Seven Regulations. One Board Question: Are We Ready?
A plain-language guide for executives who need to know which EU regulations affect their organisation — and what happens if they don’t act.
5-minute read · Last updated February 2026
Which regulations apply to your organisation?
Find your sector. If a column is marked, that regulation likely applies to you.
| Regulation | Financial Services | Energy & Utilities | Manufacturing & Tech | Healthcare | Transport & Logistics | Digital Services & SaaS | 50+ Employees | Handles Personal Data | Sells Digital Products |
|---|---|---|---|---|---|---|---|---|---|
| DORA | ✓ | — | — | — | — | If ICT provider to finance | ✓ | — | — |
| NIS2 | ✓ | ✓ | If digital infra | ✓ | ✓ | ✓ | ✓ | — | — |
| GDPR | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | Any size | ✓ | — |
| EU AI Act | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | Any size | — | If using/deploying AI |
| CRA | — | — | ✓ | If medical devices | — | ✓ | Any size | — | ✓ |
| CER | ✓ | ✓ | — | ✓ | ✓ | If digital infra | ✓ | — | — |
| ISO/SOC/PCI | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | Any size | — | — |
This is a simplified overview. Scope depends on specific activities, entity classification, and member state transposition. Scroll down for details on each regulation, or book a call for a definitive assessment.
The compliance wave is not coming. It’s here.
Between 2025 and 2027, the EU is enforcing seven overlapping regulations that affect how organisations handle technology, data, resilience, and AI. Most are already in force. The rest are months away.
They don’t arrive one at a time. DORA, NIS2, the EU AI Act, and the Cyber Resilience Act all have enforcement milestones landing within the same 18-month window. Each carries fines measured in millions or as a percentage of global turnover — and several introduce personal liability for executives and board members.
The challenge isn’t understanding any single regulation. It’s that they overlap, interact, and stack. An organisation in energy might face NIS2, CER, GDPR, and the EU AI Act simultaneously. A software company might be caught by CRA, GDPR, NIS2, and the EU AI Act. Handling them in isolation is how organisations end up scrambling.
DORA
Digital Operational Resilience ActENFORCEDIn Plain English
DORA requires financial entities to prove they can keep operating when technology fails, whether from a cyberattack, a vendor outage, or a system crash. It mandates ICT risk management frameworks, incident reporting, resilience testing, and oversight of third-party technology providers.
Key Numbers
Deadline: In force since 17 January 2025. No transition period.
Penalty: Up to 2% of global annual turnover or €10 million (whichever is higher). Individual fines up to €1 million. Criminal penalties possible depending on member state.
Why It Matters
DORA is already being enforced. Regulators are conducting oversight now. The most common gap: organisations can list their ICT vendors but cannot demonstrate they’ve assessed concentration risk or tested what happens when a critical provider fails. That’s exactly what supervisors are looking for.
You’re likely in scope if:
NIS2
Network and Information Security Directive 2ENFORCING: transposition ongoingIn Plain English
NIS2 is the EU’s broadened cybersecurity directive. It replaced the original NIS directive and dramatically expanded the scope, covering 18 sectors, requiring risk management measures, incident reporting within 24 hours, and supply chain security. The headline change: cybersecurity is now a board-level responsibility, not an IT department matter.
Key Numbers
Deadline: Member states were required to transpose by October 2024. Most EU states are now enforcing registration and compliance requirements through 2025–2026, though transposition progress varies by country.
Penalty: Up to €10 million or 2% of global turnover for essential entities. Up to €7 million or 1.4% for important entities. C-level executives can be personally liable and temporarily banned from management roles.
Why It Matters
NIS2 introduced personal accountability for board members. Management must approve cybersecurity measures, oversee their implementation, and undergo training. If there’s a breach and the board can’t demonstrate active oversight, the personal liability clause applies. Most mid-size organisations haven’t updated their governance structures to reflect this shift.
You’re likely in scope if:
GDPR
General Data Protection RegulationENFORCEDIn Plain English
GDPR governs how organisations collect, process, store, and protect personal data. Eight years in, it remains the most actively enforced data regulation globally, and enforcement keeps intensifying, not slowing down. The largest single fine to date exceeded €1.2 billion.
Key Numbers
Deadline: Fully in force since May 2018. No new deadlines, but enforcement actions and fine amounts continue to escalate year on year.
Penalty: Up to €20 million or 4% of global annual turnover, whichever is higher.
Why It Matters
GDPR is not “done.” Regulators are issuing larger fines and scrutinising data practices more aggressively than ever. For any company handling customer data, GDPR intersects directly with NIS2 and DORA. If a cybersecurity incident exposes personal data, you’re facing multiple regulators simultaneously. The organisations that struggle most treat GDPR as a standalone checkbox rather than integrating it into their security and resilience framework.
You’re likely in scope if:
EU AI Act
EU Artificial Intelligence ActENFORCING: phased rollout through 2028In Plain English
The world’s first comprehensive AI regulation. It classifies AI systems by risk level, from outright bans on manipulative or social-scoring AI, to mandatory conformity assessments for high-risk systems used in areas like hiring, credit, healthcare, and critical infrastructure. If your organisation uses AI to make or support decisions that affect people, you need to know where you stand.
Key Numbers
Deadline: Banned practices enforceable since February 2025. General-purpose AI rules since August 2025. Transparency obligations from 2 August 2026. High-risk system requirements from 2 December 2027 (2 August 2028 for AI embedded in regulated products), following the EU’s June 2026 digital omnibus package.
Penalty: Up to €35 million or 7% of global turnover for prohibited practices. Up to €15 million or 3% for other violations.
Why It Matters
Most mid-size companies are already using AI: for customer support, fraud detection, hiring screening, demand forecasting, credit assessment. The EU AI Act means these are no longer just internal tools; they’re regulated systems requiring documentation, risk assessment, and human oversight. The high-risk deadline moved to December 2027, but the runway is shorter than it looks: an AI inventory, risk assessment, and conformity assessment alone take 6–12 months, and transparency rules already apply from August 2026. The biggest risk isn’t the fine. It’s discovering your AI systems are non-compliant after the deadline and having to pause them.
You’re likely in scope if:
CRA
Cyber Resilience ActENFORCING 2026In Plain English
The CRA introduces mandatory cybersecurity requirements for all products with digital elements sold in the EU: software, hardware, IoT devices, connected systems. Manufacturers must build security in from design, maintain it through the product lifecycle, and report actively exploited vulnerabilities within 24 hours. This is the EU’s product safety regime for the digital world.
Key Numbers
Deadline: Vulnerability and incident reporting from 11 September 2026. Full compliance by 11 December 2027.
Penalty: Up to €15 million or 2.5% of global annual turnover, whichever is higher.
Why It Matters
Even if you don’t manufacture products, CRA affects your supply chain. Every piece of software and connected hardware you procure will need to meet CRA standards. For companies that develop software platforms, SaaS products, IoT devices, or digital solutions of any kind, you’re directly in scope. The September 2026 reporting obligation catches many companies off guard because it applies retroactively to products already on the market.
You’re likely in scope if:
CER
Critical Entities Resilience DirectiveENFORCING 2026In Plain English
The CER Directive requires EU member states to identify organisations whose disruption would seriously affect essential services, and impose resilience requirements covering all threats: physical, cyber, natural disasters, sabotage. It’s the “sister directive” to NIS2, but broader. Where NIS2 focuses on cybersecurity, CER covers the full spectrum of operational resilience.
Key Numbers
Deadline: National resilience strategies due by January 2026 (already passed). Critical entities must be identified by 17 July 2026. Once designated, entities have 10 months to comply, bringing the latest deadline to approximately May 2027.
Penalty: Set by individual member states, required to be “effective, proportionate, and dissuasive.” Expect fines, public notifications, mandatory remediation, and potential loss of operating authorisation.
Why It Matters
The 10-month compliance window after designation is aggressive. Most resilience programmes take 12–18 months to build properly. Organisations that wait for formal notification before starting will not meet the deadline. The practical approach is to begin a gap assessment now against CER requirements, using existing business continuity frameworks (ISO 22301, for example) as a baseline.
You’re likely in scope if:
ISO 27001 / SOC 2 / PCI DSS
International standards for information security, controls, and payment dataVOLUNTARYIn Plain English
Unlike the regulations above, these are voluntary standards. ISO 27001 certifies your information security management system. SOC 2 demonstrates your controls meet trust service criteria. PCI DSS applies to organisations handling payment card data. None are legally mandated, but in practice, they’re becoming prerequisites for doing business, winning contracts, and passing vendor due diligence.
Key Numbers
Deadline: No regulatory deadline. But commercial deadlines are real: enterprise procurement cycles increasingly require current certifications or reports before signing.
Penalty: No regulatory fine. But commercial consequences are severe: lost contracts, failed audits, inability to qualify as a vendor for larger clients.
Why It Matters
These standards are your proof of competence. When a client, auditor, or regulator asks “show me your security controls,” an ISO 27001 certificate or SOC 2 report is the fastest way to answer. More importantly, ISO 27001 overlaps significantly with DORA, NIS2, and CER requirements. Organisations that already hold certifications have a 40–60% head start on regulatory compliance. If you don’t have them yet, building towards certification is the most efficient way to address multiple obligations at once.
You’re likely in scope if:
The problem isn’t understanding the regulations. It’s implementing them all at once.
Every regulation on this page has its own requirements, deadlines, and enforcement bodies. But in practice, they overlap — DORA and NIS2 share cybersecurity requirements, CER and DORA both demand resilience testing, the EU AI Act intersects with GDPR on data governance, and ISO 27001 maps to nearly all of them.
The organisations that handle this well don’t run seven separate compliance projects. They build one integrated framework and map each regulation to it. That’s faster, cheaper, and far more likely to actually work.
Frequently Asked Questions
NIS2, the EU's network and information security directive, applies to organisations in 18 critical and important sectors — including banking, financial market infrastructure, digital infrastructure, ICT service management, energy, and manufacturing — with at least 50 employees or over €10 million annual turnover. Larger entities (250+ employees or €50 million+ turnover) are classed as essential and face stricter supervision. Some providers, such as DNS and telecoms, are covered regardless of size.
Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher; important entities up to €7 million or 1.4%. NIS2 also introduces personal accountability: management bodies can be held liable for non-compliance, including temporary bans from leadership roles. The directive has applied through national law across the EU since late 2024 — in Slovakia through Act 366/2024, effective 1 January 2025.
DORA, the EU's Digital Operational Resilience Act, has applied since 17 January 2025 — it is live, and regulators are now asking for evidence, not plans. It covers some 20 categories of financial entities: banks, insurers, payment and e-money institutions, investment firms, and crypto-asset service providers, among others. ICT providers serving those firms are pulled in too, through mandatory contractual requirements and, for the largest, direct EU oversight.
DORA. For financial entities, DORA acts as the sector-specific rulebook (lex specialis), so its ICT risk management and incident reporting requirements apply instead of the equivalent NIS2 provisions. NIS2 can still reach other parts of your group — for example an IT subsidiary or a data centre operation. The practical step is a scoping exercise that maps which regime governs which entity, before you build controls twice.
Yes, directly. Creditworthiness assessment and credit scoring of natural persons are classed as high-risk AI, triggering obligations around risk management, data governance, human oversight, and cybersecurity. Prohibited practices, such as social scoring, have been banned since February 2025, and transparency rules for AI interaction take effect in August 2026. Banks should already be running an AI inventory and governance programme, not waiting for the high-risk deadline.
The timeline changed in June 2026, when the EU adopted its digital omnibus package. Prohibitions and AI literacy duties have applied since 2 February 2025; general-purpose AI model rules since 2 August 2025. Transparency obligations apply from 2 August 2026 as originally planned. High-risk system obligations were postponed: to 2 December 2027 for stand-alone high-risk systems, and 2 August 2028 for AI embedded in regulated products.
Not sure where your gaps are? Let’s find out.
Talk to Us
A 30-minute call with a senior partner. No pitch deck. We’ll map your regulatory exposure and tell you where to focus first.
Book a CallSend Us Details
Tell us about your situation. We’ll review it and come back with an honest assessment of what needs attention.
Get In TouchNo commitment. No sales follow-up unless you ask for it.