72 hours. The final report differs by track. For a vulnerability it is due no later than 14 days after a corrective or mitigating measure is available. For a severe incident it is due within one month of the 72-hour notification .

    The transitional rule is the part that surprises people. Products placed on the market before 11 December 2027 escape the substantive requirements unless they are substantially modified. Article 69(3) then applies the Article 14 duties to all of them . A shipped fleet is in scope for reporting from September 2026 even though it is not yet in scope for the essential requirements.

    References

    Primary source

    Directive (EU) 2022/2555

    NIS2: Sweden's Cybersecurity Act took effect on 15 January 2026

    Cybersäkerhetslag (2025:1506) entered into force on 15 January 2026, fifteen months after the directive's transposition date of 17 October 2024.

    Affected
    Essential and important entities under the directive's sector lists, where those operations sit in Sweden.
    Action
    Re-test the entity classification against the Swedish act, then close the gap against the Article 21 measures and the Article 23 reporting deadlines.

    Sweden now has a NIS2 act. Cybersäkerhetslag (2025:1506) was issued on 11 December 2025 and entered into force on 15 January 2026 . It replaces the law that implemented the 2016 directive.

    The directive itself required implementing measures to be adopted and published by 17 October 2024 and applied from 18 October 2024 . Sweden was one of many Member States that missed that date, so an entity operating in several markets has been holding a patchwork of national timetables against a single directive-level duty.

    Two reference points make the Swedish act easier to work with. Article 21 sets the risk-management measures and Article 23 the reporting obligations . For the digital sectors, Commission Implementing Regulation (EU) 2024/2690 already specifies what those measures mean in practice and when an incident counts as significant .

    One caution against treating the text as settled: the Commission proposed targeted amendments to the directive on 20 January 2026, COM(2026) 13, covering jurisdictional rules and reporting simplification. That proposal is not law.

    References

    Primary source

    GB 44495-2024 and GB 44496-2024

    GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026

    China's mandatory vehicle cybersecurity and software-update standards moved from issued to in force on 1 January 2026, seventeen months after publication.

    Affected
    Vehicle manufacturers and their suppliers seeking type approval for vehicles sold in China.
    Action
    Map the existing R155 and R156 evidence set onto the GB clause structure, and read Amendment No. 1 to each standard before relying on a clause number.

    Both standards were issued on 23 August 2024 and became effective on 1 January 2026. The national catalogue now lists each as 现行, meaning current . GB 44495-2024 covers technical requirements for vehicle cybersecurity; GB 44496-2024 covers general technical requirements for software update of vehicles. Both were issued by SAMR together with the Standardization Administration, with the Ministry of Industry and Information Technology as the competent department.

    For a manufacturer already holding a UN R155 approval, the shape is familiar and the paperwork is not. The two GB standards are national mandatory standards, so conformity runs through the Chinese approval route rather than through a 1958 Agreement type approval. An existing cybersecurity management system is useful input, not a substitute.

    One detail the catalogue flags and most summaries do not: each standard carries an Amendment No. 1, recorded in the remarks field of its catalogue entry . Any clause-level mapping built before that amendment was read is provisional.

    References

    Primary source

    2025

    ISO/IEC 27001:2022

    ISO/IEC 27001:2013 certificates stopped being valid after 31 October 2025

    The accredited transition period set by IAF MD 26 ended on 31 October 2025; certificates naming the 2013 edition expire or are withdrawn.

    Affected
    Certified organisations, and anyone accepting an ISO/IEC 27001 certificate as supplier assurance.
    Action
    Re-read the certificate register: any certificate still naming the 2013 edition is outside the transition and no longer counts as evidence.

    The accredited transition to ISO/IEC 27001:2022 is closed. IAF MD 26:2023 Issue 2 set a 36-month transition period. It runs from the last day of the publication month of ISO/IEC 27001:2022, which the document states as 31 October 2025. Certification bodies had to complete their clients' transitions by that date .

    The consequence is stated plainly in the same document: all certifications based on ISO/IEC 27001:2013 expire or are withdrawn at the end of the transition period . There is no grace window in the mandatory document, and no route that keeps a 2013 certificate alive.

    Two practical consequences follow. First, a certificate presented in a supplier file that names the 2013 edition is not evidence of a current accredited certification, whatever date it carries. Second, an organisation that missed the window is starting a certification cycle rather than continuing one, which changes the audit stages and the timeline.

    Worth pairing with the base standard's own amendment. ISO/IEC 27001:2022/Amd 1:2024 adds climate-action wording, so a statement of applicability written before 2024 is also due a read.

    References

    Primary source

    ISO/IEC 42006:2025

    ISO/IEC 42006:2025 completes the certification route for AI management systems

    The requirements standard for bodies auditing AI management systems was published on 7 July 2025, alongside the impact-assessment standard of May 2025.

    Affected
    Organisations building an AI management system, and the certification bodies auditing one.
    Action
    Decide whether accredited certification is actually the goal; if it is, ask the certification body how it meets ISO/IEC 42006:2025.

    ISO/IEC 42001:2023, the AI management system standard, was published on 18 December 2023 as a first edition by ISO/IEC JTC 1/SC 42 . Until mid-2025 it had no companion standard telling certification bodies how to audit against it, which left "certified to 42001" meaning different things in different places.

