Two kinds of date end up on the same list. Regulations that start applying, and software that stops being supported. Both are set by someone else, both arrive whether or not you’re ready, and both are usually noticed late.
This is every one we’re tracking, in date order — EU, UK, US, Middle East and Asia Pacific regulation alongside end-of-life dates for the systems businesses actually run.
Narrow it to where you operate and what you run. Anything that applies everywhere stays on the list whatever you pick, because end-of-life doesn’t respect borders and a database doesn’t care what sector you’re in.
Dates that have already passed are above the line. They matter more than they look. An obligation that started applying in 2025 is still applying, and a platform that lost support in 2023 has gone unpatched every day since.
Every row carries the source it came from and the date we last checked it. Check the source before you act on anything here.
Showing all 304 dates.
164 dates have already passed — open if you are carrying older systems
2018
2020
DIFC Data Protection Law 2020
In force
Financial free zone regime (ADGM similar)
Sourcechecked 19 Aug 2026
2021
2022
Federal PDPL (Decree-Law 45/2021)
In force
Executive regulations still pending - obligations bite 6 months after issuance
Sourcechecked 19 Aug 2026
PHP 7.4
Security support ended
Still common on legacy WP/Magento hosts; pins old OpenSSL/OS packages
Sourcechecked 19 Aug 2026
2023
OpenSSL 1.1.1
End of life
Frozen TLS stacks on old distros; premium support only
Sourcechecked 19 Aug 2026
PDPL (Personal Data Protection Law)
In force
SDAIA-supervised regime
1 article on this
Sourcechecked 19 Aug 2026
MySQL 5.7
End of life
Blocks modern TLS and utf8mb4 defaults; still common on shared hosting
Sourcechecked 19 Aug 2026
SEC cybersecurity disclosure rules
Material incident 8-K within 4 business days (ongoing since Dec 2023)
Sourcechecked 19 Aug 2026
2024
Server products (Jira/Confluence/Bitbucket) all
End of support
Data Center or Cloud only since
Sourcechecked 19 Aug 2026
PSTI Act (product security regime)
In force
No default passwords, vuln disclosure, support-period transparency
Sourcechecked 19 Aug 2026
CentOS 7
End of life
Drove mass cPanel/Plesk migrations to Alma/Rocky/Ubuntu
If you are still running this
Panel-forced migrations to AlmaLinux/Rocky/Ubuntu - full rebuilds, not in-place.
Sourcechecked 19 Aug 2026
PDPL
Compliance grace period ended
Full enforcement since; transfer rules amended 2024
1 article on this
Sourcechecked 19 Aug 2026
Database for MySQL - Single Server -
Retired
Forced Flexible Server migrations
Sourcechecked 19 Aug 2026
NIS2 Directive (2022/2555)
National transposition deadline
Many states transposed late - national dates vary
6 articles on this
- NIS2: the EU cybersecurity directive that’s now being enforced
- NIS2 Enforcement Is Waking Up: A Reading for In-Scope Firms
- NIS2 Essential Entities: The Obligations the Highest Tier Actually Carries
- NIS2 and the CRA for a Device Maker: When You’re Both a Regulated Entity and a Regulated Product
- NIS2 Registration: Getting Your Entity Onto the National Register Before the Regulator Finds You
- NIS2 Is Transposed Unevenly: Building One Control Set That Satisfies Multiple Member States
Sourcechecked 19 Aug 2026
NIS2 Directive
Obligations apply (via national law)
Cyber risk measures, 24h/72h incident reporting, management liability
Sourcechecked 19 Aug 2026
Cyber Resilience Act (Reg 2024/2847)
Entered into force
5 articles on this
- CRA Full Application 11 December 2027: The CE-Marking and Conformity Path for Software
- CRA for SaaS and Remote Data Processing: When Your Cloud Backend Is In Scope
- The CRA and Open-Source: How the Manufacturer Duty Falls on Commercial Distributors, Not Volunteers
- Living SBOMs in the Pipeline: Generating, Signing and Attesting Provenance
- NIS2 and the CRA for a Device Maker: When You’re Both a Regulated Entity and a Regulated Product
Sourcechecked 19 Aug 2026
Sitecore XP 9.3
Extended support ended
Pins SQL Server <=2019, Windows Server <=2019, Solr 8.1
If you are still running this
Platform died before its stack: the app is the weak link. Upgrade Sitecore or exit - the OS/DB dates are irrelevant comfort.
