Regulatory intelligence — published
Whitepapers, blueprints, case studies, and regulatory briefs. Open access by default ; some high-value resources require email registration.
One Evidence Set, Five EU Regulations — What Maps
CRA, NIS2, DORA, the AI Act and RED demand overlapping evidence. What genuinely transfers between them, and the three places where it stops.
Five EU Regulations, One Timeline — What Binds and When
CRA, NIS2, DORA, the AI Act and RED land on different dates. Two have already passed. The single timeline every EU product team should be working from.
NIS2 Reaches You Through Procurement, Not a Regulator
Most companies meet NIS2 as a customer questionnaire, not a legal notice. Article 21(2)(d) puts it in your contracts even when you are out of scope.
They Don't Ask If You're Compliant — They Ask What You Show
Market surveillance authorities and enterprise buyers ask the same question, and it is not whether you are compliant. It is what you can produce, and how fast.
AI Act: You Are Probably a Deployer — And Owe Duties
Most companies think the AI Act is for AI builders. If you use AI in hiring, credit or access to services, you are a deployer — and you owe obligations.
NIS2 Article 23 Incident Reporting: 24h/72h/1-month Decision Tree for CISOs
NIS2 Article 23 imposes a three-tiered incident reporting regime that turns every cyber event into a ticking clock. Miss the 24-hour early warning and you risk a fine of up to €10 million or 2 % of global turnover; fail to classify severity correctly and you may notify the wrong authority, triggering a second enforcement action. This article provides an operational decision tree, severity matrix, and CSIRT routing table so CISOs in essential and important entities can meet the deadlines without
Connected Vehicle Location Data: CNIL's New GDPR Compliance Framework
The French data protection authority (CNIL) published its final recommendations on connected-vehicle location data in June 2026, closing a two-year consultation that began when a major EU fleet operator was fined €4.2 million for unlawful geofencing. With 92% of new vehicles sold in Europe now equipped with embedded telematics (EUR-Lex Regulation 2019/2144, Article 3(10)), CNIL’s framework transforms how automotive manufacturers, rental companies, and logistics providers must handle real-time tr
DORA Reporting Failures: What Moody's EUR 2.1M Fine Reveals About ICT Audit Gaps
The EUR 2.1 million fine imposed by ESMA on Moody’s Deutschland GmbH in July 2024 was not just a penalty—it was a regulatory warning shot. The enforcement action, the first major DORA-related sanction, exposed systemic weaknesses in ICT audit trails, third-party reporting controls, and supervisory alignment. For CISOs, CTOs, and compliance leaders across the EU, this case is a stark reminder: DORA’s documentation requirements are not theoretical. They are enforceable, measurable, and now, active
GDPR Meets AML: New Joint Guidelines on Data Sharing for Financial Crime Detection
Financial institutions and fintechs face a growing paradox: GDPR demands strict data minimization, while anti-money laundering (AML) and counter-terrorist financing (CFT) regulations require broad data sharing to detect suspicious transactions. The European Data Protection Board (EDPB) and the Anti-Money Laundering Authority (AMLA) have released their first joint guidelines to resolve this tension. For CTOs and DPOs managing cross-border transaction monitoring, these guidelines are not just clar
DORA Meets SREP 2026: EBA's New ICT Risk Scoring in Supervisory Reviews
The European Banking Authority’s (EBA) revised Supervisory Review and Evaluation Process (SREP) Guidance for 2026 introduces a paradigm shift: ICT risk is no longer a standalone compliance exercise but a direct input into capital and liquidity requirements. For CTOs, CISOs, and risk officers in financial entities, this means that every incident report, third-party audit, and resilience test now carries weight in supervisory efficiency metrics. The message is clear—DORA compliance is not just abo
NIS2 Article 19 Disclosure Deadlines: When Vendor Patches Miss Your Reporting Window
A single unpatched critical vulnerability in a third-party component can trigger NIS2’s 24-hour incident notification clock—long before the vendor delivers a fix. For CISOs and CTOs in essential and important entities, this creates a compliance paradox: disclose immediately and risk exposing an unmitigated threat, or delay reporting and face potential fines of up to €10 million or 2% of global turnover. The gap between regulatory deadlines and vendor patch cycles is not hypothetical. By July 202
Calibrating AI Code Review for NIS2: The 'Vibe Spectrum' Compliance Framework
AI-assisted development is now the default for most engineering teams. Yet for CTOs in NIS2-covered entities, every `git commit` that originates from an LLM prompt carries regulatory weight. NIS2 Article 21(2) requires “appropriate technical and organisational measures” to manage supply-chain risks, and Article 4(47) defines “incident” broadly enough to include a single line of insecure AI-generated code that later triggers a breach. The challenge is not whether to allow AI assistance, but how t
NIS2 Vendor SLA Breach: Your Legal Liability When Patches Don't Land on Time
A single unpatched vulnerability in a critical vendor can cascade into a systemic incident across your supply chain. Under NIS2, the clock starts ticking the moment a flaw is disclosed—not when your team applies the fix. By June 2026, essential and important entities must have contractual mechanisms in place to enforce patch timelines, document breaches, and allocate liability when vendors fail to deliver. This guide provides CTOs and CISOs with a practical framework for managing vendor SLA brea
GDPR Subcontractor Due Diligence: Building a Cyber Incident Response Chain
A single subcontractor’s 48-hour delay in notifying a ransomware lock-up can turn a containable incident into a 72-hour GDPR breach report. The CNIL’s latest alerts confirm that most controllers still treat processor vetting as a one-time security questionnaire—ignoring the contractual and operational scaffolding needed to prevent liability cascades. This article gives CTOs and CISOs a practical framework to harden the incident-response chain before the next attack arrives.
