EU Rules Radar

Which EU rules apply to your product — and what is actually true?

Twelve sets of rules that decide whether connected products, electronics and industrial parts may be sold in the EU. Explained in plain language, fact-checked and reviewed every week against official sources.

  • Last review:
  • reviewed weekly
  • primary sources: EUR-Lex, European Commission, ENISA, RIS
Self-check

Which rules apply to you?

Choose your role and tick what describes your product. The result is a first orientation — it runs only in your browser; nothing is sent or stored.

Your role
Your product …

Rules to look at

Tick at least one property to see the relevant rules.

Applies to every product placed on the market after 9 December 2026: the new product liability rules.

Have the documents for your product checked →
What changed

Latest developments

  1. PLD

    Review: we found no published Austrian implementing law; the deadline of 9 December 2026 is unchanged.

  2. NIS2 / NISG 2026

    NISG 2026 entered into force; registration window runs until 31 December 2026.

  3. WEEE / RoHS

    Retailer take-back of very small household devices containing batteries applies in Austria.

  4. Dual-use

    Commission adopted the 2026 Delegated Regulation updating Annex I (semiconductor manufacturing equipment, advanced computing ICs, inductive rotary encoders, ceramic matrix composites, additive manufacturing …); it enters into force upon publication in the Official Journal after the two-month scrutiny period.

  5. Data Act

    Access-by-design obligation (Art. 3(1)) applies to newly placed products.

  6. CRA

    Reporting obligations apply; ENISA’s CRA Single Reporting Platform went live the same day.

  7. Batteries

    Earliest application date of the labelling requirements (Art. 13); the actual date depends on the implementing act on label specifications.

  8. PPWR

    PPWR applies generally.

Timeline

Key dates 2025–2028

  1. AI ActProhibited practices and AI literacy
  2. PPWREntry into force
  3. REDCybersecurity requirements mandatory
  4. AI ActGeneral-purpose AI rules and governance
  5. BatteriesExtended producer responsibility: registration, take-back
  6. Data ActApplies — pre-contract information, data access rights, fair terms for new contracts
  7. NIS2 / NISG 2026NISG 2026 published (BGBl. I Nr. 94/2025)
  8. CRARules for conformity assessment bodies apply
  9. WEEE / RoHSEAG-VO-Novelle 2026 published (BGBl. II Nr. 218/2026)
  10. MRRegulation (EU) 2026/1744 in force — AI requirements for machinery to be set by delegated act
  11. AI ActGeneral application incl. transparency duties (marking of generated content for certain systems: 2 Dec 2026)
  12. PPWRGeneral application
  13. BatteriesLabelling requirements (Art. 13) — from this date or 18 months after the implementing act on label specifications, whichever is later
  14. CRAReporting of actively exploited vulnerabilities and severe incidents (also for products already on the market)
  15. Data ActAccess-by-design duty (Art. 3(1)) for products placed on the market after this date
  16. Dual-useCommission adopted the 2026 update of Annex I (enters into force on publication in the Official Journal)
  17. NIS2 / NISG 2026NISG 2026 in force in Austria
  18. WEEE / RoHSRetailers with ≥ 25 m² sales area take back, free of charge and without a new purchase, very small household devices containing batteries (no outer dimension over 25 cm) of the types they sell
  19. PLDTransposition deadline — applies to products placed on the market after this date
  20. NIS2 / NISG 2026Registration deadline for affected entities
  21. MRMachinery Regulation applies; Directive 2006/42/EC repealed
  22. BatteriesQR code, removability of portable batteries, battery passport
  23. BatteriesDue-diligence obligations (postponed by (EU) 2025/1561)
  24. Data ActUnfair-terms rules extend to certain older long-term contracts
  25. AI ActHigh-risk systems in Annex III areas (postponed by (EU) 2026/1744)
  26. CRAFull application — all essential requirements, CE marking
  27. REDRepealed by Delegated Regulation (EU) 2026/339 — CRA takes over
  28. MRDelegated acts adding AI-specific requirements to the Machinery Regulation must apply by this date
  29. AI ActHigh-risk AI in regulated products (Annex I)
  30. PPWRHarmonised labelling requirements — at the earliest (depends on implementing act)
Overview

All regulations on the radar

CRAApplies in stages

Cyber Resilience Act

Regulation (EU) 2024/2847

Cybersecurity becomes a condition for selling almost every product with digital elements in the EU — reporting duties already apply since 11 September 2026.