It pins you to
Sourcechecked 19 Aug 2026
2025
IRC s174 (OBBBA 2025)
Domestic R&E expensing restored for tax years from 2025
Foreign R&E still 15-year amortisation
Sourcechecked 19 Aug 2026not yet re-confirmed
Drupal 7
End of life
Whole D7 estates now unsupported end-to-end; HeroDevs or replatform
If you are still running this
Unsupported end-to-end. Paid ELTS (HeroDevs) or replatform; security insurers ask.
It pins you to
Sourcechecked 19 Aug 2026
DORA (Reg 2022/2554)
Applies
ICT risk management, TPRM contracts, register of information - the Blast Radius use case
6 articles on this
- DORA is live. What your technology function needs to do now.
- CSSF Circular 22/806: A Practical Technology Reading for ICT Outsourcing
- DORA for Maltese Financial Institutions: Six Questions Your Board Should Be Asking
- MFSA’s ICT and Security Risk Management Framework: What Your Tech Function Must Demonstrate
- Building a DORA Resilience Programme for a Luxembourg-Regulated Entity
- MiCA CASP Operational Resilience: A Technology Function’s Reading of Article 68
Sourcechecked 19 Aug 2026
Azure AD Graph API -
Fully retired
Apps had to move to Microsoft Graph
Sourcechecked 19 Aug 2026not yet re-confirmed
AI Act
Prohibitions + AI literacy duty apply
Art 5 bans; Art 4 literacy
1 article on this
Sourcechecked 19 Aug 2026
Online Safety Act 2023
Illegal content duties enforceable
Ofcom illegal harms codes
Sourcechecked 19 Aug 2026
FinCEN BOI (Corporate Transparency Act)
US domestic companies exempted (interim final rule)
Major reversal - verify current scope
Sourcechecked 19 Aug 2026not yet re-confirmed
PCI DSS 4.x
Future-dated requirements became mandatory
Contractual via card schemes
Sourcechecked 19 Aug 2026
DOJ bulk sensitive data rule (EO 14117)
Effective
Restricts certain data transactions; affects vendors/adtech
Sourcechecked 19 Aug 2026
NIS2 Directive
Member state entity registration lists established
Registration/identification duty
1 article on this
Sourcechecked 19 Aug 2026
DORA
First Register of Information submissions to NCAs
Per-NCA dates varied around Apr 2025; now annual
Sourcechecked 19 Aug 2026not yet re-confirmed
Node.js 18 LTS
End of life
AWS Lambda blocked node18 updates from Sep 2025 - cloud enforces EOL faster
If you are still running this
Cloud platforms enforce EOL faster than on-prem: deploys get blocked before your risk register notices.
It pins you to
Sourcechecked 19 Aug 2026
Cyber Security Act 2024
Ransomware payment reporting mandatory
Report payments within 72h
Sourcechecked 19 Aug 2026
Ubuntu 20.04 LTS
Standard support ended
ESM (Ubuntu Pro) to Apr 2030; distro OpenSSL 1.1.1 frozen
If you are still running this
Frozen TLS + frozen runtimes. Ubuntu Pro ESM buys time; dist-upgrade cascades every app above.
