Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
European Resilience Compliance Calendar 2024 to 2026 | Resilience Guard
Home  ›  Insights  ›  Compliance calendar
Evergreen briefing

The European resilience compliance calendar, 2024 to 2026

Every date that matters across NIS2, DORA, CER, Part-IS and the Swiss ISG, verified against the legal texts, with the next deadline twelve days out.

Practitioner led since 2014 Led by John Zeppos, Founder and Group Managing Director DRI Accredited training provider Three BCI Global Awards 16+ EU Horizon research projects Trusted to train 3 of the Big Four

Between January 2024 and July 2026, European resilience regulation moved from ambition to enforcement: the Swiss ISG, NIS2, the CER Directive, DORA and aviation's Part-IS all took effect or hit their key deadlines inside this window. This calendar lists each date, what it changed, and what remains ahead.

European resilience compliance timeline 2024 to 2026 Swiss ISGin force1 Jan 2024NIS2 transpositiondeadline17 Oct 2024CER Directiveapplies18 Oct 2024DORAapplies17 Jan 2025ISG 24hour reporting1 Apr 2025ISG sanctionsin force1 Oct 2025Part-IS firstwave16 Oct 2025CER nationalstrategies17 Jan 2026Part-IS secondwave22 Feb 2026CER identificationdeadline17 Jul 2026
The 2024 to 2026 window at a glance. Highlighted: the CER identification deadline of 17 July 2026.
The dates, in order
1 Jan 2024

Swiss ISG in force

The Information Security Act (SR 128) takes effect with its four ordinances.

17 Oct 2024

NIS2 transposition deadline

EU member states' deadline to transpose NIS2 into national law; obligations flow as national laws land.

18 Oct 2024

CER Directive applies

Directive (EU) 2022/2557 on the resilience of critical entities applies across the EU.

17 Jan 2025

DORA applies

The Digital Operational Resilience Act applies to financial entities and their critical ICT providers.

1 Apr 2025

ISG 24 hour reporting

Swiss critical infrastructure operators must report significant cyber attacks to BACS within 24 hours, 14 days to complete.

1 Oct 2025

ISG sanctions in force

Fines up to CHF 100,000 for non reporting after a BACS order (Art. 74g and 74h ISG).

16 Oct 2025

Part-IS first wave

Delegated Regulation (EU) 2022/1645 applies: information security management for the first group of aviation organisations.

17 Jan 2026

CER national strategies

Member states' deadline to adopt national strategies on the resilience of critical entities.

22 Feb 2026

Part-IS second wave

Implementing Regulation (EU) 2023/203 applies, extending Part-IS duties across aviation authorities and organisations.

17 Jul 2026
Next deadline

CER identification deadline

Member states must identify their critical entities; designated operators inherit the full duty set. Twelve days from publication of this calendar.

Regime by regime detail: KRITIS and the CER Directive, the Swiss ISG in English (also auf Deutsch), and Part-IS for aviation.

Frequently asked questions
Which of these regimes applies to us?

It depends on sector, footprint and customers: Swiss critical infrastructure operators sit under the ISG; EU essential and important entities under NIS2 and, where designated, CER; financial entities and their ICT providers under DORA; aviation under Part-IS. Most internationally active organisations sit under more than one, and the efficient response is a single management system serving all of them. We map your exposure precisely in a first conversation.

The deadlines have mostly passed. Are we too late?

No, but the posture has changed: regulators now assume the duty is known, so gaps read as non compliance rather than transition. The sequence that works is a rapid gap assessment against the regimes that bind you, remediation of reporting readiness first because it carries the shortest clocks, then the management system evidence behind it.

What single capability serves every regime on this calendar?

Evidenced response: tested plans, a drilled reporting pathway, exercised leadership and closed corrective actions. Every regime here converges on demonstration over documentation, which is why exercising has become the common denominator of compliance.

Start the conversation

Know exactly which dates bind you.

A rapid, confidential mapping of your regimes, gaps and sequence, from a practitioner team that implements all of them. We respond within 24 hours.

Book a consultation
All consultations are treated with strict confidentiality.