Next date: 11 Dec 2027 — Full application — all essential requirements, CE marking

Sources last checked: 2 Oct 2026

Details, fact check & sources →
REDApplies

Radio Equipment Directive — cybersecurity

Delegated Regulation (EU) 2022/30 · EN 18031

Since 1 August 2025 internet-connected radio equipment must protect networks and personal data and guard against fraud — until the CRA takes over on 11 December 2027.

Next date: 11 Dec 2027 — Repealed by Delegated Regulation (EU) 2026/339 — CRA takes over

Sources last checked: 2 Oct 2026

Details, fact check & sources →
GPSRApplies

General Product Safety Regulation

Regulation (EU) 2023/988

Since 13 December 2024 consumer products may only be placed on the EU market if an economic operator established in the EU is responsible for them — plus traceability, safety documentation and accident reporting.

Sources last checked: 2 Oct 2026

Details, fact check & sources →
Data ActApplies in stages

Data Act

Regulation (EU) 2023/2854

Users of connected products get a right to access and use the data their use generates — and products placed on the market after 12 September 2026 must be designed to make that data accessible.

Next date: 12 Sep 2027 — Unfair-terms rules extend to certain older long-term contracts

Sources last checked: 2 Oct 2026

Details, fact check & sources →
NIS2 / NISG 2026Applies

NIS2 — Austrian NISG 2026

Directive (EU) 2022/2555 · Austria: NISG 2026 (BGBl. I Nr. 94/2025)

Austria’s NIS2 law is in force since 1 October 2026: thousands of medium and large companies must register by 31 December 2026 — and pass security requirements on to their suppliers.

Next date: 31 Dec 2026 — Registration deadline for affected entities

Sources last checked: 2 Oct 2026

Details, fact check & sources →
PLDApplies soon

New Product Liability Directive

Directive (EU) 2024/2853

For products placed on the market after 9 December 2026, software counts as a product, missing security updates can make a product defective — and the EU importer is liable when the manufacturer sits outside the EU.

Next date: 9 Dec 2026 — Transposition deadline — applies to products placed on the market after this date

Sources last checked: 2 Oct 2026

Details, fact check & sources →
MRApplies soon

Machinery Regulation

Regulation (EU) 2023/1230

From 20 January 2027 the Machinery Regulation replaces the Machinery Directive — with cybersecurity for safety functions and digital instructions.

Next date: 20 Jan 2027 — Machinery Regulation applies; Directive 2006/42/EC repealed

Sources last checked: 2 Oct 2026

Details, fact check & sources →
AI ActApplies in stages

AI Act

Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744

The AI Act applies in stages; after the Digital Omnibus, high-risk rules apply from 2 December 2027 (Annex III) and 2 August 2028 (AI in regulated products).

Next date: 2 Dec 2027 — High-risk systems in Annex III areas (postponed by (EU) 2026/1744)

Sources last checked: 2 Oct 2026

Details, fact check & sources →
BatteriesApplies in stages

Batteries Regulation

Regulation (EU) 2023/1542

Producer registration since August 2025, labelling requirements from 18 August 2026 (or later, depending on an implementing act), QR code, removability and battery passport from 18 February 2027.

Next date: 18 Feb 2027 — QR code, removability of portable batteries, battery passport

Sources last checked: 2 Oct 2026

Details, fact check & sources →
WEEE / RoHSApplies

WEEE & RoHS (Austria: EAG-VO)

Directive 2012/19/EU · Austria: EAG-VO · Directive 2011/65/EU

Electrical and electronic equipment needs producer registration, take-back financing and restricted-substance compliance — Austria extended retailer take-back obligations from 1 October 2026.