It pins you to
Sourcechecked 19 Aug 2026
PDPA Amendment Act 2024
Breach notification + mandatory DPO in effect
Phased commencement Jan/Apr/Jun 2025
Sourcechecked 19 Aug 2026not yet re-confirmed
European Accessibility Act (Dir 2019/882)
Obligations apply
WCAG-level duties for private sector
4 articles on this
- The European Accessibility Act: why your digital products now have to be accessible
- The European Accessibility Act Is Live: Turning WCAG 2.1 AA Into a CI Gate, Not a Year-End Audit
- The Accessibility Conformance Report Under the EAA: Evidence You Can Actually Defend
- Accessibility for Self-Service Terminals and Apps Under the EAA: The Hardware-Plus-Software Scope
Sourcechecked 19 Aug 2026
Online Safety Act
Child safety duties + age assurance
Highly effective age assurance required
Sourcechecked 19 Aug 2026
Lambda runtime: nodejs18.x -
Deprecated
Pattern: Lambda deprecates shortly after upstream EOL
Sourcechecked 19 Aug 2026
Data Act (Reg 2023/2854)
Applies
Data access, switching, unfair terms
4 articles on this
- The EU Data Act Gave You the Right to Leave Your Cloud Provider — Check Your Contract
- Functional Equivalence and Cloud Exit: What the Data Act Actually Obliges Your Provider to Enable
- The Data Act Switching Deadline: Egress Fees Disappear on 12 January 2027 — Renegotiate Now
- IoT Data Access by Design: Engineering Connected Products for Data Act User-Access Rights
Sourcechecked 19 Aug 2026
vSphere/ESXi 7.0
End of general support
Hypervisor EOL invalidates supported-config status for everything hosted on it
If you are still running this
Hypervisor EOL invalidates 'supported configuration' for every guest - audit and cyber-insurance exposure.
Sourcechecked 19 Aug 2026
Entry/Exit System (EES)
Progressive rollout began
Relevant to travel-adjacent legal services & forms logic
Sourcechecked 19 Aug 2026
Exchange Server 2016
End of support
Path is Exchange SE (subscription) or Exchange Online
If you are still running this
Only paths: Exchange SE in-place or Exchange Online. Hybrid config ages with it.
It pins you to
1 article on this
Sourcechecked 19 Aug 2026
Windows 10 (22H2)
End of support
Largest desktop EOL event of the decade
If you are still running this
Endpoint EOL cascades into Cyber Essentials / insurance non-compliance and M365 support boundaries.
It pins you to
1 article on this
Sourcechecked 19 Aug 2026
ISO/IEC 27001:2022 transition
2013-edition certificates invalid after
Recertification wave complete
Sourcechecked 19 Aug 2026
NYDFS Part 500 amendments
Final phase (MFA everywhere, asset inventory)
3 articles on this
Sourcechecked 19 Aug 2026
DPDP Act 2023 - Rules
Rules notified
Phased obligations follow
Sourcechecked 19 Aug 2026not yet re-confirmed
ECCTA 2023 (Companies House reform)
Director identity verification - new appointments
Sourcechecked 19 Aug 2026
Symfony 5.4 LTS
Community security ended
Commercial extended support available from SensioLabs
Sourcechecked 19 Aug 2026not yet re-confirmed
Customer and Product Data Act 2025
Open banking designation - major banks
NZ CDR regime begins
Sourcechecked 19 Aug 2026not yet re-confirmed
Online Safety Amendment (Social Media Minimum Age)
Platforms must exclude under-16s
World-first; age assurance tech mandate
Sourcechecked 19 Aug 2026
EU adequacy decisions for UK
Interim extension expired; renewal adopted late 2025
Confirm renewed decisions and their sunset date
Sourcechecked 19 Aug 2026not yet re-confirmed
PHP 8.1
Security support ended
Many WP plugin stacks and Magento 2.4.6 pinned here; move hosts to 8.2/8.3
If you are still running this
Unpatched language runtime under a patched CMS. Host-level move to 8.2/8.3 forces a plugin compatibility audit.
