Compliance › Software
GRC Software
Modules
.legal AI
All AI features →Integrations
See all integrations →Platform & features
Understand the rules
See it in action
All customer stories →Plan your switch
Stay up to date
Ask five compliance leads what digital compliance covers and you'll get five different lists. Some start with GDPR. Others start with the NIS2 Directive, because that's what the board asks about. In product companies it's the Cyber Resilience Act, now that its reporting duty went live on 11 September 2026.
They're all right, and that's the problem. In under a decade the EU has adopted a whole rulebook of digital laws, each with its own definitions, deadlines and supervisors. An organisation with 50 or more staff is rarely caught by just one.
This guide covers what each law regulates, when it applies (checked against EUR-Lex) and who it hits, then shows how to run the rules as one programme instead of seven projects.
Digital compliance is the set of EU rules that govern how an organisation handles data, IT systems, digital products and AI. For most European organisations with 50+ staff, four of them matter today: GDPR (whenever you process personal data), NIS2 (if you sit in one of its sectors and meet the size threshold), the AI Act (if you use or build AI) and the Data Act (if you make connected products or buy cloud services). DORA applies only to the financial sector, and CER only to entities that authorities designate as critical. The Cyber Resilience Act applies to anyone placing products with digital elements on the EU market, with reporting from 11 September 2026 and full application from 11 December 2027. The efficient answer is not seven projects but one programme with a shared risk method, one asset register, one incident process and one supplier programme.
Most overviews line the rules up as if they were variations of the same thing. They aren't. They regulate different objects, and that decides who owns them.
| Category | Rules | What is regulated | Typical owner |
|---|---|---|---|
| Organisation rules | GDPR, NIS2, CER, DORA | How the organisation manages risk, security, incidents and suppliers | DPO, CISO, compliance, executive team |
| Product rules | Cyber Resilience Act, AI Act (for providers) | Whether a product or AI system may be sold in the EU, with CE marking and technical documentation | Product, engineering, quality |
| Use rules | AI Act (for deployers) | How you use AI systems that others have built | Business units, HR, IT, DPO |
| Data and market rules | Data Act, DSA, DMA | Access to data, cloud switching, platform duties and competition | Legal, product, procurement |
| Identity rules | eIDAS2 | Digital identity, the EU wallet and trust services | IT, customer service, digital |
Organisation rules need a management system that runs all year. Product rules need documentation per product and a vulnerability process for the whole support life.
One more distinction matters in EU digital regulation. GDPR, DORA, the CRA, the AI Act, the Data Act and eIDAS2 are regulations and apply directly. NIS2 and CER are directives, so what binds you is the national law that transposes them.
Dates are checked against the legal texts and, for the AI Act, against the amending Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026. Current as of 24 September 2026.
| Date | Rule | What happens |
|---|---|---|
| 25 May 2018 | GDPR | Regulation applies (adopted 27 April 2016, in force 24 May 2016) |
| 18 October 2024 | NIS2 and CER | National transposing measures were due to apply |
| 17 January 2025 | DORA | Regulation applies to financial entities |
| 2 February 2025 | AI Act | Prohibitions (Art. 5) and AI literacy (Art. 4) |
| 2 August 2025 | AI Act | General-purpose AI model rules, governance and penalties |
| 12 September 2025 | Data Act | Regulation applies (Art. 50) |
| 17 July 2026 | CER | Deadline for Member States to identify critical entities (Art. 6(1)) |
| 2 August 2026 | AI Act | General application, including the Art. 50 transparency duties |
| 11 September 2026 | Cyber Resilience Act | Reporting of actively exploited vulnerabilities and severe incidents (Art. 14), including for products already on the market |
| 12 September 2026 | Data Act | Access-by-design duty (Art. 3(1)) for newly marketed connected products |
| 2 December 2026 | AI Act | Marking of AI-generated content for systems on the market before 2 August 2026 |
| 24 December 2026 | eIDAS2 | Member States must provide a European Digital Identity Wallet |
| 12 January 2027 | Data Act | Cloud providers may no longer charge switching fees (Art. 29) |
| 2 December 2027 | AI Act | High-risk obligations for Annex III systems (e.g. recruitment, credit scoring) |
| 11 December 2027 | Cyber Resilience Act | Full application, including the essential requirements in Annex I and CE marking |
| 24 December 2027 | eIDAS2 | Private services required to use strong user authentication must accept the wallet (Art. 5f) |
| 2 August 2028 | AI Act | High-risk obligations for AI embedded in Annex I products (e.g. machinery, medical devices) |
Two things stand out. The 2 August 2026 deadline for high-risk AI is gone, though the transparency duties started then as planned. And CRA reporting already covers products you sold before 2027 (Art. 69(3)), even though the rest of the regulation only applies from 11 December 2027.