Sources last checked: 2 Oct 2026

Details, fact check & sources →
PPWRApplies in stages

Packaging and Packaging Waste Regulation

Regulation (EU) 2025/40

Since 12 August 2026 an EU regulation sets the core rules for all packaging, including transport and industrial packaging of imported goods (extended producer responsibility schemes remain national).

Next date: 12 Aug 2028 — Harmonised labelling requirements — at the earliest (depends on implementing act)

Sources last checked: 2 Oct 2026

Details, fact check & sources →
Dual-useApplies

Dual-use export controls

Regulation (EU) 2021/821

Civil electronics can be controlled goods: the 2026 update of the EU control list adds e.g. inductive rotary encoders, semiconductor manufacturing equipment and advanced computing chips.

Sources last checked: 2 Oct 2026

Details, fact check & sources →
Fact check

Common claims — checked

What we hear most often from buyers, importers and integrators, compared with the legal texts.

Not correct“The CRA only starts in December 2027 — nothing to do before.”

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents — and this also applies to products placed on the market before December 2027.

Cyber Resilience Act — Sources →
Not correct“We only import — cybersecurity is the factory’s job.”

Importers have their own duties: they may only place compliant products on the market, must verify documentation and CE marking, keep the EU declaration of conformity for at least 10 years and act on known vulnerabilities. If you sell under your own name or trademark, you are considered the manufacturer.

Cyber Resilience Act — Sources →
Partly correct“Open-source components make our firmware exempt.”

Non-commercial open-source software itself is largely outside scope. But a manufacturer that integrates open-source components into a commercial product is responsible for them and must exercise due diligence.

Cyber Resilience Act — Sources →
Not correct“Every CRA product needs a notified body.”

Most products allow self-assessment. Only “important” products (classes I and II, e.g. routers, microcontrollers with security functions, firewalls) may need third-party assessment; “critical” products may require European cybersecurity certification once a delegated act requires it — until then the class II procedures apply. The categories are listed in Annexes III and IV of the CRA; their technical descriptions are set out in Implementing Regulation (EU) 2025/2392.

Cyber Resilience Act — Sources →
Not correct“The RED cyber rules end in 2027, so we can ignore them.”

They apply to every product placed on the market before 11 December 2027, and market surveillance can still act on those products afterwards.

Radio Equipment Directive — cybersecurity — Sources →
Not correct“Bluetooth-only devices are not internet-connected.”

If the device can communicate over the internet via another device — e.g. a phone app or a gateway — it can be in scope.

Radio Equipment Directive — cybersecurity — Sources →
Partly correct“A CE mark on a radio module covers the finished device.”

A compliant module helps, but the product placed on the market is assessed as a whole — including its software, interfaces and default settings.

Radio Equipment Directive — cybersecurity — Sources →
Partly correct“Industrial parts are never affected by the GPSR.”

Purely professional products are outside scope. But products likely to be used by consumers — e.g. smart meters, sensors, tools, chargers sold openly online — are covered.

General Product Safety Regulation — Sources →
Not correct“Buying through a marketplace makes the platform responsible.”

Marketplaces have their own duties, but they do not replace the manufacturer, importer or EU responsible person. If your company is established in the EU and places goods from a non-EU country on the EU market, you are the importer.

General Product Safety Regulation — Sources →
Not correct“The Data Act is about personal data — that’s GDPR territory.”

It explicitly covers non-personal machine and sensor data too. GDPR continues to apply in parallel where personal data is involved.

Data Act — Sources →
Not correct“Only consumer smart-home devices are covered.”

Industrial machines, meters, agricultural equipment and vehicles are typical connected products under the Data Act.

Data Act — Sources →
Not correct“The Digital Omnibus has already changed the Data Act.”

As of the last review the Data Act amendments are still a proposal in negotiation. The access-by-design duty applies unchanged to products placed on the market after 12 September 2026.