It pins you to
Sourcechecked 19 Aug 2026
Spring Boot 3.4
OSS support ended
Commercial support runs years longer
Sourcechecked 19 Aug 2026not yet re-confirmed
2026
App Store Accountability Act
In effect
6 articles on this
- Multi-Regulator VASP Operations: Architecting for MiCA, VARA, MAS, and FCA
- Why UAE Trading Houses Are Outgrowing Their ERPs (And What to Do About It)
- The California Delete Act and DROP: Wiring Your Systems to the State Deletion Platform
- FRTB in the EU: Preparing for the 1 January 2027 Market-Risk Go-Live
- DAC8 for Cyprus and Malta CASPs: First Reporting and the Data You Must Capture
- CCPA ADMT Rules: What the January 2027 Automated-Decision Duties Require You to Build
Sourcechecked 19 Aug 2026not yet re-confirmed
DAC8 / CARF (Dir 2023/2226)
Crypto-asset reporting rules apply
First reports due 2027
Sourcechecked 19 Aug 2026
HB 3773 (AI in employment, IHRA amendment)
In effect
Notice + anti-discrimination
Sourcechecked 19 Aug 2026
Protection of Critical Infrastructures (Computer Systems) Ordinance
In effect
Security obligations + incident reporting
6 articles on this
- Multi-Regulator VASP Operations: Architecting for MiCA, VARA, MAS, and FCA
- ADGM vs DIFC: Choosing the Right Free Zone for a Technology-Heavy Business
- The California Delete Act and DROP: Wiring Your Systems to the State Deletion Platform
- DAC8 for Cyprus and Malta CASPs: First Reporting and the Data You Must Capture
- CCPA ADMT Rules: What the January 2027 Automated-Decision Duties Require You to Build
- CCPA Cybersecurity Audits: Preparing for the First Auditable Period Beginning January 2027
Sourcechecked 19 Aug 2026
SB 53 (frontier AI safety)
In effect
Safety frameworks + incident reporting
Sourcechecked 19 Aug 2026not yet re-confirmed
SB 942 AI Transparency Act
In effect
AI detection tools + provenance; check AB 853 amendments
Sourcechecked 19 Aug 2026not yet re-confirmed
Working for Workers (ESA amendment)
AI disclosure in public job postings
Must disclose AI use in hiring ads
Sourcechecked 19 Aug 2026
Kubernetes 1.32
End of support
Managed clouds force-upgrade or charge extended-support fees
If you are still running this
Clouds auto-upgrade or bill extended support; deprecated APIs break manifests on the cloud's schedule, not yours.
It pins you to
Sourcechecked 19 Aug 2026not yet re-confirmed
Basic auth for SMTP AUTH (client submission) -
Removed
Rollout started Sep 2025 - confirm final removal wave
Sourcechecked 19 Aug 2026not yet re-confirmed
Cyber Security (Security Standards for Smart Devices) Rules
Mandatory IoT security standard
PSTI-style regime
Sourcechecked 19 Aug 2026not yet re-confirmed
Magento OS / Adobe Commerce 2.4.6
Support ended
PHP 8.1 + MySQL 8.0 pinning made H1-2026 a forced-migration window
Sourcechecked 19 Aug 2026not yet re-confirmed
Public TLS certificates max validity 200 days
Policy takes effect
Ballot SC-081: automation (ACME) becomes near-mandatory
Sourcechecked 19 Aug 2026
GST InvoiceNow requirement
New voluntary GST registrants must use InvoiceNow
Peppol-based e-invoice transmission to IRAS; earlier wave Nov 2025
Sourcechecked 19 Aug 2026not yet re-confirmed
Making Tax Digital for Income Tax
Mandatory - income over 50k GBP
Quarterly digital submissions via compatible software
Sourcechecked 19 Aug 2026
App Store Accountability Act
Core obligations
Confirm phase dates
3 articles on this
Sourcechecked 19 Aug 2026not yet re-confirmed
Amazon Linux 2
End of support
Date was extended more than once - confirm final
Sourcechecked 19 Aug 2026not yet re-confirmed
E-invoicing mandate
Voluntary/pilot phase begins
Peppol-based; accreditation of providers since 2025
Sourcechecked 19 Aug 2026not yet re-confirmed
MiCA
CASP grandfathering ends (latest)
Member states could shorten; max transition just ended
2 articles on this
Sourcechecked 19 Aug 2026
MyInvois e-invoicing
Final phase - smallest taxpayers (to RM1m)
Earlier phases 2024-Jan 2026 by turnover
Sourcechecked 19 Aug 2026not yet re-confirmed
SQL Server 2016
Extended support ended
Just passed; huge installed base under Sitecore/SharePoint estates
If you are still running this
DB and OS retire within six months - one project, double scope. Budget as a pair.
It pins you to
Sourcechecked 19 Aug 2026
SharePoint Server 2016
End of support
Just passed
If you are still running this
Farm, OS and DB expire within six months of each other - one migration cluster (SE subscription or M365).
