Regulations
Regulations with upcoming deadlines or changes, one page each: who it applies to, what it requires, and what's next.
Markets in Crypto-Assets (MiCA)
MiCA is Regulation (EU) 2023/1114. Full application began on 30 December 2024 and the EU-wide transitional period expired on 1 July 2026, so there is now no grandfathering anywhere in the EEA. Around 325 crypto-asset service providers are authorised. Not one asset-referenced token issuer appears on ESMA's register.
NextMiCA review consultation closesChecked
Cyber Resilience Act (CRA)
The Cyber Resilience Act is Regulation (EU) 2024/2847. Its reporting obligations under Article 14 apply from 11 September 2026, to every product with digital elements on the Union market, including products placed there before the Regulation's main obligations start on 11 December 2027. Actively exploited vulnerabilities must be reported within 24 hours.
NextArticle 14 reporting obligations apply: actively exploited vulnerabilities and severe incidentsChecked
Instant Payments Regulation (IPR)
The Instant Payments Regulation is Regulation (EU) 2024/886, which amends the SEPA Regulation. Euro-area banks have had to send instant euro credit transfers and offer Verification of Payee since 9 October 2025. Payment institutions and e-money institutions have until 9 April 2027. Daily sanctions screening replaced in-flight screening on 9 January 2025.
NextVOP Scheme Rulebook v1.1 effective; API Security Framework v2.1 mandatoryChecked
EU Artificial Intelligence Act (EU AI Act)
The EU AI Act is Regulation (EU) 2024/1689. On 2 August 2026 its transparency rules and enforcement machinery took effect, but the high-risk regime for credit scoring and life and health insurance pricing did not: Regulation (EU) 2026/1744 moved it to 2 December 2027. Prohibitions have applied since February 2025.
NextNew Art. 5 prohibitions; Art. 50(2) marking deadline for pre-existing generative systemsChecked
electronic Identification, Authentication and Trust Services (eIDAS2)
eIDAS2 is Regulation (EU) 2024/1183, which amends Regulation (EU) No 910/2014. It contains no calendar deadline: wallet availability runs 24 months from the entry into force of five implementing acts, and private relying-party acceptance 36 months. Those acts entered into force on 24 December 2024, giving end-2026 and end-2027.
NextMember States to provide at least one wallet (Art. 5a(1))Checked
Digital Operational Resilience Act (DORA)
DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.
NextNext register of information cycle, reference date expected 31 December 2026Checked
Wet ter voorkoming van witwassen en financieren van terrorisme (Wwft)
The Wwft is the Dutch anti-money laundering act, in force since 2008. It requires obliged entities to report unusual transactions, not suspicious ones, to FIU-Nederland against fixed indicators. It is repealed in full on 10 July 2027, when the directly applicable AMLR takes over the conduct rules and a Dutch implementing act keeps only supervision, the FIU, sanctions and registers.
NextAMLR applies. Wwft formally repealed.Checked
Anti-Money Laundering Regulation (AMLR)
The AMLR is Regulation (EU) 2024/1624. It applies from 10 July 2027 and is directly applicable, so from that date customer due diligence, beneficial ownership, reporting and internal controls come from EU law rather than national statute. Cash payments for goods and services are capped at €10,000. Football clubs and agents follow on 10 July 2029.
NextAMLR applies (Art. 90) and the AMLD6 transposition deadline. References to Directive (EU) 2015/849 are construed as references to the AMLR and AMLD6, per the correlation table in Annex VI (Art. 89); the repeal itself sits in AMLD6Checked
Cyberbeveiligingswet (Dutch NIS2)
The Cyberbeveiligingswet is the Dutch implementation of NIS2, Directive (EU) 2022/2555. It entered into force on 15 August 2026 and covers more than 8,000 organisations. Registration, the duty of care and the 24-hour and 72-hour reporting duties applied from day one. Banks are largely displaced to DORA by Articles 22 and 31, but their IT suppliers are not.
NextArticle 40 NIS2 review of sectors, size criteria and entity types; every 36 months thereafterChecked