Data Act — Sources →
Partly correct“We have fewer than 50 employees, so NIS2 doesn’t concern us.”

You may not be directly regulated, but your NIS2 customers must secure their supply chain — they will pass requirements on to you contractually.

NIS2 — Austrian NISG 2026 — Sources →
Not correct“Manufacturing companies are not in scope — NIS2 is for critical infrastructure.”

Manufacturing of computers, electronic and optical products, electrical equipment, machinery and vehicles is a listed sector (important entities).

NIS2 — Austrian NISG 2026 — Sources →
Not correct“Software is not a product, so there is no strict liability.”

Under the new directive software — including AI systems and firmware — is explicitly a product.

New Product Liability Directive — Sources →
Not correct“We can exclude liability in our terms and conditions.”

Liability towards the injured person cannot be limited or excluded by contract.

New Product Liability Directive — Sources →
Not correct“The cybersecurity requirements of the Machinery Regulation have been postponed to 2027/2028.”

Industry associations requested a postponement, but it has not been adopted (status at last review). What was shifted to 2028 are the AI-specific requirements (via Regulation (EU) 2026/1744). Plan for 20 January 2027.

Machinery Regulation — Sources →
Partly correct“A machine with CE under the old directive can still be sold forever.”

Machines placed on the market before 20 January 2027 stay legal. Each unit placed on the market from that date must comply with the regulation.

Machinery Regulation — Sources →
Not correct“The AI Act has been postponed as a whole.”

Mainly the high-risk obligations were postponed (plus, for systems placed on the market before 2 August 2026, the marking of generated content until 2 December 2026). Prohibitions, AI-literacy measures, general-purpose AI rules and the other transparency duties already apply.

AI Act — Sources →
Not correct“A battery built into a device is the device maker’s problem, not the importer’s.”

Whoever first makes the battery available in a Member State — also inside an appliance — is the producer for extended producer responsibility. For imports that is usually the importer.

Batteries Regulation — Sources →
Partly correct“Our Chinese supplier is registered, so we don’t need to be.”

Registration is per country and per role. Only a registration (or an authorised representative) that covers your sales in Austria counts — check the EDM register.

WEEE & RoHS (Austria: EAG-VO) — Sources →
Not correct“Packaging rules only matter for consumer goods.”

The PPWR covers all packaging, including transport, sales and industrial (B2B) packaging.

Packaging and Packaging Waste Regulation — Sources →
Not correct“Dual-use is about weapons — our sensors and power electronics are civil.”

The control list is based on technical parameters, not intended use; catch-all controls can also capture unlisted items because of their end use. The 2026 update adds, for example, rotary encoders based on inductive sensing and advanced computing integrated circuits.

Dual-use export controls — Sources →
Partly correct“We only import from Asia, so export control is irrelevant.”

Importing itself requires no licence under the regulation, but re-export, delivery of spare parts or remote technical support to non-EU sites can require one — and sanctions screening applies in any case.

Dual-use export controls — Sources →

How we check

  • Every regulation has its own entry with dates, duties, fact check and sources; each source shows the date it was last opened and verified.
  • We rely on primary sources: the Official Journal via EUR-Lex, the European Commission, ENISA and the Austrian legal information system (RIS). Other sources are used only where no official source exists and are labelled.
  • The radar is reviewed every week. Changes are logged per regulation with the date of the legal event.
  • Proposals are marked as proposals until they are adopted and published.

Important note

This page provides general information on EU and Austrian rules in our own words. It is not legal advice and does not replace an individual legal assessment by a lawyer. Only the legal texts published in the Official Journal of the European Union and in the Austrian Federal Law Gazette are authentic. Dates and requirements can change; check the linked legal texts before decisions. ITDA-S offers technical and documentation checks of products — not legal advice.

Guide to download

The key rules for connected products and industrial parts on four pages, with checklist (PDF).

Not sure where your product stands?

Send us the product and its documents. We check the technical file against the rules on this radar and tell you what is missing — and source an EU-ready alternative if needed.