    Two publications closed that gap. ISO/IEC 42005:2025, AI system impact assessment, was published on 28 May 2025. ISO/IEC 42006:2025 followed on 7 July 2025, setting requirements for bodies providing audit and certification of AI management systems . Both are first editions from the same subcommittee.

    The consequence for a programme already under way is small but real. An impact assessment built against a local template can now be pointed at a published one, and a certification body's competence claim can be tested against a published requirement rather than a brochure. Neither standard changes what ISO/IEC 42001:2023 asks for; they change what a certificate is worth and what the assessment file needs to contain.

    References

    • ISO/IEC 42001:2023 — Information technology - Artificial intelligence - Management system. ISO/IEC JTC 1/SC 42. Edition 1.0, publication date 2023-12-18. https://webstore.iec.ch/en/publication/90574 · accessed 2026-09-03
    • ISO/IEC 42005:2025 — Information technology - Artificial intelligence (AI) - AI system impact assessment. ISO/IEC JTC 1/SC 42. Edition 1.0, publication date 2025-05-28. https://webstore.iec.ch/en/publication/107659 · accessed 2026-09-03
    • ISO/IEC 42006:2025 — Information technology - Artificial intelligence - Requirements for bodies providing audit and certification of artificial intelligence management systems. ISO/IEC JTC 1/SC 42. Edition 1.0, publication date 2025-07-07. https://webstore.iec.ch/en/publication/108460 · accessed 2026-09-03

    Primary source

    Regulation (EU) 2022/2554

    DORA: the subcontracting technical standard was published on 2 July 2025

    Delegated Regulation (EU) 2025/532 sets what a financial entity must determine before ICT services supporting critical or important functions are subcontracted.

    Affected
    Financial entities in scope of DORA, and the ICT third-party providers supporting critical or important functions.
    Action
    Re-open the contracts covering critical or important functions and test the subcontracting clauses against the delegated regulation before the next supervisory cycle.

    DORA itself has applied since 17 January 2025 . The technical standards under it arrived in tranches, and the subcontracting one arrived late.

    Commission Delegated Regulation (EU) 2025/532 of 24 March 2025 was published in the Official Journal of 2 July 2025. It supplements Article 30(5) of DORA. It specifies the elements a financial entity has to determine and assess when ICT services supporting critical or important functions are subcontracted .

    Two earlier instruments frame it. Commission Delegated Regulation (EU) 2024/1774 sets the ICT risk management tools, methods, processes and policies, including the simplified framework. Commission Implementing Regulation (EU) 2024/2956 sets the standard templates for the register of information .

    The register is where the three meet. A register built for the 2024 templates lists the chain; the 2025 standard says what has to be assessed before a link is added to it. An entity that filed a register and then stopped has documentation but no assessment, which is the gap a supervisor reads first.

    References

    Primary source

    UN Regulation No 155

    UN Regulation No 155: Supplement 3 entered into force on 10 January 2025

    The consolidated R155 text republished in the Official Journal as 2025/5 incorporates all valid text up to Supplement 3 to the original version.

    Affected
    Vehicle manufacturers holding or seeking a type approval under the 1958 Agreement, and their approval authorities.
    Action
    Re-read the approval file against the consolidated text published as 2025/5; an argument built on the 2021 publication is out of date.

    The cybersecurity regulation for vehicles has been republished. The consolidated text appears in the Official Journal L series of 10 January 2025 under the number 2025/5. Its header states that it incorporates all valid text up to Supplement 3 to the original version. The date of entry into force given there is 10 January 2025 .

    The same header names the authentic texts behind the consolidation. Alongside the original ECE/TRANS/WP.29/2020/79 and its two 2020 amendments, it lists ECE/TRANS/WP.29/2022/54, ECE/TRANS/WP.29/2023/70 and ECE/TRANS/WP.29/2024/55 . Three amendment documents therefore post-date the version most internal handbooks quote.

    One caveat the Official Journal states itself: only the original UN/ECE texts have legal effect under international public law. The status and the date of entry into force are to be checked against the UNECE status document TRANS/WP.29/343 . The Official Journal is an official publication of the same text, not a substitute for that status check.

    References

    Primary source

    2024

    NIST CSWP 29

    NIST CSF 2.0 restructured the Core around six Functions

    The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29, with Govern at the centre of a six-Function Core.

    Affected
    Organisations using the framework as the spine of a control set, a maturity conversation or a customer questionnaire.
    Action
    Re-cut any crosswalk or scoring sheet that still names five Functions, using the Core transition overview NIST publishes alongside the framework.

    The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29 . The framework is the reference most often reached for when a control set needs a shared vocabulary, so a change to its Core has a long tail through mappings, questionnaires and scoring sheets.

    The Core is now a hierarchy of six Functions, each holding Categories and Subcategories. The document depicts them as a wheel whose inner layer is the Govern Function alone, with the other five surrounding it. Governance is therefore read as its own Function rather than as material inside another one.

    NIST publishes a separate overview of the Core changes between version 1.1 and version 2.0 alongside the framework itself . That is the honest starting point for re-cutting an existing mapping, and it is cheaper than re-deriving the differences by hand.

    The work is small and worth doing once. Any artefact that still describes five Functions is describing an earlier structure, and that is an easy question to be asked in a supplier review.

    References

    Primary source