Which EU rules apply to your product — and what is actually true?
Twelve sets of rules that decide whether connected products, electronics and industrial parts may be sold in the EU. Explained in plain language, fact-checked and reviewed every week against official sources.
Which rules apply to you?
Choose your role and tick what describes your product. The result is a first orientation — it runs only in your browser; nothing is sent or stored.
Latest developments
- PLD
Review: we found no published Austrian implementing law; the deadline of 9 December 2026 is unchanged.
- NIS2 / NISG 2026
NISG 2026 entered into force; registration window runs until 31 December 2026.
- WEEE / RoHS
Retailer take-back of very small household devices containing batteries applies in Austria.
- Dual-use
Commission adopted the 2026 Delegated Regulation updating Annex I (semiconductor manufacturing equipment, advanced computing ICs, inductive rotary encoders, ceramic matrix composites, additive manufacturing …); it enters into force upon publication in the Official Journal after the two-month scrutiny period.
- Data Act
Access-by-design obligation (Art. 3(1)) applies to newly placed products.
- CRA
Reporting obligations apply; ENISA’s CRA Single Reporting Platform went live the same day.
- Batteries
Earliest application date of the labelling requirements (Art. 13); the actual date depends on the implementing act on label specifications.
- PPWR
PPWR applies generally.
Key dates 2025–2028
- AI ActProhibited practices and AI literacy
- PPWREntry into force
- REDCybersecurity requirements mandatory
- AI ActGeneral-purpose AI rules and governance
- BatteriesExtended producer responsibility: registration, take-back
- Data ActApplies — pre-contract information, data access rights, fair terms for new contracts
- NIS2 / NISG 2026NISG 2026 published (BGBl. I Nr. 94/2025)
- CRARules for conformity assessment bodies apply
- WEEE / RoHSEAG-VO-Novelle 2026 published (BGBl. II Nr. 218/2026)
- MRRegulation (EU) 2026/1744 in force — AI requirements for machinery to be set by delegated act
- AI ActGeneral application incl. transparency duties (marking of generated content for certain systems: 2 Dec 2026)
- PPWRGeneral application
- BatteriesLabelling requirements (Art. 13) — from this date or 18 months after the implementing act on label specifications, whichever is later
- CRAReporting of actively exploited vulnerabilities and severe incidents (also for products already on the market)
- Data ActAccess-by-design duty (Art. 3(1)) for products placed on the market after this date
- Dual-useCommission adopted the 2026 update of Annex I (enters into force on publication in the Official Journal)
- NIS2 / NISG 2026NISG 2026 in force in Austria
- WEEE / RoHSRetailers with ≥ 25 m² sales area take back, free of charge and without a new purchase, very small household devices containing batteries (no outer dimension over 25 cm) of the types they sell
- PLDTransposition deadline — applies to products placed on the market after this date
- NIS2 / NISG 2026Registration deadline for affected entities
- MRMachinery Regulation applies; Directive 2006/42/EC repealed
- BatteriesQR code, removability of portable batteries, battery passport
- BatteriesDue-diligence obligations (postponed by (EU) 2025/1561)
- Data ActUnfair-terms rules extend to certain older long-term contracts
- AI ActHigh-risk systems in Annex III areas (postponed by (EU) 2026/1744)
- CRAFull application — all essential requirements, CE marking
- REDRepealed by Delegated Regulation (EU) 2026/339 — CRA takes over
- MRDelegated acts adding AI-specific requirements to the Machinery Regulation must apply by this date
- AI ActHigh-risk AI in regulated products (Annex I)
- PPWRHarmonised labelling requirements — at the earliest (depends on implementing act)
All regulations on the radar
Cyber Resilience Act
Regulation (EU) 2024/2847
Cybersecurity becomes a condition for selling almost every product with digital elements in the EU — reporting duties already apply since 11 September 2026.
Next date: 11 Dec 2027 — Full application — all essential requirements, CE marking
Details, fact check & sources →Radio Equipment Directive — cybersecurity
Delegated Regulation (EU) 2022/30 · EN 18031
Since 1 August 2025 internet-connected radio equipment must protect networks and personal data and guard against fraud — until the CRA takes over on 11 December 2027.
Next date: 11 Dec 2027 — Repealed by Delegated Regulation (EU) 2026/339 — CRA takes over
Details, fact check & sources →General Product Safety Regulation
Regulation (EU) 2023/988
Since 13 December 2024 consumer products may only be placed on the EU market if an economic operator established in the EU is responsible for them — plus traceability, safety documentation and accident reporting.
Details, fact check & sources →Data Act
Regulation (EU) 2023/2854
Users of connected products get a right to access and use the data their use generates — and products placed on the market after 12 September 2026 must be designed to make that data accessible.