ESMA's 2025 enforcement focus: Why CTOs must align ICT audit with corporate reporting
In January 2025, ESMA published its annual enforcement priorities for corporate reporting. Buried beneath the familiar themes of climate disclosures and IFRS 17 implementation lies a less visible but equally critical shift: the deliberate linkage between financial reporting controls and ICT resilience. For CTOs and DPOs in financial entities, this convergence is not merely a compliance nuance—it is the trigger for DORA’s ICT audit requirements. Failure to align ICT audit scopes with corporate re
NIS2 Article 19: Turning May 2026 Vulnerability Cascade Into Incident Reporting Evidence
On 29 May 2026, a coordinated disclosure of critical vulnerabilities across multiple foundational software libraries will test the resilience of every essential and important entity in the EU. For CISOs and CTOs, this is not merely a patching drill—it is the first major stress test of NIS2’s continuous monitoring obligation under Article 19. The difference between treating this as a series of isolated patches and documenting it as a coordinated incident could determine whether your organisation
AI Act High-Risk Classification: Why Deployers Miss the May 2026 Guidelines Window
The European Commission’s draft guidelines on high-risk AI classification close for public feedback in May 2026—yet most deployers have not begun mapping their AI systems to the emerging criteria. With enforcement of high-risk obligations set for August 2026, the gap between regulatory expectations and operational readiness is widening. For CTOs and CISOs in essential and important entities, this delay is not just a compliance risk but a strategic blind spot that could disrupt product roadmaps,
NIS2 Incident Reporting: When 8 Zero-Days Hit on the Same Day
On 29 May 2026, an EU essential entity’s SOC detects eight previously unknown vulnerabilities—four in industrial firewalls, two in VPN concentrators, and two in hypervisor kernels—all exploited within a 90-minute window. The attack surface spans OT networks, corporate IT, and cloud-hosted ICS dashboards. NIS2 Article 23(1) requires an “initial report” within 72 hours of becoming aware of a “significant incident.” But is this one incident or eight? Does the clock start at first detection or after
When Your Vendor Gets Hacked: CNIL's New Subcontractor Liability Framework
A single compromised subcontractor can trigger GDPR fines, reputational damage, and operational chaos—yet most controllers still treat third-party risk as an afterthought. CNIL’s May 2026 guidance on subcontractor-triggered breaches makes one thing clear: your vendor’s breach is your problem. This framework doesn’t just clarify liability; it demands proactive measures from CTOs and CISOs managing complex vendor risk chains. Here’s how to align your strategy with CNIL’s expectations before the ne
AI Act High-Risk Classification: Why Deployers Miss Compliance Deadlines
The EU AI Act’s high-risk compliance deadline—2 August 2026—is less than 24 months away, yet draft guidelines released in May 2026 reveal a critical disconnect: deployers are fixated on classification but unprepared for the audit demands that follow. Without a structured self-assessment framework, even technically compliant systems risk enforcement actions due to missing documentation, misaligned teams, or untraceable risk decisions. This article dissects the audit gaps in the draft guidelines a
ESMA's 2025 Corporate Reporting Enforcement: What CTOs Must Know
In January 2025, the European Securities and Markets Authority (ESMA) published its *Public Statement on Enforcement Priorities for 2025 Annual Financial Reports*. For the first time, the statement explicitly links ICT audit expectations under the Digital Operational Resilience Act (DORA) to corporate reporting enforcement. CTOs in financial entities—banks, insurers, investment firms, and even listed non-financial companies—now face a dual mandate: ensure financial disclosures are accurate *and*
NIS2 Incident Classification: When Multi-Vendor Vulnerabilities Trigger Reporting Obligations
A coordinated May 2026 vulnerability disclosure across eight critical infrastructure vendors—Linux, Oracle, IBM, Elastic, Centreon, and others—has exposed a gap in NIS2 incident classification. When exploits chain vulnerabilities across multiple suppliers, CISOs and CTOs must determine whether each flaw constitutes a separate reportable incident or if the entire attack sequence triggers a single notification. This article clarifies how NIS2 Article 23 applies to supply chain breach cascades and
IQVIA's €5M Fine Exposes Health Data Warehouse Gaps—What CTOs Must Fix Now
In February 2024, France’s data protection authority (CNIL) imposed a €5 million fine on IQVIA, a global provider of advanced analytics and clinical research services, for failing to implement adequate safeguards in its health data warehouse. The penalty underscores a critical reality for CTOs: even sophisticated data infrastructure can become a GDPR liability if technical and organizational controls are not rigorously aligned with regulatory expectations. With health data classified as a "speci
AI Act High-Risk Classification: Why Deployers Are Unprepared for June 2026 Guidelines
The European Commission’s May 2026 draft guidelines on high-risk AI classification (AI Act Article 6 and Annex III) arrive too late for most deployers. While the document clarifies ambiguities in the original text, it also exposes a critical implementation gap: organizations have spent two years debating classification thresholds but have not operationalized the underlying governance, risk assessment, and documentation requirements. With the final guidelines due in June 2026—and enforcement of h
DORA Audit Convergence in Funds: ESMA's New Supervisory Framework for CTOs
The European Securities and Markets Authority (ESMA) has set a May 2026 deadline for supervisory convergence on compliance and internal audit functions in the funds sector. For CTOs at asset managers and fund administrators, this initiative is not just another regulatory update—it is the first clear signal of how DORA’s ICT audit requirements will be enforced across borders. With harmonized expectations on the horizon, the time to align your audit program is now.
