Skip to content
Compliance › Compliance

Digital compliance: the EU digital rulebook, deadlines and who it applies to

Digital compliance in 2026 means GDPR, NIS2, DORA, the Cyber Resilience Act, the AI Act and the Data Act. See the verified deadlines, who each rule applies to and how to run them as one programme.

Seven EU digital rules shown as badges around one central compliance dashboard that manages them all

Table of Contents

    Ask five compliance leads what digital compliance covers and you'll get five different lists. Some start with GDPR. Others start with the NIS2 Directive, because that's what the board asks about. In product companies it's the Cyber Resilience Act, now that its reporting duty went live on 11 September 2026.

    They're all right, and that's the problem. In under a decade the EU has adopted a whole rulebook of digital laws, each with its own definitions, deadlines and supervisors. An organisation with 50 or more staff is rarely caught by just one.

    This guide covers what each law regulates, when it applies (checked against EUR-Lex) and who it hits, then shows how to run the rules as one programme instead of seven projects.

    The short answer: what does digital compliance mean in 2026?

    Digital compliance is the set of EU rules that govern how an organisation handles data, IT systems, digital products and AI. For most European organisations with 50+ staff, four of them matter today: GDPR (whenever you process personal data), NIS2 (if you sit in one of its sectors and meet the size threshold), the AI Act (if you use or build AI) and the Data Act (if you make connected products or buy cloud services). DORA applies only to the financial sector, and CER only to entities that authorities designate as critical. The Cyber Resilience Act applies to anyone placing products with digital elements on the EU market, with reporting from 11 September 2026 and full application from 11 December 2027. The efficient answer is not seven projects but one programme with a shared risk method, one asset register, one incident process and one supplier programme.

    Three kinds of rules that get mixed up

    Most overviews line the rules up as if they were variations of the same thing. They aren't. They regulate different objects, and that decides who owns them.

    Category Rules What is regulated Typical owner
    Organisation rules GDPR, NIS2, CER, DORA How the organisation manages risk, security, incidents and suppliers DPO, CISO, compliance, executive team
    Product rules Cyber Resilience Act, AI Act (for providers) Whether a product or AI system may be sold in the EU, with CE marking and technical documentation Product, engineering, quality
    Use rules AI Act (for deployers) How you use AI systems that others have built Business units, HR, IT, DPO
    Data and market rules Data Act, DSA, DMA Access to data, cloud switching, platform duties and competition Legal, product, procurement
    Identity rules eIDAS2 Digital identity, the EU wallet and trust services IT, customer service, digital

    Organisation rules need a management system that runs all year. Product rules need documentation per product and a vulnerability process for the whole support life.

    One more distinction matters in EU digital regulation. GDPR, DORA, the CRA, the AI Act, the Data Act and eIDAS2 are regulations and apply directly. NIS2 and CER are directives, so what binds you is the national law that transposes them.

    The timeline: deadlines from 2018 to 2028

    Dates are checked against the legal texts and, for the AI Act, against the amending Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026. Current as of 24 September 2026.

    Date Rule What happens
    25 May 2018GDPRRegulation applies (adopted 27 April 2016, in force 24 May 2016)
    18 October 2024NIS2 and CERNational transposing measures were due to apply
    17 January 2025DORARegulation applies to financial entities
    2 February 2025AI ActProhibitions (Art. 5) and AI literacy (Art. 4)
    2 August 2025AI ActGeneral-purpose AI model rules, governance and penalties
    12 September 2025Data ActRegulation applies (Art. 50)
    17 July 2026CERDeadline for Member States to identify critical entities (Art. 6(1))
    2 August 2026AI ActGeneral application, including the Art. 50 transparency duties
    11 September 2026Cyber Resilience ActReporting of actively exploited vulnerabilities and severe incidents (Art. 14), including for products already on the market
    12 September 2026Data ActAccess-by-design duty (Art. 3(1)) for newly marketed connected products
    2 December 2026AI ActMarking of AI-generated content for systems on the market before 2 August 2026
    24 December 2026eIDAS2Member States must provide a European Digital Identity Wallet
    12 January 2027Data ActCloud providers may no longer charge switching fees (Art. 29)
    2 December 2027AI ActHigh-risk obligations for Annex III systems (e.g. recruitment, credit scoring)
    11 December 2027Cyber Resilience ActFull application, including the essential requirements in Annex I and CE marking
    24 December 2027eIDAS2Private services required to use strong user authentication must accept the wallet (Art. 5f)
    2 August 2028AI ActHigh-risk obligations for AI embedded in Annex I products (e.g. machinery, medical devices)