Next date: 12 Sep 2027 — Unfair-terms rules extend to certain older long-term contracts
Details, fact check & sources →NIS2 — Austrian NISG 2026
Directive (EU) 2022/2555 · Austria: NISG 2026 (BGBl. I Nr. 94/2025)
Austria’s NIS2 law is in force since 1 October 2026: thousands of medium and large companies must register by 31 December 2026 — and pass security requirements on to their suppliers.
Next date: 31 Dec 2026 — Registration deadline for affected entities
Details, fact check & sources →New Product Liability Directive
Directive (EU) 2024/2853
For products placed on the market after 9 December 2026, software counts as a product, missing security updates can make a product defective — and the EU importer is liable when the manufacturer sits outside the EU.
Next date: 9 Dec 2026 — Transposition deadline — applies to products placed on the market after this date
Details, fact check & sources →Machinery Regulation
Regulation (EU) 2023/1230
From 20 January 2027 the Machinery Regulation replaces the Machinery Directive — with cybersecurity for safety functions and digital instructions.
Next date: 20 Jan 2027 — Machinery Regulation applies; Directive 2006/42/EC repealed
Details, fact check & sources →AI Act
Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744
The AI Act applies in stages; after the Digital Omnibus, high-risk rules apply from 2 December 2027 (Annex III) and 2 August 2028 (AI in regulated products).
Next date: 2 Dec 2027 — High-risk systems in Annex III areas (postponed by (EU) 2026/1744)
Details, fact check & sources →Batteries Regulation
Regulation (EU) 2023/1542
Producer registration since August 2025, labelling requirements from 18 August 2026 (or later, depending on an implementing act), QR code, removability and battery passport from 18 February 2027.
Next date: 18 Feb 2027 — QR code, removability of portable batteries, battery passport
Details, fact check & sources →WEEE & RoHS (Austria: EAG-VO)
Directive 2012/19/EU · Austria: EAG-VO · Directive 2011/65/EU
Electrical and electronic equipment needs producer registration, take-back financing and restricted-substance compliance — Austria extended retailer take-back obligations from 1 October 2026.
Details, fact check & sources →Packaging and Packaging Waste Regulation
Regulation (EU) 2025/40
Since 12 August 2026 an EU regulation sets the core rules for all packaging, including transport and industrial packaging of imported goods (extended producer responsibility schemes remain national).
Next date: 12 Aug 2028 — Harmonised labelling requirements — at the earliest (depends on implementing act)
Details, fact check & sources →Dual-use export controls
Regulation (EU) 2021/821
Civil electronics can be controlled goods: the 2026 update of the EU control list adds e.g. inductive rotary encoders, semiconductor manufacturing equipment and advanced computing chips.
Details, fact check & sources →Common claims — checked
What we hear most often from buyers, importers and integrators, compared with the legal texts.
Not correct“The CRA only starts in December 2027 — nothing to do before.”
Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents — and this also applies to products placed on the market before December 2027.
Cyber Resilience Act — Sources →Not correct“We only import — cybersecurity is the factory’s job.”
Importers have their own duties: they may only place compliant products on the market, must verify documentation and CE marking, keep the EU declaration of conformity for at least 10 years and act on known vulnerabilities. If you sell under your own name or trademark, you are considered the manufacturer.
Cyber Resilience Act — Sources →Partly correct“Open-source components make our firmware exempt.”
Non-commercial open-source software itself is largely outside scope. But a manufacturer that integrates open-source components into a commercial product is responsible for them and must exercise due diligence.
Cyber Resilience Act — Sources →Not correct“Every CRA product needs a notified body.”
Most products allow self-assessment. Only “important” products (classes I and II, e.g. routers, microcontrollers with security functions, firewalls) may need third-party assessment; “critical” products may require European cybersecurity certification once a delegated act requires it — until then the class II procedures apply. The categories are listed in Annexes III and IV of the CRA; their technical descriptions are set out in Implementing Regulation (EU) 2025/2392.
Cyber Resilience Act — Sources →Not correct“The RED cyber rules end in 2027, so we can ignore them.”
They apply to every product placed on the market before 11 December 2027, and market surveillance can still act on those products afterwards.
Radio Equipment Directive — cybersecurity — Sources →Not correct“Bluetooth-only devices are not internet-connected.”
If the device can communicate over the internet via another device — e.g. a phone app or a gateway — it can be in scope.
Radio Equipment Directive — cybersecurity — Sources →Partly correct“A CE mark on a radio module covers the finished device.”
A compliant module helps, but the product placed on the market is assessed as a whole — including its software, interfaces and default settings.
Radio Equipment Directive — cybersecurity — Sources →Partly correct“Industrial parts are never affected by the GPSR.”
Purely professional products are outside scope. But products likely to be used by consumers — e.g. smart meters, sensors, tools, chargers sold openly online — are covered.
