AsteronAsteron

    European healthtech compliance calendar 2026-2031

    Track the regulatory deadlines, transition dates and standards milestones affecting healthtech, medical software, AI and health-data companies across Europe. Each entry explains what changes, who is likely to be affected and what to prepare.

    Explore the calendar

    Last updated 16 July 2026 · Dates checked against primary EU and national sources

    European healthtech compliance deadlines

    Showing 21 of 21 entries

    Applicability depends on product classification, company role, market and customers. This calendar supports planning and is not legal advice.

    2 August 2026
    Legal deadlineEU

    AI Act transparency obligations

    Who it affects: Providers and deployers of certain AI systems that interact with people or generate synthetic content.

    What changes: Applicable AI systems that interact directly with people may require a clear AI disclosure. Machine-readable marking applies to relevant AI-generated or manipulated content; it is not a universal requirement for every chatbot or AI interface.

    View actions

    Who is not automatically affected: AI systems outside Article 50 scope, such as purely internal analytical models without user interaction or synthetic-content generation.

    What to do now
    • - Inventory user-facing AI interfaces and synthetic-content features across the product.
    • - Define the required disclosure wording and machine-readable marking approach where in scope.
    • - Assign ongoing ownership for reviewing new features against Article 50.

    Why it matters: Enterprise customers and hospital procurement increasingly check AI disclosure practices during security and privacy reviews.

    15 August 2026
    Legal deadlineNetherlands

    Dutch Cyberbeveiligingswet enters into force

    Who it affects: Dutch health organisations and healthtech suppliers that may fall within the law directly or face stronger customer requirements through the supply chain.

    What changes: Registration, cybersecurity risk-management, incident-reporting and management-accountability duties begin. Hospitals and other regulated customers will increasingly expect suppliers to support their own duty of care.

    View actions

    Who is not automatically affected: Companies fully outside the essential and important entity criteria and outside supply chains for regulated Dutch entities. Applicability must be confirmed - not assumed.

    What to do now
    • - Confirm direct applicability against the Dutch essential and important entity criteria.
    • - Map current controls to Dutch cybersecurity risk-management requirements.
    • - Prepare evidence packs for hospital and health-organisation security reviews.

    Why it matters: Even where the law does not apply directly, Dutch healthcare customers will push the requirements downstream through procurement and contracts.

    11 September 2026
    Legal deadlineEU

    Cyber Resilience Act reporting begins

    Who it affects: Manufacturers of products with digital elements covered by the CRA, including relevant non-medical health software and connected products.

    What changes: Reporting duties for actively exploited vulnerabilities and severe security incidents begin before the CRA full application in 2027.

    View actions

    Who is not automatically affected: Medical devices governed by MDR or IVDR are not automatically covered. Classify the product before making an applicability claim.

    What to do now
    • - Classify each product against the CRA and MDR or IVDR scope.
    • - Assign an accountable owner for CRA vulnerability and incident reporting.
    • - Update vulnerability-handling procedures and test the notification workflow end-to-end.
    12 September 2026
    Legal deadlineEU

    Data Act connected-product design duty

    Who it affects: Connected health devices and related services placed on the EU market after this date.

    What changes: Products must be designed so users can access data generated through their use, subject to the Regulation scope and conditions.

    View actions
    What to do now
    • - Map generated data, its access methods and the users entitled to it.
    • - Clarify contractual responsibilities between the device, cloud service and mobile application.
    • - Update product documentation, in-app disclosures and support processes.
    Official source: Data Act - EUR-LexLast verified 2026-07-16
    26 September 2026
    Transition deadlineEU

    IVDR Class C notified-body agreement deadline

    Who it affects: Eligible legacy Class C IVD manufacturers relying on the extended IVDR transition.

    What changes: Manufacturers that submitted the required application must have a written agreement with a notified body by this date to retain the transition pathway.

    View actions

    Who is not automatically affected: IVDs that never met the transition eligibility conditions and IVDs already under a valid IVDR certificate.