It pins you to
Sourcechecked 19 Aug 2026
Digital Omnibus on AI (Reg 2026/1744)
In force - amends AI Act timeline
Published OJ 24 Jul 2026; defers high-risk regime
Sourcechecked 19 Aug 2026
AI Act (as amended)
Art 50 transparency applies (chatbot disclosure, deepfake labelling)
NOT deferred by the Omnibus - live now
6 articles on this
- EU AI Act Article 9 Risk Management Systems: A Technology Function’s Reading
- The EU AI Act Digital Omnibus: What Changed, and What Your Technology Function Must Still Do Before 2 August 2026
- Training-Data Transparency: What the GPAI Public Summary Template Requires
- From Voluntary Code to Enforcement: How the GPAI Code of Practice Shapes Expectations
- The AI System Inventory Schema That Maps to the AI Act Risk Tiers
- AI Serious-Incident Reporting Pipeline: Engineering for the AI Act’s 15-Day Clock
Sourcechecked 19 Aug 2026
2026
Debian 11 (bullseye) LTS
LTS ends
Imminent: unpatched after this unless on paid ELTS
Sourcechecked 19 Aug 2026
OpenSSL 3.0 LTS
End of life
Imminent: affects Ubuntu 22.04-era builds, Node 18-era binaries, many appliances
Sourcechecked 19 Aug 2026
Cyber Resilience Act
Vulnerability & incident reporting duties (Art 14)
Imminent: 24h early warning to ENISA/CSIRT for exploited vulns
6 articles on this
- The EU Cyber Resilience Act: what the 2026 deadline means for anyone who ships software
- Cyber Resilience Act and Crypto-Agility: The Product Duty Nobody Priced In
- The CRA Deadline That Arrives Before the One Everyone Is Watching
- CRA Full Application 11 December 2027: The CE-Marking and Conformity Path for Software
- Automating SBOM Generation for the CRA: From CI Artefact to Machine-Readable Deliverable
- The CRA Vulnerability-Handling Process: What ‘Free Security Updates for the Support Period’ Forces You to Build
Sourcechecked 19 Aug 2026
Data Act
Access-by-design for new connected products
Imminent
1 article on this
Sourcechecked 19 Aug 2026
Exchange Web Services (EWS) in Exchange Online -
Retired
Any integration still on EWS breaks; move to Microsoft Graph
Sourcechecked 19 Aug 2026
Windows Server 2012 / 2012 R2
ESU (year 3) ends
Extended support already ended Oct 2023; after this there is nothing left to buy
Sourcechecked 19 Aug 2026
ECCTA 2023
Existing directors verified (via annual confirmation statement)
12-month transition window
Sourcechecked 19 Aug 2026not yet re-confirmed
Temurin JDK 8
Community support ends
Free-support trap: ends far earlier than Oracle paid
Sourcechecked 19 Aug 2026not yet re-confirmed
AI Act (as amended)
Art 50(2) marking for legacy GenAI + new Art 5 prohibitions (NCII/CSAM)
1 article on this
Sourcechecked 19 Aug 2026
New Product Liability Directive (2024/2853)
Transposition deadline; applies to products placed after
Direct exposure for software vendors
Sourcechecked 19 Aug 2026
Privacy Act amendments (2024)
Automated decision transparency in privacy policies
24 months post-assent
Sourcechecked 19 Aug 2026
Proxmox VE 8
End of life
Tracks Debian 12 base - confirm exact date
Sourcechecked 19 Aug 2026not yet re-confirmed
SWIFT Customer Security Programme
Annual attestation due (recurring)
By 31 Dec each year
Sourcechecked 19 Aug 2026not yet re-confirmed
Sitecore XP 10.1
Extended support ends
After this: no vendor fixes; stack pinned to SQL<=2019/WS<=2019
If you are still running this
After Dec 2026 no vendor fixes for the DXP layer; compensating controls or move to 10.4/XM Cloud.
