NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian, Arabic and Chinese.See what’s new →

LEARN

Deep-dive guides to DORA, NIS2, ISO 27001, GDPR, SOC 2 and the EU AI Act: what each one actually requires, article by article, and how to evidence it.

Browse by subject

One hub per framework. Each walks the whole programme in the order the work happens, from scope through evidence, and pulls in the templates and comparisons at the point you need them. If you want the product rather than the reading, go to frameworks.

23 pagesDORAEverything on DORA in work order: scope and readiness, ICT risk governance, the register of information, incidents, resilience testing and audit evidence.20 pagesEU AI ActThe EU AI Act in the order you need it: who is in scope and from when, how systems are classified, what providers and deployers must document, and fines.14 pagesNIS2NIS2 from scope to audit: essential and important entities, the Article 21 measures, the overlap with ISO 27001 and DORA, costs, and management liability.12 pagesCyber Resilience ActThe Cyber Resilience Act for manufacturers, importers and distributors: who it covers, the 2026 and 2027 dates, essential requirements and penalties.7 pagesThird-party riskThird-party risk management end to end: the lifecycle, how to assess a vendor, what a security questionnaire should ask, and what DORA and NIS2 add on top.8 pagesISO 27001ISO 27001 in the order the work happens: how the 93 Annex A controls are organised, how the Statement of Applicability selects them, and choosing software.8 pagesSOC 2SOC 2 from the first buyer request to the report: what the attestation is, choosing criteria and report type, scoring readiness, and picking software.8 pagesGDPRVenvera's GDPR pages in working order: a compliance checklist to find the gaps, templates for the Article 30 register and DPIAs, and choosing software.7 pageseIDAS 2.0eIDAS 2.0 from scope to software: who must accept the EU Digital Identity Wallet, the 24 December 2027 deadline, cost, fines and a readiness checklist.7 pagesSolvency IISolvency II from the three pillars to the ORSA review: scope, Pillar 2 governance in Articles 41 to 49, what a supervisor tests, and choosing tools.3 pagesMiCAMiCA from capital to sanctions: the Annex IV capital floors and fixed overheads test that set the cost of authorisation, and the Article 111 penalty tiers.6 pagesHIPAAHIPAA in the order the work happens: covered entities and business associates, the Security Rule risk analysis and its template, and choosing software.6 pagesPCI DSSPCI DSS from scope to tooling: who must comply, which SAQ or ROC route applies, a checklist for the 12 requirements of v4.0.1, and how platforms compare.6 pagesUAE IAUAE IA in work order: designation, the always applicable core, the risk assessment that selects the rest, the P1 to P4 order, a checklist and cost.4 pagesSaudi NCA ECCSaudi NCA ECC in the order the work happens: what ECC-2:2024 asks in each domain, what the 2024 revision changed, what it costs and how to judge software.5 pagesSAMA CSFSAMA CSF from requirements to tooling: what the four domains and 32 subdomains ask for, why level 3 is a floor, what it costs and how to judge software.5 pagesNDPANigeria's NDPA in working order: duties section by section, the 200 data subject line for major importance, section 48 penalties, a checklist and software.3 pagesCMMC 2.0CMMC 2.0 in working order: which level your contract sets, drawing the CUI boundary, self-assessing the Level 2 practices, the POA&M and choosing software.2 pagesCyber EssentialsCyber Essentials from self-assessment to certificate: scope, the five NCSC technical controls, Cyber Essentials Plus, and which software fits a UK bid.2 pagesNIST CSF 2.0NIST CSF 2.0 as the work happens: rate the six functions against a target profile, read the gap, then choose software that scores maturity, not tick boxes.1 pagesFedRAMPFedRAMP under the 2026 Consolidated Rules: who is in scope, the six exclusions, Classes A to D, the Rev 5 and 20x paths, costs, and GovRAMP and CMMC.

Latest

CMMC Compliance Cost: What the DoD Estimated
Learn

CMMC Compliance Cost: What the DoD Estimated

The DoD puts a small firm's Level 2 C3PAO route at $104,670 over three years, but that figure leaves out the controls. What it covers and what you must add.