    Two things stand out. The 2 August 2026 deadline for high-risk AI is gone, though the transparency duties started then as planned. And CRA reporting already covers products you sold before 2027 (Art. 69(3)), even though the rest of the regulation only applies from 11 December 2027.

    Timeline 2018 to 2028 with deadlines for GDPR, NIS2, DORA, the AI Act, the Data Act, eIDAS2 and the CRA, with 11 September 2026 highlighted

    Who each rule applies to

    Fines are the maximum administrative fines in the texts. Where penalties are left to Member States, national law sets the amount.

    Rule In scope Supervised by Maximum fine
    GDPRControllers and processors handling personal data of people in the EU/EEA (Art. 3)National data protection authoritiesEUR 20m / 4% (Art. 83(5))
    NIS2Medium and large entities in the Annex I and II sectors, some regardless of sizeNational competent authorities and CSIRTsEUR 10m / 2% (essential), EUR 7m / 1.4% (important), Art. 34
    CEREntities designated as critical in 11 sectorsNational competent authoritiesSet nationally (Art. 22)
    DORABanks, insurers, investment firms, payment institutions and other financial entities (Art. 2)Financial supervisors, ESAs for critical ICT providersSet nationally (Art. 50)
    Cyber Resilience ActManufacturers, importers and distributors of products with digital elementsMarket surveillance authorities, CSIRTs and ENISA for reportsEUR 15m / 2.5% (Art. 64(2))
    AI ActProviders and deployers of AI systems, importers and distributorsNational market surveillance authorities, AI Office for GPAIEUR 35m / 7% for prohibited AI (Art. 99(3))
    Data ActMakers of connected products, data holders, cloud providers and their customersNational competent authoritiesSet nationally (Art. 40)

    The same organisation can be a controller under GDPR, an important entity under NIS2, a manufacturer under the CRA, a data holder under the Data Act and a deployer under the AI Act. Five roles, five sets of duties.

    GDPR: the foundation under everything

    GDPR catches almost every organisation. Its core is the seven principles in Article 5, ending with accountability: you must be able to demonstrate compliance with the other six.

    That evidence rests on the controller's record of processing activities under Article 30, appropriate technical and organisational measures under Article 32, and data protection by design and by default under Article 25. A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware of it (Article 33). Data subjects must be told without undue delay where the breach is likely to result in a high risk to them (Article 34).

    Your record and risk assessments are the best raw material when NIS2, the Data Act and the AI Act ask which systems and data you hold. The Data Omnibus package could amend parts of GDPR, but it hadn't been adopted as of September 2026.

    The NIS2 Directive and national transposition

    The NIS2 Directive (Directive (EU) 2022/2555) had to be transposed by 17 October 2024. Many Member States were late. The Commission sent reasoned opinions to 19 of them on 7 May 2025 and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice. Check the Commission's transposition page for each country you operate in.

    Scope turns on sector and size. Entities in Annex I (such as energy, transport, banking, health, digital infrastructure and public administration) and Annex II (such as postal services, waste, food, manufacturing and digital providers) are in scope if they are at least medium-sized, broadly 50 staff or more than EUR 10 million in turnover and balance sheet. Some are covered regardless of size.