It pins you to
Sourcechecked 19 Aug 2026
Sitecore XP 10.3
Mainstream support ends
Extended to Dec 2028
Sourcechecked 19 Aug 2026not yet re-confirmed
eIDAS 2.0 (Reg 2024/1183)
Member states must offer EUDI Wallet
24 months after Nov/Dec 2024 implementing acts - confirm exact date
Sourcechecked 19 Aug 2026not yet re-confirmed
2027
CPPA regulations - ADMT
Compliance date
Opt-outs and pre-use notices
1 article on this
Sourcechecked 19 Aug 2026not yet re-confirmed
Colorado AI Act -> SB 26-189 replacement
Narrowed ADMT disclosure law takes effect
Original CAIA repealed/replaced May 2026; duty-of-care regime dropped
Sourcechecked 19 Aug 2026
E-invoicing mandate
Phase 1 mandatory (large businesses)
Confirm thresholds & later phases
Sourcechecked 19 Aug 2026not yet re-confirmed
Data Act
Cloud switching charges abolished
Egress-fee endgame
3 articles on this
Sourcechecked 19 Aug 2026
Windows Server 2016
Extended support ends
Pairs with the SQL Server 2016 / SharePoint 2016 wave
Sourcechecked 19 Aug 2026
Machinery Regulation (2023/1230)
Applies
Software performing safety functions in scope
Sourcechecked 19 Aug 2026
DAC7
Annual platform operator reports due (recurring)
Report by 31 Jan each year for prior year
Sourcechecked 19 Aug 2026not yet re-confirmed
EHDS (Reg 2025/327)
First obligations apply (staged 2027-2031)
Staged; confirm chapter-by-chapter dates
4 articles on this
- EHDS EHR Certification: The Real Timeline, and Why It Is a Data-Model Problem
- EHDS Secondary Use: The Data Permit, Health Data Access Body and Secure Processing You’ll Query Through
- EHDS Primary Use and the European Electronic Health Record Exchange Format: A FHIR Data-Model Problem
- EHDS Secondary Use: Preparing Health Data for the Access Bodies Without Breaching GDPR
Sourcechecked 19 Aug 2026not yet re-confirmed
ECCTA 2023
Accounts filing becomes software-only
Web/paper filing routes close - a genuine software mandate
Sourcechecked 19 Aug 2026
Magento OS / Adobe Commerce 2.4.7
Support ends
Confirm exact day on Adobe lifecycle page
Sourcechecked 19 Aug 2026not yet re-confirmed
DPDP Act 2023
Main obligations apply (18-month phase-in)
Consent, notice, breach reporting, SDF duties - confirm exact commencement
Sourcechecked 19 Aug 2026not yet re-confirmed
AI Act
Member state AI regulatory sandboxes operational
6 articles on this
- Regulatory Sandboxes: The Delayed National Obligation
- Training-Data Transparency: What the GPAI Public Summary Template Requires
- The Annex III Reprieve Is a Trap: Why 2 December 2027 Needs Work Started in 2026
- Human Oversight by Design: Implementing AI Act Article 14 in the Interface, Not the Policy
- Data Governance Under AI Act Article 10: Training-Set Lineage, Bias Testing and Representativeness
- Don’t forget to rewrite the deadline slide you built for the board last year
Sourcechecked 19 Aug 2026not yet re-confirmed
SLES 12 SP5 (LTSS)
LTSS ends
General support ended Oct 2024
Sourcechecked 19 Aug 2026not yet re-confirmed
AI Act (as amended)
High-risk obligations - Annex III (standalone)
Deferred from 2 Aug 2026 by the Omnibus
6 articles on this
- The EU AI Act deadlines just changed: what now applies, and when
- The EU AI Act Digital Omnibus: What Changed, and What Your Technology Function Must Still Do Before 2 August 2026
- AI Due Diligence: The Diligence Workstream Nobody Ran Last Cycle
- The AI System Inventory Schema That Maps to the AI Act Risk Tiers
- AI Serious-Incident Reporting Pipeline: Engineering for the AI Act’s 15-Day Clock
- The Annex III Reprieve Is a Trap: Why 2 December 2027 Needs Work Started in 2026
Sourcechecked 19 Aug 2026
Cyber Resilience Act
Full application (CE marking, security-by-design)
Applies to software placed on EU market, incl. plugins sold commercially