    What to do now
    • - Confirm eligibility for the extended transition and the status of the notified-body application.
    • - Track written-agreement progress with the notified body and escalate delays.
    • - Sequence remaining technical-documentation work against the notified-body plan.
    27 September 2026
    Legal deadlineFrance

    French HDS delayed provisions take effect

    Who it affects: Organisations hosting health data in France and healthtech vendors relying on HDS-certified hosting arrangements.

    What changes: The delayed hosting-location and third-country access or transfer-risk provisions introduced by the 2026 decree take effect.

    View actions
    What to do now
    • - Review hosting locations and subprocessor chains for French health data.
    • - Assess remote-access arrangements and third-country transfer risk.
    • - Update contractual evidence with the HDS provider and internal records.
    28 November 2026
    Transition deadlineEU

    EUDAMED legacy-device registration deadline

    Who it affects: Manufacturers of legacy medical devices that must be registered in EUDAMED.

    What changes: The transitional deadline for registering applicable legacy devices in the mandatory EUDAMED UDI and Device module ends.

    View actions
    What to do now
    • - Validate actor data and internal ownership for EUDAMED registrations.
    • - Complete device records and identifiers for all in-scope legacy devices.
    • - Assign long-term responsibility for maintaining EUDAMED entries.
    9 December 2026
    EU transposition deadlineEUNetherlandsGermanyFrance

    Product Liability Directive transposition deadline

    Who it affects: Healthtech software, AI and connected-product manufacturers selling into the EU.

    What changes: This is the deadline for EU Member States to transpose the Directive. Company-level obligations and enforcement will arise through the resulting national laws. Track implementation in the Netherlands, Germany and France.

    View actions
    What to do now
    • - Strengthen development traceability, decision logs and vulnerability-handling records.
    • - Preserve update records and post-market evidence in a defensible structure.
    • - Track national implementation in the Netherlands, Germany and France.
    20 February 2027
    Transition deadlineNetherlands

    NEN 7510:2024 transition deadline

    Who it affects: Dutch healthcare organisations and healthtech suppliers whose contracts depend on NEN 7510.

    What changes: Existing NEN 7510 certificates must complete transition to the 2024 version, aligned with ISO/IEC 27001:2022 and expanded supply-chain expectations.

    View actions
    What to do now
    • - Plan the transition audit slot with the certification body early.
    • - Update the ISMS to the 2024 control structure.
    • - Refresh supplier and cloud-service evidence.
    26 March 2027
    Implementation milestoneEU

    EHDS implementing-acts milestone

    Who it affects: Vendors indirectly affected through downstream implementing acts and national infrastructure planning.

    What changes: A Commission implementation deadline for the European Health Data Space. This is not a universal compliance deadline for vendors and not an EHDS certification requirement.

    View actions

    Who is not automatically affected: This date does not by itself impose direct vendor obligations. Real obligations come with the phased applications from 2029 and follow-up national implementation.

    What to do now
    • - Track implementing acts as they are published.
    • - Assess EHR system and health-data implications early.
    • - Do not react to any messaging that presents this as EHDS certification.
    28 May 2027
    Transition deadlineEU

    EUDAMED certificate-registration transition deadline

    Who it affects: Notified bodies and manufacturers holding in-scope MDR and IVDR certificates.

    What changes: Transitional deadline for registration of certificates in the mandatory EUDAMED modules.

    View actions
    What to do now
    • - Confirm certificate data with notified bodies.
    • - Align internal records with EUDAMED entries.
    • - Assign a long-term EUDAMED owner.
    2 December 2027
    Official EU timelineEU

    AI Act Annex III high-risk systems

    Who it affects: Providers and deployers of AI systems that fall within Annex III.

    What changes: Presented as the latest application date in the current official EU timeline for Annex III high-risk systems.

    This date reflects the current European Commission timeline following political agreement. Formal legislative publication should continue to be monitored.

    View actions
    What to do now
    • - Confirm whether the AI system is Annex III high-risk.
    • - Plan the technical documentation, risk management and post-market monitoring evidence.
    • - Align AI Act evidence with any medical-device conformity work.
    11 December 2027
    Legal deadlineEU

    Full Cyber Resilience Act application

    Who it affects: Manufacturers, importers and distributors of covered products with digital elements.