UAE IA vs ISO 27001: Where They Differ
Learn

UAE IA vs ISO 27001: Where They Differ

An ISO 27001 certificate builds much of a UAE IA programme but stands in for none of it. The overlap, the IA only rules, and which edition you are held to.

Saudi NCA ECC vs SAMA CSF: Scope and Differences
Learn

Saudi NCA ECC vs SAMA CSF: Scope and Differences

Who the NCA's ECC-2:2024 and the SAMA CSF each bind, when a financial institution answers to both, and the rules where the two disagree. From the texts.

SAMA CSF vs ISO 27001: What a Certificate Covers
Learn

SAMA CSF vs ISO 27001: What a Certificate Covers

An ISO 27001 certificate builds much of a SAMA CSF programme but replaces none of it. Where the two overlap, and the SAMA rules the standard never asks for.

GDPR vs NDPA: Where Nigeria's Law Differs
Learn

GDPR vs NDPA: Where Nigeria's Law Differs

The NDPA borrows GDPR's principles and six lawful bases, then parts ways on registration, annual returns, breach notice, fines and transfers. Side by side.

SOC 2 vs ISO 27001: What EU Buyers Ask For
Learn

SOC 2 vs ISO 27001: What EU Buyers Ask For

NIS2, DORA and the GDPR require neither. What those laws and German C5 say about each, and how to pick the one an EU customer's procurement team will accept.

PCI DSS vs ISO 27001: Scope, Proof and Overlap
Learn

PCI DSS vs ISO 27001: Scope, Proof and Overlap

PCI DSS protects card data under rules the brands enforce; ISO 27001 certifies a system you scope. Where they overlap, and why neither replaces the other.

ISO 27001 vs DORA: What the Certificate Covers
Learn

ISO 27001 vs DORA: What the Certificate Covers

DORA never mentions ISO 27001. Where an ISMS already answers its ICT risk articles, and the reporting, register, contract and testing duties it leaves open.

SOC 2 Audit: What to Expect From Start to Report
Learn

SOC 2 Audit: What to Expect From Start to Report

What happens in a SOC 2 examination: the description and assertion you write, how a Type 2 is tested, vendors, the four possible opinions, the final letter.

HIPAA Fines and Penalties: What OCR Really Charges
Learn

HIPAA Fines and Penalties: What OCR Really Charges

HIPAA penalty tiers at the amounts in force since January 2026, the 2019 yearly caps OCR still applies, how one gap becomes a daily violation, real cases.

PCI DSS Compliance Cost: What Drives the Bill
Learn

PCI DSS Compliance Cost: What Drives the Bill

Nobody publishes a PCI DSS price. What sets yours: the validation route your card brand and acquirer require, the tests the standard mandates, and your scope.

ISO 27001 Audit: What to Expect in the Room
Learn

ISO 27001 Audit: What to Expect in the Room

What happens inside an ISO 27001 certification audit: the opening meeting, sampling and interviews, major and minor findings, the closing meeting, the report.

How Long Does ISO 27001 Certification Take?
Learn

How Long Does ISO 27001 Certification Take?

No standard sets a duration. What has to exist before stage 1, what happens between the two audit stages, and what can hold the certificate back.

GDPR Fines and Penalties: What Changed in 2026
Learn

GDPR Fines and Penalties: What Changed in 2026

The two GDPR fine tiers, whose turnover counts, why fault is now required, how the EDPB sets the amount, and the fines and rule changes of 2026.

SOC 2 Cost for Companies Outside the US
Learn

SOC 2 Cost for Companies Outside the US

What sets a SOC 2 fee when you are not a US company: who may sign the report, AICPA versus ISAE 3000, report type, the period and the scope.

ISO 27001 Certification Cost: What Sets the Price
Learn

ISO 27001 Certification Cost: What Sets the Price

There is no ISO price list. How audit days follow headcount, what the three year cycle bills you for, and what accreditation in Europe changes.

NIS2 for Healthcare Providers: Scope and Duties
Learn

NIS2 for Healthcare Providers: Scope and Duties

Which hospitals, clinics and pharmacies NIS2 covers, why a public hospital is sized like any other, and what Articles 20, 21 and 23 ask of them.

DORA for Payment Institutions: Scope and TLPT
Learn

DORA for Payment Institutions: Scope and TLPT

Which payment and e-money institutions DORA covers, what it changed in PSD2 incident reporting, and when a payment firm must run TLPT.

