11 September 2026
Reporting obligations begin: actively exploited vulnerabilities and severe incidents must be reported to ENISA. That requires an up-to-date SBOM and continuous vulnerability monitoring.
11 December 2027
Full application: from then on, products newly placed on the market must meet all requirements, technical documentation, conformity assessment, CE marking, secure-by-design.
What this means for you
The runway is shorter than it looks. Start SBOM, monitoring and documentation in 2026 and 2027 becomes routine, and you can already attest conformity to your buyers today.