    Suppliers are not directly in scope of NIS2. An IT vendor or a cleaning company doesn't become a NIS2 entity because its customer is one. Suppliers are affected indirectly, because in-scope entities must secure their supply chain under Article 21(2)(d) and pass requirements down through contracts and supplier assessments. A supplier is only covered in its own right if it sits in an annexed sector and meets the size test, for example as a managed service provider.

    The obligations are the ten minimum measures in Article 21(2), management body accountability and training in Article 20, and three-stage reporting in Article 23. For more detail, see our NIS2 introduction and our comparison of NIS2 and ISO 27001.

    On 20 January 2026 the Commission proposed targeted NIS2 amendments, including a new small mid-cap category and an entity-level cyber posture certificate. They haven't been adopted, so the current national laws still apply.

    CER: the physical twin of NIS2

    The Critical Entities Resilience Directive (Directive (EU) 2022/2557) covers physical resilience against sabotage, natural hazards, power failures and terrorism, where NIS2 covers network and information systems.

    CER only applies to entities that Member States designate. The designation deadline was 17 July 2026 (Art. 6(1)). Once notified, an entity has nine months for its own risk assessment (Art. 12) and ten months to put resilience measures in place (Art. 13). An entity designated as critical under CER is treated as an essential entity under NIS2.

    DORA: the financial sector's specific regime

    DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and is the specific regime for financial entities. For them it takes precedence over NIS2's risk management and reporting rules.

    DORA requires a documented ICT risk management framework that the management body approves and is accountable for (Articles 5 and 6), classification and reporting of major ICT-related incidents (Articles 17 to 19), digital operational resilience testing (Articles 24 and 25) and threat-led penetration testing (TLPT) for selected entities at least every three years (Article 26). On top of that comes ICT third-party risk management, with a register of information and mandatory contract terms (Articles 28 to 30).

    On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers for direct EU oversight. Financial entities must still manage the risk those providers pose.

    Cyber Resilience Act: when the product itself is regulated

    The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. It covers products with digital elements: hardware and software with a data connection to a device or network, from routers and smart meters to installable software and apps.

    Pure SaaS is generally out of scope. Remote data processing is only covered where the product needs it to perform a function. Medical devices, vehicles, aviation and marine equipment have their own rules and are excluded.

    From 11 September 2026 manufacturers must report through ENISA's Single Reporting Platform (Art. 14). The duty covers two things, and precision matters here:

    • Actively exploited vulnerabilities: an early warning within 24 hours, a vulnerability notification within 72 hours and a final report no later than 14 days after a corrective or mitigating measure is available.
    • Severe incidents affecting the product's security: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month of the notification.

    So the 24-hour clock doesn't apply to every serious vulnerability you find, only to actively exploited ones and to severe incidents. Reports go to the coordinating CSIRT and to ENISA at the same time.

    From 11 December 2027 the rest applies: the essential cybersecurity requirements in Annex I, vulnerability handling for the whole support period, technical documentation, conformity assessment and CE marking. Critical product categories need third-party assessment. Breaching the essential requirements or Articles 13 and 14 can cost up to EUR 15 million or 2.5% of worldwide turnover (Art. 64(2)). The Commission published practical CRA guidance on 27 July 2026.

    CRA reporting in two tracks: early warning in 24 hours, notification in 72 hours, final report after 14 days or one month, to CSIRT and ENISA

    The AI Act after the 2026 amendment

    The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. It was amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026. It removes no obligations but moves the high-risk deadlines and softens the AI literacy duty.

    The Article 5 prohibitions have applied since 2 February 2025. Article 4 now requires providers and deployers to take measures to support AI literacy among their staff, rather than to ensure a given level. The Article 50 transparency duties apply from 2 August 2026. High-risk obligations apply from 2 December 2027 for Annex III systems, such as AI used in recruitment, and from 2 August 2028 for AI embedded in products under Annex I.