NIS2 for Manufacturers: Scope and Obligations
Learn

NIS2 for Manufacturers: Scope and Obligations

Which manufacturers NIS2 covers, why most are important rather than essential entities, and what Articles 20, 21 and 23 ask of a plant operator.

DORA for Insurers: Scope, Solvency II and TLPT
Learn

DORA for Insurers: Scope, Solvency II and TLPT

Which insurers, reinsurers and intermediaries DORA covers, what it changed in Solvency II, and when an insurer must report an incident or run TLPT.

MiCA Requirements for CASPs Explained
Learn

MiCA Requirements for CASPs Explained

What MiCA Title V asks of a crypto-asset service provider: authorisation, capital, governance, client asset safekeeping and the service rules.

EU AI Act High-Risk Requirements Explained
Learn

EU AI Act High-Risk Requirements Explained

The seven requirements a high-risk AI system must meet under Articles 8 to 15, what providers and deployers each owe, and what the 2026 Omnibus changed.

UAE IA Audit: What to Expect
Learn

UAE IA Audit: What to Expect

How UAE IA compliance is checked: self-assessment reports via your sector regulator, audits and tests where TRA sees fit, and the evidence it reads.

eIDAS 2.0 Relying Party Requirements
Learn

eIDAS 2.0 Relying Party Requirements

What eIDAS 2.0 asks of a wallet relying party: register, request only registered data, identify yourself, validate, accept pseudonyms, keep other routes.

SAMA CSF Audit: What to Expect
Learn

SAMA CSF Audit: What to Expect

A SAMA CSF audit tests your periodic self-assessment: evidence per subdomain, maturity level 3 as the floor, independent audits and waivers for real gaps.

Solvency II Governance Requirements in Detail
Learn

Solvency II Governance Requirements in Detail

Solvency II governance in Articles 258 to 275 of Delegated Regulation 2015/35: the 12 general duties, key function tasks, outsourcing clauses and pay rules.

Cyber Resilience Act Requirements Explained
Learn

Cyber Resilience Act Requirements Explained

The CRA requirements in one place: the 13 product properties and 8 vulnerability duties in Annex I, the Article 13 duties, and Article 14 reporting.

HIPAA Risk Assessment: What OCR Actually Checks
Learn

HIPAA Risk Assessment: What OCR Actually Checks

The HIPAA risk analysis from the regulation itself: two Required duties, the nine elements OCR expects, a scored example, and what a missing one has cost.

Nigeria NDPA Compliance Cost
Learn

Nigeria NDPA Compliance Cost

Registration is N10,000 to N250,000 and audit returns N100,000 to N1,000,000 a year under the 2025 GAID. The fees, the six budget lines, and what recurs.

DORA Requirements Explained
Learn

DORA Requirements Explained

DORA sets five sets of requirements: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. What each asks.

Solvency II Pillar 2 Compliance Cost
Learn

Solvency II Pillar 2 Compliance Cost

The Commission's own impact assessment prices Solvency II at EUR 12m one-off and EUR 2.7m a year on average. What that means for a Pillar 2 governance budget.

NIS2 Article 21 Requirements Explained
Learn

NIS2 Article 21 Requirements Explained

Article 21 of NIS2 requires ten minimum cybersecurity measures on an all-hazards basis, sized by exposure, size and impact. What each point asks for.

Who Needs FedRAMP? The 2026 Scope Test
Learn

Who Needs FedRAMP? The 2026 Scope Test

The three conditions that put a cloud service in FedRAMP scope, the six exclusions, the four classes and which you can enter today, and what it costs.

Risk Management Frameworks: Which One, and How
Learn

Risk Management Frameworks: Which One, and How

Ten risk management frameworks compared on what they produce and who accepts it, with a decision tree, a 90-day plan and the regulation each one satisfies.

What Is Solvency II? The Three Pillars Explained
Learn

What Is Solvency II? The Three Pillars Explained

Solvency II is the EU prudential regime for insurers in Directive 2009/138/EC. The three pillars, who is in scope, and what changes on 30 January 2027.