Fines are the maximum administrative fines in the texts. Where penalties are left to Member States, national law sets the amount.
| Rule | In scope | Supervised by | Maximum fine |
|---|---|---|---|
| GDPR | Controllers and processors handling personal data of people in the EU/EEA (Art. 3) | National data protection authorities | EUR 20m / 4% (Art. 83(5)) |
| NIS2 | Medium and large entities in the Annex I and II sectors, some regardless of size | National competent authorities and CSIRTs | EUR 10m / 2% (essential), EUR 7m / 1.4% (important), Art. 34 |
| CER | Entities designated as critical in 11 sectors | National competent authorities | Set nationally (Art. 22) |
| DORA | Banks, insurers, investment firms, payment institutions and other financial entities (Art. 2) | Financial supervisors, ESAs for critical ICT providers | Set nationally (Art. 50) |
| Cyber Resilience Act | Manufacturers, importers and distributors of products with digital elements | Market surveillance authorities, CSIRTs and ENISA for reports | EUR 15m / 2.5% (Art. 64(2)) |
| AI Act | Providers and deployers of AI systems, importers and distributors | National market surveillance authorities, AI Office for GPAI | EUR 35m / 7% for prohibited AI (Art. 99(3)) |
| Data Act | Makers of connected products, data holders, cloud providers and their customers | National competent authorities | Set nationally (Art. 40) |
The same organisation can be a controller under GDPR, an important entity under NIS2, a manufacturer under the CRA, a data holder under the Data Act and a deployer under the AI Act. Five roles, five sets of duties.
GDPR catches almost every organisation. Its core is the seven principles in Article 5, ending with accountability: you must be able to demonstrate compliance with the other six.
That evidence rests on the controller's record of processing activities under Article 30, appropriate technical and organisational measures under Article 32, and data protection by design and by default under Article 25. A personal data breach must be notified to the supervisory authority within 72 hours of becoming aware of it (Article 33). Data subjects must be told without undue delay where the breach is likely to result in a high risk to them (Article 34).
Your record and risk assessments are the best raw material when NIS2, the Data Act and the AI Act ask which systems and data you hold. The Data Omnibus package could amend parts of GDPR, but it hadn't been adopted as of September 2026.
The NIS2 Directive (Directive (EU) 2022/2555) had to be transposed by 17 October 2024. Many Member States were late. The Commission sent reasoned opinions to 19 of them on 7 May 2025 and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice. Check the Commission's transposition page for each country you operate in.
Scope turns on sector and size. Entities in Annex I (such as energy, transport, banking, health, digital infrastructure and public administration) and Annex II (such as postal services, waste, food, manufacturing and digital providers) are in scope if they are at least medium-sized, broadly 50 staff or more than EUR 10 million in turnover and balance sheet. Some are covered regardless of size.
Suppliers are not directly in scope of NIS2. An IT vendor or a cleaning company doesn't become a NIS2 entity because its customer is one. Suppliers are affected indirectly, because in-scope entities must secure their supply chain under Article 21(2)(d) and pass requirements down through contracts and supplier assessments. A supplier is only covered in its own right if it sits in an annexed sector and meets the size test, for example as a managed service provider.
The obligations are the ten minimum measures in Article 21(2), management body accountability and training in Article 20, and three-stage reporting in Article 23. For more detail, see our NIS2 introduction and our comparison of NIS2 and ISO 27001.
On 20 January 2026 the Commission proposed targeted NIS2 amendments, including a new small mid-cap category and an entity-level cyber posture certificate. They haven't been adopted, so the current national laws still apply.
The Critical Entities Resilience Directive (Directive (EU) 2022/2557) covers physical resilience against sabotage, natural hazards, power failures and terrorism, where NIS2 covers network and information systems.
