Seven Regulations. One Board Question: Are We Ready?

A plain-language guide for executives who need to know which EU regulations affect their organisation — and what happens if they don’t act.

5-minute read · Last updated February 2026

Which regulations apply to your organisation?

Find your sector. If a column is marked, that regulation likely applies to you.

RegulationFinancial ServicesEnergy & UtilitiesManufacturing & TechHealthcareTransport & LogisticsDigital Services & SaaS50+ EmployeesHandles Personal DataSells Digital Products
DORAIf ICT provider to finance
NIS2If digital infra
GDPRAny size
EU AI ActAny sizeIf using/deploying AI
CRAIf medical devicesAny size
CERIf digital infra
ISO/SOC/PCIAny size

This is a simplified overview. Scope depends on specific activities, entity classification, and member state transposition. Scroll down for details on each regulation, or book a call for a definitive assessment.

The compliance wave is not coming. It’s here.

Between 2025 and 2027, the EU is enforcing seven overlapping regulations that affect how organisations handle technology, data, resilience, and AI. Most are already in force. The rest are months away.

They don’t arrive one at a time. DORA, NIS2, the EU AI Act, and the Cyber Resilience Act all have enforcement milestones landing within the same 18-month window. Each carries fines measured in millions or as a percentage of global turnover — and several introduce personal liability for executives and board members.

The challenge isn’t understanding any single regulation. It’s that they overlap, interact, and stack. An organisation in energy might face NIS2, CER, GDPR, and the EU AI Act simultaneously. A software company might be caught by CRA, GDPR, NIS2, and the EU AI Act. Handling them in isolation is how organisations end up scrambling.

DORA

Digital Operational Resilience ActENFORCED

In Plain English

DORA requires financial entities to prove they can keep operating when technology fails, whether from a cyberattack, a vendor outage, or a system crash. It mandates ICT risk management frameworks, incident reporting, resilience testing, and oversight of third-party technology providers.

Key Numbers

Deadline: In force since 17 January 2025. No transition period.

Penalty: Up to 2% of global annual turnover or €10 million (whichever is higher). Individual fines up to €1 million. Criminal penalties possible depending on member state.

Why It Matters

DORA is already being enforced. Regulators are conducting oversight now. The most common gap: organisations can list their ICT vendors but cannot demonstrate they’ve assessed concentration risk or tested what happens when a critical provider fails. That’s exactly what supervisors are looking for.

You’re likely in scope if:

You are a bank, insurer, investment firm, or payment provider operating in the EU
You manage a pension fund, crypto-asset service, or credit rating agency
You are an ICT service provider to any of the above (cloud, software, data, infrastructure)

NIS2

Network and Information Security Directive 2ENFORCING: transposition ongoing

In Plain English

NIS2 is the EU’s broadened cybersecurity directive. It replaced the original NIS directive and dramatically expanded the scope, covering 18 sectors, requiring risk management measures, incident reporting within 24 hours, and supply chain security. The headline change: cybersecurity is now a board-level responsibility, not an IT department matter.

Key Numbers

Deadline: Member states were required to transpose by October 2024. Most EU states are now enforcing registration and compliance requirements through 2025–2026, though transposition progress varies by country.

Penalty: Up to €10 million or 2% of global turnover for essential entities. Up to €7 million or 1.4% for important entities. C-level executives can be personally liable and temporarily banned from management roles.

Why It Matters

NIS2 introduced personal accountability for board members. Management must approve cybersecurity measures, oversee their implementation, and undergo training. If there’s a breach and the board can’t demonstrate active oversight, the personal liability clause applies. Most mid-size organisations haven’t updated their governance structures to reflect this shift.

You’re likely in scope if:

You have 50+ employees and €10M+ annual turnover
You operate in energy, transport, banking, health, water, digital infrastructure, ICT services, public administration, space, postal services, waste management, chemicals, food, or manufacturing
You provide managed services, managed security services, or DNS/cloud/data centre services (regardless of size)

GDPR

General Data Protection RegulationENFORCED

In Plain English

GDPR governs how organisations collect, process, store, and protect personal data. Eight years in, it remains the most actively enforced data regulation globally, and enforcement keeps intensifying, not slowing down. The largest single fine to date exceeded €1.2 billion.

Key Numbers

Deadline: Fully in force since May 2018. No new deadlines, but enforcement actions and fine amounts continue to escalate year on year.

Penalty: Up to €20 million or 4% of global annual turnover, whichever is higher.