6 articles on this
- The EU Cyber Resilience Act: what the 2026 deadline means for anyone who ships software
- Cyber Resilience Act and Crypto-Agility: The Product Duty Nobody Priced In
- The CRA Deadline That Arrives Before the One Everyone Is Watching
- CRA Annex I Is a Risk Assessment, Not a Checklist
- CRA Full Application 11 December 2027: The CE-Marking and Conformity Path for Software
- Important vs Critical Products Under the CRA: The Class Test That Decides Your Assessment Route
Sourcechecked 19 Aug 2026
ECC 6.0 (Business Suite 7) EhP6-8
Mainstream maintenance ends
Extended maintenance (paid) to 2030; the S/4HANA forcing function
Sourcechecked 19 Aug 2026
Sitecore XP 10.2
Extended support ends
Mainstream ended Dec 2025
Sourcechecked 19 Aug 2026not yet re-confirmed
Sitecore XP 10.4
Mainstream support ends
Last XP release; XM Cloud is the successor path
Sourcechecked 19 Aug 2026not yet re-confirmed
2028
CSRD (post stop-the-clock, Dir 2025/794)
Wave 2 first reports (FY2027)
Two-year delay via Omnibus I
Sourcechecked 19 Aug 2026not yet re-confirmed
CPPA regulations - cybersecurity audits
First audit certifications (largest tier)
1 article on this
Sourcechecked 19 Aug 2026not yet re-confirmed
CPPA regulations - risk assessments
First submissions due
Assessments to be conducted from 2026-27
1 article on this
Sourcechecked 19 Aug 2026not yet re-confirmed
Making Tax Digital for Income Tax
Mandatory - income over 20k GBP
Announced; confirm
Sourcechecked 19 Aug 2026not yet re-confirmed
RHEL 7 (ELS)
Extended Life Support ends
Standard maintenance ended Jun 2024
Sourcechecked 19 Aug 2026not yet re-confirmed
AI Act (as amended)
High-risk obligations - Annex I (embedded in regulated products)
Deferred from 2 Aug 2027
6 articles on this
- The EU AI Act Digital Omnibus: What Changed, and What Your Technology Function Must Still Do Before 2 August 2026
- The AI System Inventory Schema That Maps to the AI Act Risk Tiers
- The Annex III Reprieve Is a Trap: Why 2 December 2027 Needs Work Started in 2026
- Conformity Assessment Under the AI Act: Internal Control vs Notified Body, and Which You Actually Need
- Technical Documentation as Living Code: Generating AI Act Annex IV From Your Pipeline
- Accuracy, Robustness and Cybersecurity: The AI Act Article 15 Test Battery You Have to Evidence
Sourcechecked 19 Aug 2026
2029
Oracle Database 19c
Premier support ends
Waivers/extensions have shifted several times - confirm on MOS
Sourcechecked 19 Aug 2026not yet re-confirmed
PHP 8.5
Security support ends
Released Nov 2025; confirm exact policy window
Sourcechecked 19 Aug 2026not yet re-confirmed
2030
European Accessibility Act
Service transition period ends
3 articles on this
Sourcechecked 19 Aug 2026not yet re-confirmed
VAT in the Digital Age (ViDA, Dir 2025/516)
Intra-EU digital reporting & e-invoicing mandatory
Member states may mandate domestic e-invoicing earlier (from 2025)
1 article on this
Sourcechecked 19 Aug 2026not yet re-confirmed
Classical public-key crypto (RSA-2048, ECC-256) -
Deprecated (per IR 8547 draft)
Disallowed 2035; PQC migration horizon
Sourcechecked 19 Aug 2026not yet re-confirmed
Java (Oracle JDK) 8
Extended support ends
Paid extended only; free public updates ended years ago
Sourcechecked 19 Aug 2026not yet re-confirmed
2031
2032
Java (Oracle JDK) 11
Extended support ends
Premier ended Sep 2023
Sourcechecked 19 Aug 2026not yet re-confirmed
2035
No date set
Proposals, bills in progress and things expected but not yet timetabled.
.NET Framework 4.8 / 4.8.1
Policy - no fixed date
Supported for the lifetime of the host Windows OS; server refresh drags app regression testing
If you are still running this
Framework is 'supported' only while its OS is - every server refresh drags full app regression.