CER only applies to entities that Member States designate. The designation deadline was 17 July 2026 (Art. 6(1)). Once notified, an entity has nine months for its own risk assessment (Art. 12) and ten months to put resilience measures in place (Art. 13). An entity designated as critical under CER is treated as an essential entity under NIS2.
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and is the specific regime for financial entities. For them it takes precedence over NIS2's risk management and reporting rules.
DORA requires a documented ICT risk management framework that the management body approves and is accountable for (Articles 5 and 6), classification and reporting of major ICT-related incidents (Articles 17 to 19), digital operational resilience testing (Articles 24 and 25) and threat-led penetration testing (TLPT) for selected entities at least every three years (Article 26). On top of that comes ICT third-party risk management, with a register of information and mandatory contract terms (Articles 28 to 30).
On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers for direct EU oversight. Financial entities must still manage the risk those providers pose.
The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. It covers products with digital elements: hardware and software with a data connection to a device or network, from routers and smart meters to installable software and apps.
Pure SaaS is generally out of scope. Remote data processing is only covered where the product needs it to perform a function. Medical devices, vehicles, aviation and marine equipment have their own rules and are excluded.
From 11 September 2026 manufacturers must report through ENISA's Single Reporting Platform (Art. 14). The duty covers two things, and precision matters here:
So the 24-hour clock doesn't apply to every serious vulnerability you find, only to actively exploited ones and to severe incidents. Reports go to the coordinating CSIRT and to ENISA at the same time.
From 11 December 2027 the rest applies: the essential cybersecurity requirements in Annex I, vulnerability handling for the whole support period, technical documentation, conformity assessment and CE marking. Critical product categories need third-party assessment. Breaching the essential requirements or Articles 13 and 14 can cost up to EUR 15 million or 2.5% of worldwide turnover (Art. 64(2)). The Commission published practical CRA guidance on 27 July 2026.

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. It was amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026. It removes no obligations but moves the high-risk deadlines and softens the AI literacy duty.
The Article 5 prohibitions have applied since 2 February 2025. Article 4 now requires providers and deployers to take measures to support AI literacy among their staff, rather than to ensure a given level. The Article 50 transparency duties apply from 2 August 2026. High-risk obligations apply from 2 December 2027 for Annex III systems, such as AI used in recruitment, and from 2 August 2028 for AI embedded in products under Annex I.
National market surveillance authorities supervise AI systems and the Commission's AI Office supervises general-purpose AI models. Our AI Act guide explains the roles, and if you deploy high-risk AI in public services or for credit scoring, Article 27 requires a fundamental rights impact assessment.
The Data Act (Regulation (EU) 2023/2854) belongs in digital compliance, but it isn't about IT security. It governs who is entitled to data from connected products and the right to switch cloud provider.
It has applied since 12 September 2025. Users of connected products, consumers and businesses alike, can demand access to the data the product generates and have it shared with a third party (Articles 4 and 5). From 12 September 2026 new products must be designed so data is accessible to the user by default (Art. 3(1)). Cloud customers can switch provider, and from 12 January 2027 providers may not charge for the switch (Art. 29).
Rules on unfair B2B contract terms apply to contracts concluded after 12 September 2025, and from 12 September 2027 to certain older ones. For compliance teams this is mostly legal and procurement work on vendor contracts.
eIDAS2 (Regulation (EU) 2024/1183) obliges Member States to offer a European Digital Identity Wallet by 24 December 2026. Private services that must use strong user authentication by law or contract, such as banks, insurers and telecoms, must accept it by 24 December 2027 (Art. 5f).
The DSA and DMA mainly target online platforms and gatekeepers. Unless you run a marketplace or a platform with user content, they are rarely your main workload.
UK organisations aren't bound by these laws at home, but GDPR, the CRA and the AI Act reach businesses that sell into the EU. The UK's own Cyber Security and Resilience Bill was still before Parliament at the time of writing.