NIS2 Disclosure Deadlines: When Vendor Silence Becomes Your Liability
On 29 May 2026, eight critical CVEs land in your inbox—same day, different vendors. One issues a patch within hours; another imposes a 14-day embargo; a third goes silent. NIS2 Article 19(1) starts the 24-hour “awareness” clock, but whose awareness counts? When vendor timelines diverge, your legal exposure compounds. This is not a hypothetical. It is the first major test of NIS2’s disclosure regime, and the difference between compliance and a €10M fine hinges on how you sequence reporting when v
AI Act High-Risk Guidelines: Why Enforcement Starts Before Your Compliance Does
The European Commission’s draft *Guidelines on High-Risk AI Classification* land in May 2026—just three months before enforcement of the AI Act’s high-risk obligations begins. For CTOs, CISOs, and compliance leads, this timing is not a grace period. It is a warning: regulators will not wait for your audit to conclude before assessing whether your systems meet the law’s standards. The enforcement-compliance lag is real, and the gap is widening. Understanding how market surveillance authorities wi
NIS2 Article 21.2: Enforcing Vendor Disclosure SLAs When 8 Zero-Days Drop Simultaneously
On 29 May 2024, eight critical vulnerabilities surfaced across widely deployed enterprise software—three in VPN gateways, two in identity providers, and three in industrial control systems. For CISOs in essential and important entities under NIS2, the event was a stress test: not of technical response, but of contractual leverage over suppliers. When vendors missed disclosure timelines or failed to provide patches within agreed SLAs, security teams faced a dilemma—accept the risk or breach NIS2’
AI Act High-Risk Guidelines: Why Your Input Window Closes June 23—and What You're Missing
The European Commission’s targeted consultation on high-risk AI classification closes on **23 June 2026**—just weeks before the AI Act’s high-risk obligations take effect on **2 August 2026**. Yet most EU deployers are treating this deadline as a bureaucratic formality. That miscalculation could leave your organisation exposed to enforcement actions, reputational damage, and avoidable compliance costs. This article explains why the consultation is your last chance to shape the rules that will go
NIS2 Article 19: When Vendor Silence Breaks Your Incident Reporting Chain
A critical vulnerability surfaces in a widely used enterprise component. Your SOC flags it at 03:47 UTC on May 29. By 04:12, you’ve confirmed exploitation attempts against your infrastructure. At 04:30, you notify the vendor—only to receive radio silence. The 72-hour clock under NIS2 Article 19 is ticking, and your vendor’s non-disclosure is now your compliance risk. This scenario is not hypothetical; it is the reality for essential and important entities across the EU as NIS2 enforcement begins
When Your Subcontractor Is Hacked: GDPR Liability & Prevention After CNIL's Latest Breach Alerts
A single phishing email to your payroll provider. A misconfigured cloud bucket at your logistics partner. A ransomware attack on your marketing agency. In each case, the data belongs to your customers—and the liability belongs to you. CNIL’s May 2026 guidance on subcontractor-led breaches makes one point unmistakably clear: under GDPR, controllers cannot outsource accountability. This article breaks down the legal exposure, the recurring failure patterns CNIL identified, and the concrete steps C
AI Act High-Risk Systems: Building Audit-Ready Evidence Before June 2026
The EU AI Act’s high-risk provisions enter into force on 2 August 2026, but enforcement will begin with the first requests for documentation—not the last. Regulators will prioritise cases where evidence is missing, incomplete, or inconsistent. For CTOs and CISOs, this means compliance is not about ticking boxes; it is about constructing a defensible audit trail that proves conformity before the first inspection arrives.
NIS2 Article 18: Why Your Detection Tools Failed the May 2026 Cascade
The May 29, 2026 multi-vendor vulnerability cascade exposed critical gaps in detection capabilities across essential and important entities. While NIS2 Article 18 mandates "effective and continuous monitoring," many organizations discovered their SIEM/XDR deployments failed to detect exploit chains that national authorities later flagged during inspections. This article provides a framework for CTOs to audit and remediate detection blind spots before facing regulatory scrutiny.
Health Research Under GDPR: New CNIL Methodology Rules for 2026
The French data protection authority (CNIL) has overhauled its reference methodologies MR-001 and MR-003, introducing long-awaited flexibilities for health research while tightening accountability. For CTOs and DPOs in hospitals, biotech firms, and academic consortia, the 2026 update means both opportunity and risk: remote quality control, cross-border studies, and digital consent are now permitted—but only if existing research pipelines are audited against granular new requirements. Failure to
AI Act High-Risk Classification: Why You Need an Appeals Strategy Now
The EU AI Act’s high-risk classification framework is now law, yet the draft guidelines on classification lack any formal appeals or reclassification procedure. For CTOs and CISOs, this omission creates a compliance blind spot: if a regulator deems your AI system high-risk, you have no clear pathway to challenge the decision—only the certainty of costly obligations. With enforcement of high-risk provisions beginning in August 2026, the time to prepare an appeals strategy is now.
ESMA's New Audit Convergence Rules: What Fund Compliance Teams Must Do Now
ESMA’s May 2026 supervisory convergence guidance on compliance and internal audit in funds is not just another regulatory update—it is a warning shot. For fund managers already grappling with DORA’s ICT risk requirements, the guidance reveals systemic audit deficiencies that, if left unaddressed, will expose firms to heightened supervisory scrutiny and potential enforcement. Compliance officers and CTOs must act now to close these gaps before 2026 enforcement intensifies.
NIS2 Incident Response: Prioritizing 8 Critical Vulnerabilities Across Your Stack
A coordinated disclosure on 29 May 2026 reveals eight critical vulnerabilities spanning Linux kernels, enterprise databases, and monitoring tools. For NIS2-covered operators, this creates a compliance triage dilemma: patching under Article 23’s 24-hour reporting deadline while maintaining service continuity. This guide provides a sector-agnostic framework for CTOs and CISOs to classify, prioritize, and document remediation efforts—before auditors or regulators demand evidence.
When Your Subcontractor Breaches: GDPR Liability Chain & Prevention
A single misconfigured cloud bucket at a subcontractor can cascade into a €5M fine for your organisation—even if your own systems remain untouched. CNIL’s latest breach decisions reveal a troubling pattern: controllers are being held liable for processor failures they neither detected nor controlled. With GDPR’s joint-controller and processor liability provisions now routinely enforced, CTOs and CISOs must move beyond passive contractual protections to active technical and operational oversight
AI Act High-Risk Classification: What the Draft Guidelines Mean for Your Compliance Timeline
The European Commission’s May 2026 draft guidelines on high-risk AI classification mark the first official interpretation of Annex III of the EU AI Act. With the high-risk conformity assessment deadline set for 2 August 2026, CTOs and AI leads must act now to align their systems with the new criteria—or risk costly reclassification, audit delays, and potential enforcement actions. This article breaks down the key changes, their practical implications, and how to prepare your compliance timeline.
DORA Beyond Banks: How CCPs Must Operationalize ESMA's New Resolution Guidance
The European Securities and Markets Authority’s (ESMA) final report on CCP resolution tools, published in May 2026, does more than clarify recovery and resolution planning for central counterparties (CCPs). It exposes a critical gap in how CCPs interpret the Digital Operational Resilience Act (DORA): resolution-readiness is no longer a standalone exercise in financial continuity but a core component of ICT resilience. For CTOs and CISOs managing critical financial market infrastructure, this shi
NIS2 Critical Patch Cascade (May 29): CISO Triage & Reporting Obligations
On 29 May 2026, security teams across the EU’s essential and important sectors faced an unprecedented challenge: eight critical vulnerabilities disclosed simultaneously across core infrastructure components—Linux kernels, enterprise databases, and monitoring stacks. For CISOs and CTOs under NIS2, this "Critical Patch Tuesday" was not just a technical fire drill but a regulatory stress test. With NIS2’s 72-hour incident reporting clock ticking, the question was no longer *if* to patch, but *how*
IQVIA €5M Fine: What Health Data Warehouse Safeguards GDPR Now Requires
The French data protection authority (CNIL) imposed a €5 million fine on IQVIA in December 2023 for failing to implement adequate safeguards in its health data warehouse. The decision sends a clear message: GDPR’s Article 32 security obligations are not theoretical for repositories holding sensitive health information. For CTOs, DPOs, and compliance leads managing similar datasets, the case provides a concrete blueprint of what regulators now demand—technically and organizationally.
AI Act High-Risk Guidelines: Why Deployers Face Compliance Gaps
The EU AI Act’s high-risk classification system is designed to protect fundamental rights, but the May 2026 draft guidelines reveal a critical enforcement blind spot: deployers lack clear, actionable criteria to assess third-party AI systems before deployment. While providers bear primary responsibility for conformity assessments, deployers—whether financial institutions, healthcare providers, or industrial operators—remain liable for systems they integrate into critical operations. With enforce
DORA meets MiFID II: How compliance audits must evolve for sustainability reporting
The European Securities and Markets Authority (ESMA) has sent a clear signal: supervision of MiFID II sustainability disclosures will be "proportionate." For CTOs and compliance leads in investment firms and fund managers, this might sound like regulatory breathing room. It is not. The Digital Operational Resilience Act (DORA) remains unyielding on internal audit rigor, creating a compliance audit gap that demands immediate attention. Sustainability reporting is no longer a standalone ESG exerci
NIS2 Supply Chain Triage: Managing the May 2026 Vulnerability Cascade
The first week of May 2026 will see coordinated disclosures of critical vulnerabilities in widely deployed industrial control systems, network appliances, and cloud orchestration tools. For essential and important entities under NIS2, this is not a hypothetical scenario—it is the compliance deadline for implementing Article 21 technical measures while simultaneously managing supplier notification obligations. Failure to triage these vulnerabilities within the 72-hour window risks cascading servi
Cloud Providers Must Clarify Controller vs. Processor Status: CNIL's New Guidance
The French data protection authority (CNIL) published guidance in May 2026 that cuts to the heart of a long-standing ambiguity in cloud computing: who is the data controller, and who is the processor under GDPR? The answer has profound implications for liability, enforcement, and the very architecture of cloud-based data processing. Yet many organizations—both cloud providers and their customers—continue to operate under outdated or incorrect assumptions about their roles, exposing themselves to
AI Act High-Risk Classification: Why Deployers Face Urgent Compliance Gaps Before 2026
The EU AI Act’s high-risk classification framework arrives in August 2026, but deployers—entities using AI systems in critical sectors—are already exposed to enforcement risk. A €200 million fine against Temu in July 2024 for non-compliance with DSA transparency rules signals a broader regulatory shift: deployers, not just providers, are now accountable for third-party AI systems. With draft guidelines on high-risk classification published in May 2026, the ambiguity around deployer obligations i
DORA TLPT (TIBER-EU): How to Select a Red Team Provider for Financial Entities
Financial entities in the EU face a hard deadline: by 17 January 2025, Digital Operational Resilience Act (DORA) Article 26(8) requires them to have completed at least one threat-led penetration test (TLPT) if they are identified as “significant” by their competent authority. Even non-significant entities must still run TLPTs on a risk-based cycle. The only EU-harmonised framework for these tests is TIBER-EU, developed by the European Central Bank and now embedded in DORA Article 27. Selecting t
AI Act Foundation Model vs High-Risk System: A Decision Flow for AI Vendors
The EU AI Act introduces a tiered regulatory framework that treats general-purpose AI (GPAI) models and high-risk AI systems as distinct but potentially overlapping categories. For AI vendors, misclassification risks delayed market access, fines up to 35 million EUR or 7% of global turnover, and reputational damage. This article provides a visual decision flow to determine whether your AI system falls under GPAI obligations (Articles 53-55), high-risk obligations (Annex III), or both—along with
CRA SBOM Requirements: SPDX vs CycloneDX vs SWID — Which Format Wins? (mis à jour 07/2026)
The Cyber Resilience Act (CRA) mandates that manufacturers of digital products provide a machine-readable software bill of materials (SBOM) for every release. Annex I.2(1)(d) leaves the format open, but the choice carries long-term compliance, interoperability, and cost consequences. This article compares SPDX, CycloneDX, and SWID against the CRA’s requirements, maps them to the NTIA minimum elements, and recommends tooling for each major ecosystem. Mise à jour du 31/07/2026 : SWID a été retiré
GDPR + AI Act Overlap: Handling Data Subject Rights in AI Systems
The convergence of GDPR and the EU AI Act creates a complex operational landscape for AI deployers. When a data subject exercises rights under Articles 15-22 GDPR in relation to an AI system, DPOs must navigate explainability requirements, human review obligations, and the technical challenges of model retraining. This guide provides a concrete framework for compliance, focusing on the operational intersection of these two critical regulations.
NIS2 Essential vs Important Entity: Classification Checklist + Penalty Cap Matrix
NIS2 removes the old “operator of essential services” distinction and replaces it with two tiers—essential and important—based on sector, size, and systemic risk. Misclassification means either over-spending on compliance or facing enforcement that could reach 2 % of global turnover. This checklist gives CISOs, DPOs, and board members a single reference to determine their tier, understand the penalty caps, and meet the 17 October 2024 registration deadline.
DORA Register of Information: Template Spec + Mandatory Fields (Article 28)
The Digital Operational Resilience Act (DORA) transforms ICT third-party risk from a best practice into a supervisory reporting obligation. Article 28 requires every financial entity to maintain a "register of information" on all ICT third-party service providers—whether critical or not. This register is not a static spreadsheet; it is a living document that feeds into concentration-risk dashboards, exit-planning exercises, and annual supervisory filings. Below, we break down the exact field-lev
CRA Article 13(8) Vulnerability Handling Policy: Free Template for Manufacturers
The Cyber Resilience Act (CRA) enters into force on 10 December 2024, imposing strict vulnerability handling obligations on manufacturers of connected products. Article 13(8) requires a documented policy for coordinated disclosure and remediation of vulnerabilities—failure to comply risks fines up to €15 million or 2.5% of global turnover. This article provides a production-ready template aligned with CRA and ISO/IEC 30111, including a CVD process flow, severity-based SLAs, and ENISA reporting i
DORA Stress Testing Gets Simpler: What CTOs Need to Know About ESMA's MMF Guidance
The European Securities and Markets Authority (ESMA) has introduced a simplified approach to money market fund (MMF) stress test parameters, reducing the operational burden on fund managers. While this change primarily targets asset managers, CTOs across financial entities must understand its ripple effects on ICT resilience testing under DORA Chapter III. The guidance alters stress test frequency, scope, and documentation requirements—key components of your DORA compliance framework. This artic
NIS2 Patch SLAs Under Fire: How to Prove Timely Remediation in Audits
On 29 May 2026, eight critical vulnerabilities surfaced in a single day—two with active exploits, three in widely deployed industrial controllers, and one in a core library used by 60% of EU cloud providers. For CISOs and CTOs in essential and important entities, this wasn’t just another “Patch Tuesday.” It was the moment NIS2’s Article 21 technical measures shifted from theoretical obligation to enforceable audit requirement. By then, national CSIRTs had already begun cross-referencing vulnerab
CNIL's Updated Health Research Methodologies: What CTOs Must Know
The French data protection authority (CNIL) has expanded its reference methodologies MR-001 and MR-003 for health research in May 2026, introducing remote quality controls, cross-border study provisions, and stricter governance rules for identification data. For CTOs in biotech, pharma, and health-tech firms, these changes demand immediate technical audits of data processing pipelines—failure to align risks GDPR non-compliance fines up to €20 million or 4% of global turnover.
Audit Your AI Systems Against Draft High-Risk Guidelines: What Deployers Must Check Now
The European Commission’s **draft guidelines on high-risk AI classification** (published May 2026) are not just another consultation document—they are the closest thing to final rules deployers will get before the **EU AI Act’s high-risk obligations apply on 2 August 2026**. For CTOs, AI leads, and compliance teams, this is the moment to conduct an internal audit, identify systems that may fall under high-risk scope, and begin compiling compliance evidence. Waiting for the final guidelines is no
NIS2 Supplier Audit vs SOC 2: Why US frameworks miss EU Article 21.2
In the rapidly evolving landscape of cybersecurity regulations, EU entities face unique challenges when aligning their compliance efforts with existing frameworks. A common misconception is that a SOC 2 Type II report can serve as adequate proof of compliance with NIS2 supplier audit requirements. However, a bank relying solely on a SaaS vendor's SOC 2 report risks non-compliance under NIS2 Article 21.2, which mandates specific supplier vulnerability assessments, audit rights, and exit strategie
DORA Chapter V vs OCC Heightened Standards: transatlantic third-party convergence
In the complex landscape of financial regulation, global banks face the challenge of aligning compliance efforts across multiple jurisdictions. For those operating under both the EU's Digital Operational Resilience Act (DORA) and the US Office of the Comptroller of the Currency (OCC) Heightened Standards, there is potential to consolidate up to 70% of compliance evidence. This convergence is particularly evident in third-party risk management, where both regulatory frameworks share foundational
EU AI Act high-risk classification: practical decision tree for CTOs and CISOs
In a 2025 survey conducted by ENISA, it was revealed that 60% of CTOs misclassified their AI products as being out of scope of the EU AI Act. This misclassification could lead to significant compliance risks and financial penalties. Understanding whether your AI system falls under the high-risk category is crucial as the EU AI Act's high-risk provisions come into effect on 2 August 2026. This article provides a practical decision tree to help CTOs and CISOs determine if their AI systems are high
Cyber Resilience Act: SBOM and vulnerability handling for software vendors
The Cyber Resilience Act (CRA) is a transformative regulation for software vendors operating in the European Union. With fines reaching up to 15 million EUR or 2.5% of global turnover, the stakes are high for non-compliance. From 11 December 2027, software products must include a machine-readable Software Bill of Materials (SBOM) and a coordinated vulnerability disclosure policy. This article outlines the essential requirements and provides a blueprint for compliance.
China CSL and DSL vs EU NIS2: data localization conflict matrix for multinationals
In today's interconnected global landscape, multinational corporations often find themselves navigating complex regulatory environments across different jurisdictions. A European automotive manufacturer with research and development facilities in Shanghai, for instance, must comply with both the French National Cybersecurity Agency (ANSSI) and the Cyberspace Administration of China (CAC). This dual compliance scenario highlights the intricate challenges posed by the overlapping requirements of t
NIS2 Article 21: The 10 Security Measures — Implementation Checklist for EU Companies
As the NIS2 Directive approaches its enforcement date of 17 October 2024, EU companies must prepare to comply with its stringent security requirements. Article 21 of the directive outlines ten mandatory security measures that essential and important entities must implement. This guide provides a detailed checklist, mapping each requirement to practical technical controls, timelines, and evidence artefacts necessary for auditors.
GDPR Article 35 DPIA for AI Systems: Step-by-Step Guide for DPOs
The integration of Artificial Intelligence (AI) systems into business processes that involve personal data processing necessitates a careful examination of compliance obligations under the General Data Protection Regulation (GDPR). Specifically, Article 35 of the GDPR mandates a Data Protection Impact Assessment (DPIA) in certain circumstances. This guide provides a comprehensive overview for Data Protection Officers (DPOs) on when a DPIA is required for AI systems, how to structure it, and the
DORA ICT Incident Classification: Severity Matrix and Reporting Timelines
The Digital Operational Resilience Act (DORA) mandates that financial entities within the EU classify ICT incidents by severity and report major incidents to supervisory authorities. This article delves into the classification criteria, thresholds, and the reporting timeline of 4 hours, 24 hours, and 72 hours, ensuring compliance with DORA's stringent requirements.
AI Act Prohibited Practices: What Is Banned and When Enforcement Starts
The European Union's AI Act introduces stringent regulations on artificial intelligence, aiming to ensure ethical use and prevent harm. Title II of the Act explicitly bans certain AI practices, with enforcement of these prohibitions starting February 2025. This guide outlines these prohibitions, their scope, and the penalties for non-compliance, providing a roadmap for organizations to align their AI strategies with EU regulations.
NIS2 vs CIS Controls v8: Complete Mapping for CISOs
As the deadline for NIS2 compliance approaches, many organizations are evaluating their existing cybersecurity frameworks to ensure alignment with the new directive. For those already implementing CIS Controls v8, there is a significant overlap with NIS2 requirements, providing a head start. This article offers a detailed mapping between NIS2 Article 21 measures and CIS Controls v8, highlights areas where CIS Controls fall short, and prioritizes remediation efforts for organizations aiming to me
EU Data Act 2025: Key B2B Obligations for Product Manufacturers and Cloud Providers
The EU Data Act, which entered into force in September 2023 and will apply from September 2025, introduces significant changes for businesses across various sectors. It aims to facilitate data sharing, enhance competition, and empower users with greater control over data generated by connected devices. This article provides a comprehensive overview of the key obligations for product manufacturers and cloud providers under the new regulation.
GDPR Article 28 Processor Agreements: Practical Guide for Cloud Services
Every cloud service that processes personal data must have a Data Processing Agreement (DPA) compliant with GDPR Article 28. Such agreements are crucial for ensuring that data processors adhere to the GDPR's stringent requirements. This guide outlines the mandatory clauses, sub-processor management, audit rights, and the use of Standard Contractual Clauses (SCCs) for non-EU providers.
DORA ICT Third-Party Risk: Managing Critical Providers and the Oversight Framework
The Digital Operational Resilience Act (DORA) introduces a significant shift in how financial entities manage their ICT third-party risks, particularly focusing on Critical ICT Third-Party Providers (CTPPs). With the European Supervisory Authorities (ESAs) now directly supervising these providers, understanding the designation criteria, oversight framework, and contractual obligations is crucial for compliance and operational resilience. This article delves into these aspects, providing a compre
NIS2 Q1 2026 enforcement watch: what national authorities are actually fining
As the first quarter of 2026 draws to a close, the initial wave of NIS2 Directive enforcement actions has begun to take shape across the European Union. Competent authorities such as BSI in Germany, ANSSI in France, CNCS in Romania, and CCN in Spain have started publishing their enforcement actions, shedding light on the compliance landscape for essential entities. This article explores the key findings from these publications, identifies common compliance failures, and provides a practical resp
AI Act deployer vs provider: a 60-second quick reference
The EU AI Act introduces stringent requirements for both providers and deployers of high-risk AI systems. Misidentifying your role can lead to compliance failures, especially as the 2026 deadline for high-risk AI systems approaches. This guide provides a concise reference to help you determine whether you are a provider or a deployer under the AI Act, ensuring your organization meets its obligations.
CRA self-assessment vs third-party conformity: choose the right path
The Cyber Resilience Act (CRA) introduces a structured approach to assessing the conformity of software products within the EU. While many products fall under the self-assessment category, others require a more rigorous third-party conformity assessment. Understanding the criteria and requirements for each path is crucial for software vendors aiming to comply with the CRA. This article explores the self-assessment requirements and the conditions under which third-party conformity becomes mandato
GDPR DPIA and AI Act FRIA: the double impact assessment for AI systems
Deploying an AI system that processes personal data within the EU necessitates a dual approach to impact assessments, as mandated by GDPR Article 35 and AI Act Article 27. These assessments, known respectively as the Data Protection Impact Assessment (DPIA) and the Fundamental Rights Impact Assessment (FRIA), are crucial for ensuring compliance and safeguarding rights. This article explores how organizations can effectively combine these assessments to avoid redundancy and streamline compliance
NexCyber NIS2 Supplier Audit Playbook 2026 (premium)
The evolving landscape of cybersecurity regulations in the EU, particularly under the NIS2 Directive, necessitates a comprehensive approach to supplier management. Essential and important entities must ensure that their suppliers are compliant with stringent security requirements. Our premium dossier, the NexCyber NIS2 Supplier Audit Playbook 2026, provides a robust framework to navigate these complexities, offering tools such as a supplier risk scoring algorithm and a library of audit interview
NexCyber DORA Register of Information — EBA ITS-compliant template (premium)
The Digital Operational Resilience Act (DORA) is reshaping the landscape for financial entities across the EU, mandating robust frameworks to withstand, respond to, and recover from ICT-related disruptions. A critical component of compliance is maintaining a comprehensive Register of Information on ICT third-party service providers, as outlined by the European Banking Authority's (EBA) Implementing Technical Standards (ITS). NexCyber offers a premium, fully populated DORA register template, meti
NexCyber AI Act Classifier — decision matrix Annex III walkthrough (premium)
The EU AI Act introduces a comprehensive framework to regulate artificial intelligence systems, particularly those classified as high-risk under Annex III. For organizations deploying AI in sectors like HR tech, education tech, biometric ID, credit scoring, and law enforcement, understanding these categories is crucial. This guide provides a detailed walkthrough of the Annex III categories with practical examples, alongside a documentation kit to ensure compliance with Articles 11-15.
NexCyber CRA Vulnerability Handling Toolkit — SBOM + CVD + reporting (premium)
The Cyber Resilience Act (CRA) is set to transform the landscape of cybersecurity compliance for software vendors in the EU. With its stringent requirements for vulnerability handling and incident reporting, the CRA mandates a comprehensive approach to managing software vulnerabilities. NexCyber’s premium toolkit is designed to support software vendors in meeting these requirements, offering tools for SBOM generation, Coordinated Vulnerability Disclosure (CVD) policy development, and incident re
NexCyber 13×13 Multi-Regulation Matrix — full version (premium)
In the evolving landscape of European cybersecurity and data protection regulations, maintaining comprehensive compliance across multiple frameworks is a daunting task. The NexCyber 13×13 Multi-Regulation Matrix offers a robust solution, mapping 13 critical controls across 13 supplier types, with cross-references to NIS2, DORA, CRA, GDPR, and the AI Act. Used by over 40 EU clients, this premium tool consolidates compliance evidence, streamlining the audit process and enhancing regulatory alignme
NexCyber Cross-border Transfer Register — EU / China / US triple compliance (premium)
In the complex landscape of international data transfers, multinationals face the daunting task of navigating diverse regulatory frameworks. The NexCyber Cross-border Transfer Register offers a premium solution, providing a unified register that covers GDPR Standard Contractual Clauses (SCC), Schrems II supplementary measures, China's CAC standard contract, and the US Data Privacy Framework. This comprehensive tool, already utilized by 12 NexCyber Fortune 500 clients, includes a decision tree fo
NIS2 Article 21.2 in practice: the 13 by 13 supplier audit matrix
Navigating the complexities of NIS2 compliance, particularly Article 21.2, can be daunting and costly. While some consulting firms, such as KPMG, might charge upwards of 80,000 EUR for a comprehensive supplier audit, NexCyber offers a streamlined solution that automates this process in just two hours. This article delves into how NexCyber's innovative 13 by 13 supplier audit matrix simplifies compliance and ensures that competent authorities accept your supplier register.
EU AI Act crossed with ISO/IEC 42001: mapping guide for GenAI deployers
As the European Union's AI Act looms on the horizon, organizations deploying generative AI (GenAI) systems face the challenge of aligning with stringent regulatory requirements. Notably, ISO/IEC 42001:2023, the first AI management system standard, emerges as a valuable tool. This standard can potentially cover up to 60% of the high-risk obligations under the AI Act, particularly in the areas of risk and quality management. This article provides a detailed mapping guide to help GenAI deployers le
DORA TLPT (TIBER-EU): how to choose a certified red team provider
The Digital Operational Resilience Act (DORA) marks a significant shift in cybersecurity obligations for financial entities across the EU. With the first wave of Threat-Led Penetration Testing (TLPT) set to begin in January 2026, financial institutions must prepare to meet these stringent requirements. However, the current red team capacity within the EU may struggle to meet the anticipated demand, making the selection of a certified provider a critical task.
Healthcare under NIS2 essential entity: 90-day remediation playbook
In the first quarter of 2026, a significant milestone was reached in the enforcement of the NIS2 Directive when a healthcare provider faced a fine of 4.2 million EUR. This event underscored the urgent need for hospitals and pharmaceutical companies, classified as essential entities under NIS2 Annex I, to comply with the directive's stringent cybersecurity requirements. Many healthcare organizations missed the October 2024 implementation deadline, highlighting the necessity for a robust and pragm
Manufacturing under CRA and Machinery Regulation 2023/1230: double conformity
As the European Union continues to bolster its regulatory framework for cybersecurity and safety, manufacturers of industrial machines with digital control systems face a dual challenge. From January 2027, any connected CNC machine sold within the EU must adhere to two distinct CE conformity tracks: one under the Cyber Resilience Act (CRA) and the other under the updated Machinery Regulation 2023/1230. This dual conformity requirement necessitates a comprehensive understanding of both regulatory
EU Cyber Solidarity Act 2025: what changes for cyber MSPs in the Union
The EU Cyber Solidarity Act 2025 introduces significant opportunities for Managed Security Service Providers (MSSPs) in the European Union. By joining the European Cybersecurity Reserve, MSPs can receive up to 40% reimbursement for incident response costs in eligible cases. This initiative aims to bolster the Union's cyber resilience by enhancing collaboration and resource sharing among member states and private entities. Understanding the implications of this Act is crucial for MSPs looking to
NIS2 Article 20 board accountability: comparing cyber training providers
The Network and Information Security Directive 2 (NIS2) introduces a groundbreaking shift in cybersecurity governance across the European Union. For the first time, board members of essential entities face personal liability for cybersecurity failures. This directive mandates that management bodies not only approve risk measures but also undergo specific cybersecurity training. As we approach 2026, understanding the landscape of board-level cyber training programs becomes crucial for compliance
DORA Register of Information: Excel template vs SaaS — making the right technical choice
In the evolving landscape of financial regulations, compliance with the Digital Operational Resilience Act (DORA) is paramount for financial entities across the EU. One of Europe's largest insurers recently spent 14 months migrating 1,200 contracts from an Excel-based system to a Software as a Service (SaaS) solution for managing their register of ICT third-party arrangements. This transition underscores the complexities and strategic decisions involved in choosing the right technical solution f
AI Act general-purpose AI obligations: developer + deployer split and the 10^25 FLOP threshold
As the European Union moves towards implementing the AI Act, the distinction between developers and deployers of general-purpose AI (GPAI) systems becomes crucial, especially for those working with advanced models like Llama 4. Chapter V of the AI Act introduces specific obligations for GPAI providers, with additional responsibilities triggered when the training compute exceeds 10^25 floating-point operations per second (FLOPs). This article explores the implications for foundation model provide
China PIPL crossed with EU GDPR: cross-border transfers after Schrems II
In the wake of Schrems II, EU companies operating in China face a complex landscape for cross-border data transfers. With the introduction of China's Personal Information Protection Law (PIPL), a third layer of compliance is added to the already intricate requirements of the EU General Data Protection Regulation (GDPR). As of 2025, a significant portion of EU multinationals—estimated at 75%—have yet to complete the necessary Cybersecurity Administration of China (CAC) and GDPR transfer documenta
From CRA to Certificate : how a deterministic engine replaces 18-month audit cycles
A 28-page deep-dive into NexCyber's regulatory intelligence chain.
We explain how the deterministic intelligence chain maps 144 atomic obligations to product features, what makes the MRCC a new compliance standard, and why 0% LLM in compliance logic matters for audit defensibility.
Hybrid Ed25519 + ML-DSA-65 signatures on NexCyber MRCC : implementation notes
Why we shipped post-quantum cryptography on every certificate in May 2026.
NIST FIPS 204 (Category 3) signature scheme implementation notes covering liboqs integration, key sizes, performance benchmarks on signed Machine-Readable Compliance Certificates, and the rationale for hybrid Ed25519 + ML-DSA-65 over pure post-quantum at this stage of the EU regulatory cycle.
EU AI Act GPAI obligations enter force 2026-08-02 — what model providers must do
A 4-page regulatory brief for GPAI model providers.
Article 53 transparency, Article 55 systemic risk, EU AI Office reporting. Practical compliance steps for upstream model providers — open access.
IoT product CRA readiness — 34-point operator checklist
Step-by-step CRA compliance blueprint for connected device makers.
From SBOM generation to vulnerability disclosure procedures, this blueprint walks through every CRA obligation a digital product maker must close before 2027-12-11 enforcement.
How a 50-person fintech achieved DORA readiness in 6 weeks
Anonymized case study from our Design Partner Cohort 2026.
Email-gated full case study (15 pages). Preview : initial DORA gap analysis (62% readiness), 6-week sprint plan, final MRCC issuance.