Why It Matters

GDPR is not “done.” Regulators are issuing larger fines and scrutinising data practices more aggressively than ever. For any company handling customer data, GDPR intersects directly with NIS2 and DORA. If a cybersecurity incident exposes personal data, you’re facing multiple regulators simultaneously. The organisations that struggle most treat GDPR as a standalone checkbox rather than integrating it into their security and resilience framework.

You’re likely in scope if:

You process personal data of anyone in the EU (customers, employees, partners)
You offer goods or services to EU residents, regardless of where you’re based
You monitor the behaviour of EU residents (analytics, tracking, profiling)
In practice: virtually every company operating in or with the EU

EU AI Act

EU Artificial Intelligence ActENFORCING: phased rollout through 2028

In Plain English

The world’s first comprehensive AI regulation. It classifies AI systems by risk level, from outright bans on manipulative or social-scoring AI, to mandatory conformity assessments for high-risk systems used in areas like hiring, credit, healthcare, and critical infrastructure. If your organisation uses AI to make or support decisions that affect people, you need to know where you stand.

Key Numbers

Deadline: Banned practices enforceable since February 2025. General-purpose AI rules since August 2025. Transparency obligations from 2 August 2026. High-risk system requirements from 2 December 2027 (2 August 2028 for AI embedded in regulated products), following the EU’s June 2026 digital omnibus package.

Penalty: Up to €35 million or 7% of global turnover for prohibited practices. Up to €15 million or 3% for other violations.

Why It Matters

Most mid-size companies are already using AI: for customer support, fraud detection, hiring screening, demand forecasting, credit assessment. The EU AI Act means these are no longer just internal tools; they’re regulated systems requiring documentation, risk assessment, and human oversight. The high-risk deadline moved to December 2027, but the runway is shorter than it looks: an AI inventory, risk assessment, and conformity assessment alone take 6–12 months, and transparency rules already apply from August 2026. The biggest risk isn’t the fine. It’s discovering your AI systems are non-compliant after the deadline and having to pause them.

You’re likely in scope if:

You use AI for credit scoring, fraud detection, or financial risk assessment
You use AI tools in recruitment, employee evaluation, or HR decisions
You deploy AI in healthcare diagnostics, safety systems, or critical infrastructure management
You use AI-based customer assessment, profiling, or automated decision-making

CRA

Cyber Resilience ActENFORCING 2026

In Plain English

The CRA introduces mandatory cybersecurity requirements for all products with digital elements sold in the EU: software, hardware, IoT devices, connected systems. Manufacturers must build security in from design, maintain it through the product lifecycle, and report actively exploited vulnerabilities within 24 hours. This is the EU’s product safety regime for the digital world.

Key Numbers

Deadline: Vulnerability and incident reporting from 11 September 2026. Full compliance by 11 December 2027.

Penalty: Up to €15 million or 2.5% of global annual turnover, whichever is higher.

Why It Matters

Even if you don’t manufacture products, CRA affects your supply chain. Every piece of software and connected hardware you procure will need to meet CRA standards. For companies that develop software platforms, SaaS products, IoT devices, or digital solutions of any kind, you’re directly in scope. The September 2026 reporting obligation catches many companies off guard because it applies retroactively to products already on the market.

You’re likely in scope if:

You develop or sell software, firmware, or connected hardware in the EU
You manufacture or distribute IoT devices, smart products, or embedded systems
You import or resell digital products from non-EU manufacturers
You develop SaaS platforms or digital tools that connect to other systems or networks

CER

Critical Entities Resilience DirectiveENFORCING 2026

In Plain English

The CER Directive requires EU member states to identify organisations whose disruption would seriously affect essential services, and impose resilience requirements covering all threats: physical, cyber, natural disasters, sabotage. It’s the “sister directive” to NIS2, but broader. Where NIS2 focuses on cybersecurity, CER covers the full spectrum of operational resilience.

Key Numbers

Deadline: National resilience strategies due by January 2026 (already passed). Critical entities must be identified by 17 July 2026. Once designated, entities have 10 months to comply, bringing the latest deadline to approximately May 2027.

Penalty: Set by individual member states, required to be “effective, proportionate, and dissuasive.” Expect fines, public notifications, mandatory remediation, and potential loss of operating authorisation.

Why It Matters

The 10-month compliance window after designation is aggressive. Most resilience programmes take 12–18 months to build properly. Organisations that wait for formal notification before starting will not meet the deadline. The practical approach is to begin a gap assessment now against CER requirements, using existing business continuity frameworks (ISO 22301, for example) as a baseline.