    National market surveillance authorities supervise AI systems and the Commission's AI Office supervises general-purpose AI models. Our AI Act guide explains the roles, and if you deploy high-risk AI in public services or for credit scoring, Article 27 requires a fundamental rights impact assessment.

    Data Act: not a security law

    The Data Act (Regulation (EU) 2023/2854) belongs in digital compliance, but it isn't about IT security. It governs who is entitled to data from connected products and the right to switch cloud provider.

    It has applied since 12 September 2025. Users of connected products, consumers and businesses alike, can demand access to the data the product generates and have it shared with a third party (Articles 4 and 5). From 12 September 2026 new products must be designed so data is accessible to the user by default (Art. 3(1)). Cloud customers can switch provider, and from 12 January 2027 providers may not charge for the switch (Art. 29).

    Rules on unfair B2B contract terms apply to contracts concluded after 12 September 2025, and from 12 September 2027 to certain older ones. For compliance teams this is mostly legal and procurement work on vendor contracts.

    eIDAS2, DSA and DMA in brief

    eIDAS2 (Regulation (EU) 2024/1183) obliges Member States to offer a European Digital Identity Wallet by 24 December 2026. Private services that must use strong user authentication by law or contract, such as banks, insurers and telecoms, must accept it by 24 December 2027 (Art. 5f).

    The DSA and DMA mainly target online platforms and gatekeepers. Unless you run a marketplace or a platform with user content, they are rarely your main workload.

    UK organisations aren't bound by these laws at home, but GDPR, the CRA and the AI Act reach businesses that sell into the EU. The UK's own Cyber Security and Resilience Bill was still before Parliament at the time of writing.

    Five reporting clocks, one incident process

    One ransomware attack on a system holding customer data can start several clocks at once, each with its own recipient and trigger.

    Rule Trigger Deadlines Recipient
    GDPR Art. 33Personal data breach72 hoursData protection authority
    NIS2 Art. 23Significant incident24 hours, 72 hours, 1 monthCSIRT or competent authority
    DORA Art. 19Major ICT-related incident4 hours after classification (24 hours at the latest), 72 hours, 1 monthFinancial supervisor
    CRA Art. 14Actively exploited vulnerability or severe incident in a product24 hours, 72 hours, 14 days or 1 monthCoordinating CSIRT and ENISA
    CER Art. 15Incident disrupting an essential service24 hours, 1 monthCompetent authority

    The DORA timings sit in Delegated Regulation (EU) 2025/301. The answer is one incident process with one triage step: Is personal data involved? Is it significant under NIS2? Is it our own product? The answers decide which clocks run. Our article on security breaches goes deeper on the GDPR side.

    The Digital Omnibus proposes a single reporting entry point. Until it exists, you report to each recipient separately.

    One incident branching into four reporting clocks for GDPR, NIS2, DORA and the CRA, each with its deadlines and recipient

    How to run digital compliance as one programme

    Most of these rules ask for the same groundwork in different formats. Here is the sequence we see working.

    1. Map your role under each rule

    Record whether you're in scope and in which role: controller, processor, essential or important entity, manufacturer, deployer or data holder.

    2. Build one register of assets, systems and data

    Your GDPR Article 30 record, asset management under NIS2 Article 21(2)(i) and DORA Article 8, and your AI inventory can be one register with different fields.

    3. Use one risk method

    GDPR Article 32, NIS2 Article 21, DORA Article 6, AI Act Article 9 and CRA Article 13 all require risk assessment, and one method (often ISO/IEC 27005) can serve them all. We've described how one risk method can cover many obligations.

    4. Pick a control framework as the backbone

    ISO/IEC 27001:2022 isn't law, but its 93 Annex A controls cover much of the technical and organisational ground in NIS2, DORA and GDPR Article 32. ENISA has published a mapping between the NIS2 Implementing Regulation (EU) 2024/2690 and ISO 27001. It's a navigation aid, not a statement of equivalence. Read more about ISO 27001 certification.