One ransomware attack on a system holding customer data can start several clocks at once, each with its own recipient and trigger.
| Rule | Trigger | Deadlines | Recipient |
|---|---|---|---|
| GDPR Art. 33 | Personal data breach | 72 hours | Data protection authority |
| NIS2 Art. 23 | Significant incident | 24 hours, 72 hours, 1 month | CSIRT or competent authority |
| DORA Art. 19 | Major ICT-related incident | 4 hours after classification (24 hours at the latest), 72 hours, 1 month | Financial supervisor |
| CRA Art. 14 | Actively exploited vulnerability or severe incident in a product | 24 hours, 72 hours, 14 days or 1 month | Coordinating CSIRT and ENISA |
| CER Art. 15 | Incident disrupting an essential service | 24 hours, 1 month | Competent authority |
The DORA timings sit in Delegated Regulation (EU) 2025/301. The answer is one incident process with one triage step: Is personal data involved? Is it significant under NIS2? Is it our own product? The answers decide which clocks run. Our article on security breaches goes deeper on the GDPR side.
The Digital Omnibus proposes a single reporting entry point. Until it exists, you report to each recipient separately.

Most of these rules ask for the same groundwork in different formats. Here is the sequence we see working.
Record whether you're in scope and in which role: controller, processor, essential or important entity, manufacturer, deployer or data holder.
Your GDPR Article 30 record, asset management under NIS2 Article 21(2)(i) and DORA Article 8, and your AI inventory can be one register with different fields.
GDPR Article 32, NIS2 Article 21, DORA Article 6, AI Act Article 9 and CRA Article 13 all require risk assessment, and one method (often ISO/IEC 27005) can serve them all. We've described how one risk method can cover many obligations.
ISO/IEC 27001:2022 isn't law, but its 93 Annex A controls cover much of the technical and organisational ground in NIS2, DORA and GDPR Article 32. ENISA has published a mapping between the NIS2 Implementing Regulation (EU) 2024/2690 and ISO 27001. It's a navigation aid, not a statement of equivalence. Read more about ISO 27001 certification.
One incident process with the clocks from the table, and one supplier programme covering data processing agreements under GDPR Article 28, supply chain security under NIS2 Article 21(2)(d), ICT third-party risk under DORA Article 28 and cloud contracts under the Data Act.
NIS2 Article 20 and DORA Article 5 put accountability on the management body. Give it one report across the rules and one compliance calendar, so the deadlines become tasks with an owner.

Corrib Metering Ltd and Aoife Byrne are fictional. We invented them for this article, and they are neither customers nor a case study.
Corrib Metering is an Irish company with 180 staff and EUR 30 million in turnover. It makes smart heat meters for district heating operators across the EU and runs a platform where operators read consumption. HR uses an AI tool to screen applicants. Aoife Byrne, head of compliance, has to work out what applies.
She starts with roles. Household consumption data is personal data, so Corrib is a GDPR controller and a processor for its customers. The meters are products with digital elements, so Corrib is a manufacturer under the CRA with a reporting duty since 11 September 2026. The meters are connected products, so Corrib is a data holder under the Data Act. The recruitment tool is high-risk under Annex III, so Corrib is a deployer with obligations from 2 December 2027.
NIS2 is where Aoife first goes wrong. She assumes Corrib is covered because its customers are energy operators. That isn't the reason, because suppliers aren't covered as such. Corrib falls within scope because manufacturing of computer, electronic and optical products is an Annex II sector, and with 180 staff it is medium-sized. That makes it an important entity. The catch: when the Commission referred Ireland to the Court of Justice in July 2026, Ireland hadn't notified full transposition, so Aoife must check which national law binds Corrib today. The CRA, Data Act, AI Act and GDPR apply directly regardless.
| Building block | GDPR | NIS2 | CRA | Data Act | AI Act |
|---|---|---|---|---|---|
| Register of systems and data | ✓ | ✓ | ✓ | ✓ | ✓ |
| Shared risk method | ✓ | ✓ | ✓ | ✗ | ✓ |
| Incident and vulnerability process | ✓ | ✓ | ✓ | ✗ | ✗ |
| Supplier and contract programme | ✓ | ✓ | ✓ | ✓ | ✓ |
| Training and board reporting | ✓ | ✓ | ✗ | ✗ | ✓ |
Aoife's conclusion is that five rules need five building blocks, not 25. CRA reporting already applies, so the meters' vulnerability process comes first, linked to the NIS2 incident process. Then Data Act design for the next meter generation. AI recruitment and CRA conformity assessment are planned towards December 2027.
With 40 staff and turnover under EUR 10 million, NIS2 wouldn't apply, but the CRA, the Data Act and GDPR still would. Roles and products decide digital compliance, not industry labels.