General Product Safety Regulation — Sources →Not correct“Buying through a marketplace makes the platform responsible.”
Marketplaces have their own duties, but they do not replace the manufacturer, importer or EU responsible person. If your company is established in the EU and places goods from a non-EU country on the EU market, you are the importer.
General Product Safety Regulation — Sources →Not correct“The Data Act is about personal data — that’s GDPR territory.”
It explicitly covers non-personal machine and sensor data too. GDPR continues to apply in parallel where personal data is involved.
Data Act — Sources →Not correct“Only consumer smart-home devices are covered.”
Industrial machines, meters, agricultural equipment and vehicles are typical connected products under the Data Act.
Data Act — Sources →Not correct“The Digital Omnibus has already changed the Data Act.”
As of the last review the Data Act amendments are still a proposal in negotiation. The access-by-design duty applies unchanged to products placed on the market after 12 September 2026.
Data Act — Sources →Partly correct“We have fewer than 50 employees, so NIS2 doesn’t concern us.”
You may not be directly regulated, but your NIS2 customers must secure their supply chain — they will pass requirements on to you contractually.
NIS2 — Austrian NISG 2026 — Sources →Not correct“Manufacturing companies are not in scope — NIS2 is for critical infrastructure.”
Manufacturing of computers, electronic and optical products, electrical equipment, machinery and vehicles is a listed sector (important entities).
NIS2 — Austrian NISG 2026 — Sources →Not correct“Software is not a product, so there is no strict liability.”
Under the new directive software — including AI systems and firmware — is explicitly a product.
New Product Liability Directive — Sources →Not correct“We can exclude liability in our terms and conditions.”
Liability towards the injured person cannot be limited or excluded by contract.
New Product Liability Directive — Sources →Not correct“The cybersecurity requirements of the Machinery Regulation have been postponed to 2027/2028.”
Industry associations requested a postponement, but it has not been adopted (status at last review). What was shifted to 2028 are the AI-specific requirements (via Regulation (EU) 2026/1744). Plan for 20 January 2027.
Machinery Regulation — Sources →Partly correct“A machine with CE under the old directive can still be sold forever.”
Machines placed on the market before 20 January 2027 stay legal. Each unit placed on the market from that date must comply with the regulation.
Machinery Regulation — Sources →Not correct“The AI Act has been postponed as a whole.”
Mainly the high-risk obligations were postponed (plus, for systems placed on the market before 2 August 2026, the marking of generated content until 2 December 2026). Prohibitions, AI-literacy measures, general-purpose AI rules and the other transparency duties already apply.
AI Act — Sources →Not correct“A battery built into a device is the device maker’s problem, not the importer’s.”
Whoever first makes the battery available in a Member State — also inside an appliance — is the producer for extended producer responsibility. For imports that is usually the importer.
Batteries Regulation — Sources →Partly correct“Our Chinese supplier is registered, so we don’t need to be.”
Registration is per country and per role. Only a registration (or an authorised representative) that covers your sales in Austria counts — check the EDM register.
WEEE & RoHS (Austria: EAG-VO) — Sources →Not correct“Packaging rules only matter for consumer goods.”
The PPWR covers all packaging, including transport, sales and industrial (B2B) packaging.
Packaging and Packaging Waste Regulation — Sources →Not correct“Dual-use is about weapons — our sensors and power electronics are civil.”
The control list is based on technical parameters, not intended use; catch-all controls can also capture unlisted items because of their end use. The 2026 update adds, for example, rotary encoders based on inductive sensing and advanced computing integrated circuits.
Dual-use export controls — Sources →Partly correct“We only import from Asia, so export control is irrelevant.”
Importing itself requires no licence under the regulation, but re-export, delivery of spare parts or remote technical support to non-EU sites can require one — and sanctions screening applies in any case.
Dual-use export controls — Sources →How we check
- Every regulation has its own entry with dates, duties, fact check and sources; each source shows the date it was last opened and verified.
- We rely on primary sources: the Official Journal via EUR-Lex, the European Commission, ENISA and the Austrian legal information system (RIS). Other sources are used only where no official source exists and are labelled.
- The radar is reviewed every week. Changes are logged per regulation with the date of the legal event.
- Proposals are marked as proposals until they are adopted and published.
Important note
This page provides general information on EU and Austrian rules in our own words. It is not legal advice and does not replace an individual legal assessment by a lawyer. Only the legal texts published in the Official Journal of the European Union and in the Austrian Federal Law Gazette are authentic. Dates and requirements can change; check the linked legal texts before decisions. ITDA-S offers technical and documentation checks of products — not legal advice.
Guide to download
The key rules for connected products and industrial parts on four pages, with checklist (PDF).
Not sure where your product stands?
Send us the product and its documents. We check the technical file against the rules on this radar and tell you what is missing — and source an EU-ready alternative if needed.