    5. Run incidents and suppliers as one process each

    One incident process with the clocks from the table, and one supplier programme covering data processing agreements under GDPR Article 28, supply chain security under NIS2 Article 21(2)(d), ICT third-party risk under DORA Article 28 and cloud contracts under the Data Act.

    6. Give the board one picture and one calendar

    NIS2 Article 20 and DORA Article 5 put accountability on the management body. Give it one report across the rules and one compliance calendar, so the deadlines become tasks with an owner.

    Matrix linking six building blocks of one programme to the GDPR, NIS2, DORA, AI Act, CRA and Data Act articles each block serves

    A worked example: five rules in one company

    Corrib Metering Ltd and Aoife Byrne are fictional. We invented them for this article, and they are neither customers nor a case study.

    Corrib Metering is an Irish company with 180 staff and EUR 30 million in turnover. It makes smart heat meters for district heating operators across the EU and runs a platform where operators read consumption. HR uses an AI tool to screen applicants. Aoife Byrne, head of compliance, has to work out what applies.

    She starts with roles. Household consumption data is personal data, so Corrib is a GDPR controller and a processor for its customers. The meters are products with digital elements, so Corrib is a manufacturer under the CRA with a reporting duty since 11 September 2026. The meters are connected products, so Corrib is a data holder under the Data Act. The recruitment tool is high-risk under Annex III, so Corrib is a deployer with obligations from 2 December 2027.

    NIS2 is where Aoife first goes wrong. She assumes Corrib is covered because its customers are energy operators. That isn't the reason, because suppliers aren't covered as such. Corrib falls within scope because manufacturing of computer, electronic and optical products is an Annex II sector, and with 180 staff it is medium-sized. That makes it an important entity. The catch: when the Commission referred Ireland to the Court of Justice in July 2026, Ireland hadn't notified full transposition, so Aoife must check which national law binds Corrib today. The CRA, Data Act, AI Act and GDPR apply directly regardless.

    Building block GDPR NIS2 CRA Data Act AI Act
    Register of systems and data✓✓✓✓✓
    Shared risk method✓✓✓✗✓
    Incident and vulnerability process✓✓✓✗✗
    Supplier and contract programme✓✓✓✓✓
    Training and board reporting✓✓✗✗✓

    Aoife's conclusion is that five rules need five building blocks, not 25. CRA reporting already applies, so the meters' vulnerability process comes first, linked to the NIS2 incident process. Then Data Act design for the next meter generation. AI recruitment and CRA conformity assessment are planned towards December 2027.

    With 40 staff and turnover under EUR 10 million, NIS2 wouldn't apply, but the CRA, the Data Act and GDPR still would. Roles and products decide digital compliance, not industry labels.

    What digital compliance is not

    Three caveats. An ISO 27001 certificate isn't NIS2 compliance, and it doesn't cover the Data Act or the AI Act's requirements for documentation and human oversight. National labels, such as the Danish D-seal, are voluntary schemes rather than law, and we've compared the D-seal and ISO 27001 separately.

    No software makes you compliant. A tool tracks requirements, tasks and evidence, but assessments and accountability stay with you. And the rules keep moving. The Data Omnibus and the NIS2 amendment proposal could change deadlines and scope in 2027 and 2028. Build to the obligations and treat future dates as provisional until they appear in the Official Journal.

    How .legal supports one joined-up programme

    The practical challenge in digital compliance is documenting the same work twice. Our Frameworks module lets you map one control or task, such as your annual risk assessment or your supplier review, to the requirements in GDPR, NIS2, ISO 27001 and the AI Act that it satisfies. Once the task is done, you can see it across the frameworks.

    Risk assessments sit in the risk module, suppliers and processors in Vendor Management, and the timeline deadlines can go into compliance task management with an owner each. To see it with your own rules, book a demo.

    Frequently Asked Questions about Digital Compliance

    What does digital compliance mean?