It pins you to
Sourcechecked 19 Aug 2026
Bill C-27 (CPPA/AIDA)
Died on prorogation (Jan 2025)
Federal privacy/AI reform reset
Sourcechecked 19 Aug 2026not yet re-confirmed
Bill C-8 (critical cyber systems)
In Parliament
Reintroduction of C-26
Sourcechecked 19 Aug 2026not yet re-confirmed
CIRCIA (cyber incident reporting)
Final rule pending
Statutory deadline slipped - track CISA
Sourcechecked 19 Aug 2026not yet re-confirmed
Chrome third-party cookie deprecation -
Cancelled
Reversed Apr 2025 - deprecation is NOT happening; Privacy Sandbox pivot
Sourcechecked 19 Aug 2026not yet re-confirmed
Cyber Security and Resilience Bill
In Parliament
UK NIS update - expected to bite MSPs; track passage
Sourcechecked 19 Aug 2026not yet re-confirmed
Cybersecurity (Amendment) Act 2024
Phased commencement
Track CSA commencement notices
Sourcechecked 19 Aug 2026not yet re-confirmed
Data (Use and Access) Act 2025
Main data provisions commencement (phased SIs)
Check ICO commencement tracker - phased through 2025-26
Sourcechecked 19 Aug 2026not yet re-confirmed
Data Center LTS per release
Policy - ~2y per LTS
Each LTS supported ~2 years from release
Sourcechecked 19 Aug 2026not yet re-confirmed
Drupal 10
Policy - EOL pegged to D12
EOL when Drupal 12 ships (expected 2026) - confirm
Sourcechecked 19 Aug 2026not yet re-confirmed
ETIAS
Expected launch (last quarter 2026)
Date not fixed; 6-month grace expected after start
Sourcechecked 19 Aug 2026not yet re-confirmed
Elasticsearch 7.17
Policy - check matrix
7.17 EOL is pegged to 9.0 GA timing - confirm on Elastic support matrix
Sourcechecked 19 Aug 2026not yet re-confirmed
FTC click-to-cancel rule
Vacated by 8th Circuit (Jul 2025)
State auto-renewal laws still apply
Sourcechecked 19 Aug 2026not yet re-confirmed
Federal PDPL executive regulations
Pending issuance
The real compliance clock starts here - track
Sourcechecked 19 Aug 2026not yet re-confirmed
GitLab self-managed
Policy - rolling
Patches for current + two previous minors only
Sourcechecked 19 Aug 2026
Go all
Policy - rolling
Only the two most recent minor releases are supported
Sourcechecked 19 Aug 2026
HIPAA Security Rule update
NPRM issued Jan 2025; final rule pending
Would mandate MFA, encryption, asset inventory
Sourcechecked 19 Aug 2026not yet re-confirmed
NIS2 transposition (National Cyber Security Bill)
Transposition in progress
EU deadline was Oct 2024; Ireland late - confirm enactment
Sourcechecked 19 Aug 2026not yet re-confirmed
Online Safety Act
Categorised services - additional duties
Register published; extra duties phased through 2026 - track Ofcom roadmap
Sourcechecked 19 Aug 2026not yet re-confirmed
Privacy Act reform - tranche 2
Expected
Fair-and-reasonable test, small business exemption removal - track
Sourcechecked 19 Aug 2026not yet re-confirmed
Redis community
Policy - rolling
Community builds: latest + previous only; licensing changed (RSAL/SSPL then AGPL for 8)
Sourcechecked 19 Aug 2026not yet re-confirmed
Tomcat 9
Policy - no announced EOL
Runs on Java 8+; watch for announcement
Sourcechecked 19 Aug 2026not yet re-confirmed
WordPress core 6.x
Policy - rolling
Only the current branch is fully supported; security backports to older branches are best-effort. PHP version compatibility is the real cascade driver
Sourcechecked 19 Aug 2026
ePrivacy Regulation
Proposal withdrawn (Feb 2025)
Cookie reform folded into Digital Omnibus discussions
Sourcechecked 19 Aug 2026not yet re-confirmed
macOS current-2
Policy - rolling
Apple patches current + two previous majors; no published dates
Sourcechecked 19 Aug 2026
Something missing?
If a date that affects you is not here, tell us and we will go and look. You do not need to leave an email address.
How to read this
Every row links to the source it came from and shows when it was last checked. Rows marked not yet re-confirmed came from a seed list and have not been re-read at source since. Check the source before you act on anything here.
This is a reference list, not legal or compliance advice, and it does not create a professional relationship. Dates move — the AI Act timeline has already been amended once — so confirm anything load-bearing against the primary source on the day you rely on it.