Builder watchlist

Regulatory deadlines

A date-backed watchlist for software builders, AI-assisted product teams, connected-product makers, platform operators, and regulated-sector vendors.

Online withdrawal function applies

Trigger

Distance contracts concluded through websites or apps where EU consumers have a statutory withdrawal right.

Builder action

Design a clear withdrawal function, confirmation step, durable acknowledgement, and support records before launch.

Article 14 reporting obligations apply

Trigger

Products with digital elements where actively exploited vulnerabilities or severe incidents may need reporting.

Builder action

Set up vulnerability intake, severity triage, exploitation checks, incident ownership, and durable evidence records.

New EU product-liability cutover

Trigger

Software, AI, updates, or connected-product components placed on the EU market or put into service after the cutover.

Builder action

Document release decisions, update behavior, defect handling, dependency provenance, and post-market security fixes.

Full CRA application

Trigger

Commercial software, hardware, components, and products with digital elements made available on the EU market.

Builder action

Turn secure-by-design, support-period disclosure, technical documentation, vulnerability handling, and CE evidence into release gates.

Conformity assessment body chapter applies

Trigger

Manufacturers and product teams depending on notified bodies for CRA conformity assessment.

Builder action

Map whether your product category needs self-assessment, third-party assessment, or deeper legal review.

EU Data Act applies

Trigger

Connected-product data, user data access, third-party data sharing, and data-processing service switching.

Builder action

Review product data architecture, export/access paths, contract terms, switching support, and user-facing data flows.

FTC Safeguards notification requirement active

Trigger

Covered financial-in-nature products with notification events involving customer information.

Builder action

Make incident detection, customer-information scoping, FTC notice timing, and evidence retention explicit in the security program.

UK consumer connectable product security regime active

Trigger

Consumer smart devices, connected hardware, and related apps sold into the UK.

Builder action

Check default credentials, vulnerability reporting, security update transparency, and supply-chain role duties.

DSA applies to all online intermediaries in the EU

Trigger

Hosting, marketplace, app store, social, search, and other user-content or intermediary services serving EU users.

Builder action

Check notice-and-action, moderation transparency, complaint handling, trader traceability, and advertising transparency.

Builder regulatory deadlines | Burhuc Regulation