You’re likely in scope if:

You operate in energy, transport, banking, financial market infrastructure, healthcare, water supply, or wastewater
You provide digital infrastructure, public administration, space, or food production/distribution services
You are classified as a “critical entity” or expect to be, i.e., your disruption would significantly impact essential services in your member state

ISO 27001 / SOC 2 / PCI DSS

International standards for information security, controls, and payment dataVOLUNTARY

In Plain English

Unlike the regulations above, these are voluntary standards. ISO 27001 certifies your information security management system. SOC 2 demonstrates your controls meet trust service criteria. PCI DSS applies to organisations handling payment card data. None are legally mandated, but in practice, they’re becoming prerequisites for doing business, winning contracts, and passing vendor due diligence.

Key Numbers

Deadline: No regulatory deadline. But commercial deadlines are real: enterprise procurement cycles increasingly require current certifications or reports before signing.

Penalty: No regulatory fine. But commercial consequences are severe: lost contracts, failed audits, inability to qualify as a vendor for larger clients.

Why It Matters

These standards are your proof of competence. When a client, auditor, or regulator asks “show me your security controls,” an ISO 27001 certificate or SOC 2 report is the fastest way to answer. More importantly, ISO 27001 overlaps significantly with DORA, NIS2, and CER requirements. Organisations that already hold certifications have a 40–60% head start on regulatory compliance. If you don’t have them yet, building towards certification is the most efficient way to address multiple obligations at once.

You’re likely in scope if:

Your clients ask for proof of security controls during procurement or vendor assessments
You process, store, or transmit payment card data (PCI DSS)
You want to accelerate compliance with DORA, NIS2, or CER by building on an established framework
You’re competing for enterprise contracts where security certification is a qualification requirement

The problem isn’t understanding the regulations. It’s implementing them all at once.

Every regulation on this page has its own requirements, deadlines, and enforcement bodies. But in practice, they overlap — DORA and NIS2 share cybersecurity requirements, CER and DORA both demand resilience testing, the EU AI Act intersects with GDPR on data governance, and ISO 27001 maps to nearly all of them.

The organisations that handle this well don’t run seven separate compliance projects. They build one integrated framework and map each regulation to it. That’s faster, cheaper, and far more likely to actually work.

Frequently Asked Questions

NIS2, the EU's network and information security directive, applies to organisations in 18 critical and important sectors — including banking, financial market infrastructure, digital infrastructure, ICT service management, energy, and manufacturing — with at least 50 employees or over €10 million annual turnover. Larger entities (250+ employees or €50 million+ turnover) are classed as essential and face stricter supervision. Some providers, such as DNS and telecoms, are covered regardless of size.

Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher; important entities up to €7 million or 1.4%. NIS2 also introduces personal accountability: management bodies can be held liable for non-compliance, including temporary bans from leadership roles. The directive has applied through national law across the EU since late 2024 — in Slovakia through Act 366/2024, effective 1 January 2025.

DORA, the EU's Digital Operational Resilience Act, has applied since 17 January 2025 — it is live, and regulators are now asking for evidence, not plans. It covers some 20 categories of financial entities: banks, insurers, payment and e-money institutions, investment firms, and crypto-asset service providers, among others. ICT providers serving those firms are pulled in too, through mandatory contractual requirements and, for the largest, direct EU oversight.

DORA. For financial entities, DORA acts as the sector-specific rulebook (lex specialis), so its ICT risk management and incident reporting requirements apply instead of the equivalent NIS2 provisions. NIS2 can still reach other parts of your group — for example an IT subsidiary or a data centre operation. The practical step is a scoping exercise that maps which regime governs which entity, before you build controls twice.

Yes, directly. Creditworthiness assessment and credit scoring of natural persons are classed as high-risk AI, triggering obligations around risk management, data governance, human oversight, and cybersecurity. Prohibited practices, such as social scoring, have been banned since February 2025, and transparency rules for AI interaction take effect in August 2026. Banks should already be running an AI inventory and governance programme, not waiting for the high-risk deadline.

The timeline changed in June 2026, when the EU adopted its digital omnibus package. Prohibitions and AI literacy duties have applied since 2 February 2025; general-purpose AI model rules since 2 August 2025. Transparency obligations apply from 2 August 2026 as originally planned. High-risk system obligations were postponed: to 2 December 2027 for stand-alone high-risk systems, and 2 August 2028 for AI embedded in regulated products.

Not sure where your gaps are? Let’s find out.

Talk to Us

A 30-minute call with a senior partner. No pitch deck. We’ll map your regulatory exposure and tell you where to focus first.

Book a Call

Send Us Details

Tell us about your situation. We’ll review it and come back with an honest assessment of what needs attention.

Get In Touch

No commitment. No sales follow-up unless you ask for it.