Three caveats. An ISO 27001 certificate isn't NIS2 compliance, and it doesn't cover the Data Act or the AI Act's requirements for documentation and human oversight. National labels, such as the Danish D-seal, are voluntary schemes rather than law, and we've compared the D-seal and ISO 27001 separately.
No software makes you compliant. A tool tracks requirements, tasks and evidence, but assessments and accountability stay with you. And the rules keep moving. The Data Omnibus and the NIS2 amendment proposal could change deadlines and scope in 2027 and 2028. Build to the obligations and treat future dates as provisional until they appear in the Official Journal.
The practical challenge in digital compliance is documenting the same work twice. Our Frameworks module lets you map one control or task, such as your annual risk assessment or your supplier review, to the requirements in GDPR, NIS2, ISO 27001 and the AI Act that it satisfies. Once the task is done, you can see it across the frameworks.
Risk assessments sit in the risk module, suppliers and processors in Vendor Management, and the timeline deadlines can go into compliance task management with an owner each. To see it with your own rules, book a demo.
Digital compliance means meeting the rules that apply to an organisation's data, IT systems, digital products and use of AI. In the EU that typically covers GDPR, NIS2, DORA, the Cyber Resilience Act, the AI Act and the Data Act. It isn't a legal category but a practical umbrella term. Which rules apply to you depends on your roles, such as controller, NIS2 entity, manufacturer or AI deployer.
Start with roles, not sectors. GDPR applies if you process personal data. NIS2 applies through national law if you're a medium or large entity in an Annex I or II sector. The AI Act applies if you build or use AI systems, the Data Act if you make connected products or buy cloud services, and the Cyber Resilience Act if you place products with digital elements on the EU market. DORA is limited to financial entities.
Not simply by being suppliers. A vendor doesn't become a NIS2 entity because its customer is one. It feels the rules through customer requirements, because in-scope entities must manage supply chain security under Article 21(2)(d). That usually means contract clauses, questionnaires and audits. A supplier can still be covered in its own right if it operates in one of the directive's sectors and meets the size threshold.
The Cyber Resilience Act entered into force on 10 December 2024 and applies in stages. Rules on notified bodies apply from 11 June 2026. The duty to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026, including for products already sold. The essential cybersecurity requirements, CE marking and the rest of the regulation apply from 11 December 2027.
Generally not. The Cyber Resilience Act regulates products with digital elements, meaning hardware and software supplied to the user. Pure SaaS accessed only through a browser isn't such a product. Remote data processing is covered only where a product needs it to perform its functions, for example the cloud backend of an app or a connected device. SaaS providers may instead fall under NIS2 as digital providers.
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the dates. High-risk obligations now apply from 2 December 2027 for Annex III systems, such as AI in recruitment and credit scoring, and from 2 August 2028 for AI embedded in Annex I products. The prohibitions, transparency duties and general-purpose AI rules were not postponed.
NIS2 is a directive covering many sectors and applies through national transposing laws. DORA is a regulation that applies directly and only to financial entities. For them, DORA takes precedence over NIS2's risk management and reporting rules. DORA goes further on ICT third-party risk, the register of information and threat-led penetration testing. Supervision sits with financial supervisors for DORA and with NIS2 competent authorities otherwise.
The EU digital rulebook is a shorthand for the laws the EU has adopted to regulate data, cybersecurity, AI and digital markets. It includes GDPR, NIS2, CER, DORA, the Cyber Resilience Act, the AI Act, the Data Act, eIDAS2, the DSA and the DMA. The Commission is now simplifying parts of it through omnibus packages, starting with the AI Act amendment adopted in July 2026.
Several do when UK companies deal with the EU. GDPR applies to organisations offering goods or services to people in the EU or monitoring them there. The Cyber Resilience Act applies to any product with digital elements placed on the EU market, wherever the manufacturer sits. The AI Act covers providers placing AI systems on the EU market and cases where AI output is used in the EU.
Partly. ISO/IEC 27001:2022 is a voluntary standard, but its management system and 93 controls give a common frame for much of the technical and organisational ground in NIS2, DORA and GDPR Article 32. It doesn't cover legal duties such as reporting deadlines, registration, Data Act rights or the AI Act's product requirements. Use it as the backbone and add each rule's specific requirements on top.
Explore more articles about navigating the digital regulatory landscape and building a robust compliance program.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.