    Digital compliance means meeting the rules that apply to an organisation's data, IT systems, digital products and use of AI. In the EU that typically covers GDPR, NIS2, DORA, the Cyber Resilience Act, the AI Act and the Data Act. It isn't a legal category but a practical umbrella term. Which rules apply to you depends on your roles, such as controller, NIS2 entity, manufacturer or AI deployer.

    Which EU digital regulations apply to my organisation?

    Start with roles, not sectors. GDPR applies if you process personal data. NIS2 applies through national law if you're a medium or large entity in an Annex I or II sector. The AI Act applies if you build or use AI systems, the Data Act if you make connected products or buy cloud services, and the Cyber Resilience Act if you place products with digital elements on the EU market. DORA is limited to financial entities.

    Are suppliers covered by NIS2?

    Not simply by being suppliers. A vendor doesn't become a NIS2 entity because its customer is one. It feels the rules through customer requirements, because in-scope entities must manage supply chain security under Article 21(2)(d). That usually means contract clauses, questionnaires and audits. A supplier can still be covered in its own right if it operates in one of the directive's sectors and meets the size threshold.

    When does the Cyber Resilience Act apply?

    The Cyber Resilience Act entered into force on 10 December 2024 and applies in stages. Rules on notified bodies apply from 11 June 2026. The duty to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026, including for products already sold. The essential cybersecurity requirements, CE marking and the rest of the regulation apply from 11 December 2027.

    Does the Cyber Resilience Act apply to SaaS?

    Generally not. The Cyber Resilience Act regulates products with digital elements, meaning hardware and software supplied to the user. Pure SaaS accessed only through a browser isn't such a product. Remote data processing is covered only where a product needs it to perform its functions, for example the cloud backend of an app or a connected device. SaaS providers may instead fall under NIS2 as digital providers.

    Have the AI Act's high-risk rules been delayed?

    Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the dates. High-risk obligations now apply from 2 December 2027 for Annex III systems, such as AI in recruitment and credit scoring, and from 2 August 2028 for AI embedded in Annex I products. The prohibitions, transparency duties and general-purpose AI rules were not postponed.

    What is the difference between NIS2 and DORA?

    NIS2 is a directive covering many sectors and applies through national transposing laws. DORA is a regulation that applies directly and only to financial entities. For them, DORA takes precedence over NIS2's risk management and reporting rules. DORA goes further on ICT third-party risk, the register of information and threat-led penetration testing. Supervision sits with financial supervisors for DORA and with NIS2 competent authorities otherwise.

    What is the EU digital rulebook?

    The EU digital rulebook is a shorthand for the laws the EU has adopted to regulate data, cybersecurity, AI and digital markets. It includes GDPR, NIS2, CER, DORA, the Cyber Resilience Act, the AI Act, the Data Act, eIDAS2, the DSA and the DMA. The Commission is now simplifying parts of it through omnibus packages, starting with the AI Act amendment adopted in July 2026.

    Do EU digital rules apply to UK companies?

    Several do when UK companies deal with the EU. GDPR applies to organisations offering goods or services to people in the EU or monitoring them there. The Cyber Resilience Act applies to any product with digital elements placed on the EU market, wherever the manufacturer sits. The AI Act covers providers placing AI systems on the EU market and cases where AI output is used in the EU.

    Can ISO 27001 cover several EU regulations at once?

    Partly. ISO/IEC 27001:2022 is a voluntary standard, but its management system and 93 controls give a common frame for much of the technical and organisational ground in NIS2, DORA and GDPR Article 32. It doesn't cover legal duties such as reporting deadlines, registration, Data Act rights or the AI Act's product requirements. Use it as the backbone and add each rule's specific requirements on top.

    Still unsure?

    Ask Johannes directly, he runs most demos personally

    Book him here
    Processing activities

    .legal compliance platform

    Master Digital Compliance with .legal

    • Centralized management of multiple digital regulations
    • Automated monitoring and compliance tracking
    • Built-in frameworks for GDPR, DSA, and NIS2
    • Real-time compliance status dashboards
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell