Skip to main content
All Insights

Regulatory Compliance.

NIS2, DORA, EU AI Act, and cross-border regulatory exposure for enterprises operating in the EU and US.

Regulatory Compliance·11 min read

The Cyber Resilience Act's First Obligation Gate Is 90 Days Away. Most Smaller Product Companies Still Cannot Prove They Are Ready.

The CRA has been binding law since December 2024, but its obligations arrive in phases. This week the conformity-assessment machinery switched on. The first reporting deadline is 11 September 2026. For most smaller product companies the gap is not capability. It is evidence.

Read
Regulatory Compliance·12 min read

The EU's Single Entry Point Solves the Regulator's Problem. The Operator Still Needs a Crosswalk.

The Digital Omnibus consolidates incident reporting into one ENISA-run portal. The five underlying regimes do not go away. The work moves upstream, into the controls crosswalk.

Read
Regulatory Compliance·9 min read

The EU's High-Risk AI Filter: Inside the May 2026 Draft Guidelines

On 19 May 2026 the European Commission published draft guidelines clarifying when an AI system is high-risk under Article 6. The exceptions are narrower than the market assumed.

Read
Regulatory Compliance·8 min read

Five Frameworks, One Vendor: How NIS2, DORA, CRA, the Revised CSA, and the EU AI Act Create Cross-Framework Exposure

NIS2, DORA, CRA, the revised CSA, and the EU AI Act each evaluate different dimensions of the same vendor. Running them as separate programs hides cross-framework exposure.

Read
Regulatory Compliance·8 min read

Sweden's Cybersecurity Act (2025:1506): NIS2 Is Now Law

Sweden's Cybersecurity Act (SFS 2025:1506) entered into force on 15 January 2026, shifting cybersecurity obligations to entity-wide scope with explicit management accountability requirements and fines up to €10M.

Read
Subscribe