    What changes: Secure-by-design, vulnerability handling, product documentation and conformity obligations apply to covered products.

    View actions
    What to do now
    • - Complete secure-by-design evidence for each product family.
    • - Finalise product documentation and conformity route.
    • - Operate vulnerability handling continuously, not only at release.
    31 December 2027
    Transition deadlineEU

    MDR transition for eligible Class III and certain Class IIb implantable legacy devices

    Who it affects: Legacy-device manufacturers relying on the extended MDR transition.

    What changes: End of the extended MDR transition for eligible Class III and certain Class IIb implantable legacy devices, subject to the Regulation transition conditions.

    View actions

    Who is not automatically affected: Devices that do not meet transition eligibility, or devices already covered by valid MDR certificates.

    What to do now
    • - Verify transition eligibility per device family.
    • - Sequence notified-body work against remaining calendar.
    • - Communicate proactively with customers about certificate status.
    31 December 2027
    Transition deadlineEU

    IVDR transition for applicable Class D and IVDD-certified legacy IVDs

    Who it affects: Legacy IVD manufacturers relying on the extended IVDR transition.

    What changes: End of the extended IVDR transition for applicable Class D and IVDD-certified legacy IVDs, subject to the Regulation transition conditions.

    View actions
    What to do now
    • - Confirm transition eligibility per product.
    • - Progress technical documentation and notified-body milestones.
    • - Plan supply continuity for affected customers.
    2 August 2028
    Official EU timelineEU

    AI systems embedded in regulated products

    Who it affects: Manufacturers of regulated products, including medical devices and IVDs, that embed AI systems.

    What changes: Presented as the latest date in the current official AI Act timeline for AI embedded in regulated products.

    This date reflects the current European Commission timeline following political agreement. Formal legislative publication should continue to be monitored.

    View actions
    What to do now
    • - Align AI Act conformity work with MDR or IVDR notified-body activity.
    • - Consolidate technical documentation across regimes.
    • - Prepare unified post-market monitoring for AI-embedded devices.
    31 December 2028
    Transition deadlineEU

    MDR transition for remaining eligible legacy-device classes

    Who it affects: Legacy-device manufacturers still relying on the extended MDR transition.

    What changes: End of the extended MDR transition for remaining eligible legacy-device classes, subject to the Regulation transition conditions.

    View actions
    What to do now
    • - Confirm remaining transition eligibility per device family.
    • - Complete technical documentation and clinical evaluation updates.
    • - Coordinate notified-body slots early.
    31 December 2028
    Transition deadlineEU

    IVDR transition for eligible Class C legacy IVDs

    Who it affects: Legacy Class C IVD manufacturers relying on the extended IVDR transition.

    What changes: End of the extended IVDR transition for eligible Class C legacy IVDs, subject to the Regulation transition conditions.

    View actions
    What to do now
    • - Confirm eligibility and notified-body agreement status.
    • - Progress technical documentation.
    • - Plan supply continuity.
    26 March 2029
    Legal deadlineEU

    First major EHDS application phase

    Who it affects: EHR-system suppliers and organisations involved in the exchange of patient summaries and electronic prescriptions, together with data holders and users affected by the first phase of the secondary-use rules.

    What changes: Key EHDS provisions begin applying. The first priority categories for primary use cover patient summaries and ePrescriptions/eDispensations, while secondary-use rules begin applying to most health-data categories.

    View actions
    What to do now
    • - Determine which EHDS obligations apply to the product.
    • - Plan interoperability and secondary-use evidence.
    • - Prepare governance and role clarity across the data value chain.
    31 December 2029
    Transition deadlineEU

    IVDR transition for eligible Class B and Class A sterile legacy IVDs

    Who it affects: Legacy Class B and Class A sterile IVD manufacturers relying on the transition.

    What changes: End of the extended IVDR transition for eligible Class B and Class A sterile legacy IVDs, subject to the Regulation transition conditions.

    View actions
    What to do now
    • - Confirm eligibility per product.
    • - Complete notified-body milestones.
    • - Plan for supply continuity.
    26 March 2031
    Legal deadlineEU

    Second EHDS application phase

    Who it affects: Systems and organisations exchanging medical images, laboratory results and hospital discharge reports, together with parties handling the remaining secondary-use data categories.

    What changes: The second group of priority health-data categories becomes operational for primary use. Secondary-use rules extend to the remaining categories, including genomic data.

    View actions
    What to do now
    • - Extend interoperability and secondary-use work.
    • - Update governance for additional data categories.
    • - Refresh evidence and DPIA artefacts.

    Dates to monitor - not confirmed compliance deadlines

    Regulatory activity worth tracking. These entries do not carry countdowns and should not be planned as if they were fixed deadlines.

    ISO 9001 revision publication

    Under development

    Revision in progress; publication timing still indicative.

    BSI C5 revision and transition arrangements

    Under development

    German BSI is preparing the next C5 revision; monitor transition guidance.

    AI Act harmonised standards

    Under development

    CEN-CENELEC JTC 21 harmonised standards continue to develop.

    EN IEC 81001-5-1 harmonisation

    Expected

    Harmonisation status monitored for MDR and IVDR presumption of conformity.

    ISO/IEC 27701 transition arrangements

    Under development

    Transition arrangements linked to the 2019 to next-version move.

    EUDI Wallet implementation

    Awaiting national implementation

    National wallet rollouts progress on distinct timelines.

    Dutch Wegiz implementation dates

    Awaiting national implementation

    Sector-specific implementation dates continue to be issued.

    MDR reform

    Under development

    Reform initiatives are being discussed at EU level; no confirmed applicable dates.

    GDPR Digital Omnibus

    Under development

    Legislative process ongoing; scope and dates not confirmed.

    National Product Liability Directive laws

    Awaiting national implementation

    Watch NL, DE and FR transposition trajectories.

    How to use this calendar

    1. Step 1

      Filter by product and market

      Start with the countries where the company sells and the way its product is classified.

    2. Step 2

      Separate applicability from customer pressure

      A law may not regulate the vendor directly while still changing hospital procurement and supplier-security requirements.

    3. Step 3

      Plan backwards from evidence

      Identify the policies, technical files, contracts, testing and management decisions that must exist before the formal date.

    Frequently asked questions

    What is a healthtech compliance calendar?

    A structured view of the EU and national regulatory deadlines, transition dates and standards milestones that affect healthtech, medical software, AI and health-data companies, alongside guidance on what to prepare and who is affected.

    Which EU compliance deadlines apply to my company?

    It depends on product classification, role in the value chain, markets served and customer type. This calendar is designed to help identify candidate dates, not to declare applicability by itself.

    Does NIS2 apply to every healthtech company?

    No. NIS2 applies to essential and important entities defined by the Directive and national transpositions. Many healthtech vendors are affected indirectly through customer procurement rather than as regulated entities themselves.

    Does the Cyber Resilience Act apply to medical-device software?

    Medical devices governed by MDR or IVDR are not automatically in scope of the CRA. Classification must be done per product before making an applicability claim.

    Is EHDS certification required in 2027?

    There is no universal EHDS certification requirement in 2027. The 2027 date is a Commission implementation milestone; vendor obligations arrive with the phased applications from 2029.

    What is the difference between a legal deadline and a transition deadline?

    A legal deadline is when a new obligation directly applies. A transition deadline is when a prior regime, certificate or standard version stops being valid under specific conditions.

    Why can customer requirements arrive before a law applies directly?

    Regulated customers such as hospitals must comply with their own obligations and typically push those requirements to suppliers via procurement, security reviews and contract clauses well before enforcement dates.

    Which countries does this calendar cover?

    The calendar prioritises the EU, the Netherlands, Germany and France. Other markets can be added on request when mapping a specific product and customer footprint.

    How often is the calendar reviewed?

    It is reviewed regularly against primary sources. Each entry carries a last-verified date, and the page footer shows the overall last-updated date.

    Is this calendar legal advice?

    No. The calendar supports planning and prioritisation. Applicability, interpretation and defensibility of positions require qualified legal input.

    Not sure which dates apply to your product?

    We can map your product, markets and customer obligations against the relevant EU and national requirements, then turn the applicable dates into a practical compliance plan.

    Explore Compliance Operations