Solvency II ORSA Review: What to Expect
Learn

Solvency II ORSA Review: What to Expect

A Solvency II ORSA review tests Article 45 as a process: a board approved policy, a record of each run, real challenge, and a report filed within two weeks.

Saudi NCA ECC Compliance Cost: What Drives It
Learn

Saudi NCA ECC Compliance Cost: What Drives It

There is no price list for ECC-2:2024. What the 108 controls make you pay for, the four lines that are hires and audits, not software, and how to size yours.

EU AI Act Compliance Timeline: How Long It Takes
Learn

EU AI Act Compliance Timeline: How Long It Takes

How long does EU AI Act compliance take? Weeks for most deployers, 9 to 18 months for a high risk provider. The phases and the date to plan against.

eIDAS 2.0 Fines and Penalties Explained
Learn

eIDAS 2.0 Fines and Penalties Explained

eIDAS 2.0 fines for trust service providers reach at least EUR 5 million or 1% of turnover. What Article 16 fixes, and what relying parties actually risk.

Nigeria NDPA Requirements Explained
Learn

Nigeria NDPA Requirements Explained

What the Nigeria Data Protection Act 2023 and the 2025 GAID require, section by section, and the 200 data subject line that doubles the list.

How to Collect Audit Evidence
Learn

How to Collect Audit Evidence

Audit evidence is records, statements of fact and other verifiable information. How to collect it once, map it to controls and keep it current.

DORA Audit: What to Expect
Learn

DORA Audit: What to Expect

There is no DORA certificate. A DORA audit is your supervisor using Article 50 powers, plus the internal audit Article 6(6) makes you run. What each asks for.

Cyber Resilience Act vs NIS2 vs DORA
Learn

Cyber Resilience Act vs NIS2 vs DORA

The CRA regulates products, NIS2 regulates entities, and DORA replaces NIS2 for financial firms. Scope, dates, reporting clocks and fines side by side.

MiCA Fines and Penalties: What You Actually Risk
Learn

MiCA Fines and Penalties: What You Actually Risk

MiCA fines for companies start at EUR 5 million or 3% to 12.5% of turnover, and reach 15% for market abuse. Every Article 111 tier, and who imposes each.

How Long Does NIS2 Compliance Take?
Learn

How Long Does NIS2 Compliance Take?

NIS2 compliance takes six to twelve months for most entities, up to 18 from a standing start. The phases, what sets the range, and what had to be ready first.

Cyber Resilience Act Scope: Who It Applies To
Learn

Cyber Resilience Act Scope: Who It Applies To

CRA scope turns on one Article 2 test: a product with digital elements whose use includes a data connection. The test, the definitions and the carve-outs.

CRA Penalties and Deadlines: What Applies When
Learn

CRA Penalties and Deadlines: What Applies When

Cyber Resilience Act penalties reach 15 million euros or 2.5% of turnover, but not all at once. Which fine can apply on which date, from 2026 to 2027.

Solvency II Pillar 2 Requirements Explained
Learn

Solvency II Pillar 2 Requirements Explained

Solvency II Pillar 2 is the system of governance in Articles 41 to 49: risk management, ORSA, key functions, fit and proper, outsourcing. What each asks for.

MiCA Compliance Cost After 1 July 2026
Learn

MiCA Compliance Cost After 1 July 2026

MiCA prices exactly one thing: capital. Annex IV sets EUR 50 000 to EUR 150 000, and the fixed overheads test quietly overtakes it sooner than most expect.

EU AI Act: Provider vs Deployer
Learn

EU AI Act: Provider vs Deployer

Article 3 defines the two roles, Article 16 and Article 26 set what each owes, and Article 25 turns one into the other. What each side has to hold.

EU AI Act Article 6: High-Risk Classification
Learn

EU AI Act Article 6: High-Risk Classification

Article 6 has two routes into high risk and one derogation with four conditions. What the 2026 Omnibus changed in it, and the dates that now apply.

UAE IA Requirements: What Entities Must Do
Learn

UAE IA Requirements: What Entities Must Do

The UAE IA Regulation sets 15 control families, four priority levels and a set of always applicable controls. What each one asks of a designated entity.

Nigeria NDPA Fines and Penalties Explained
Learn

Nigeria NDPA Fines and Penalties Explained

NDPA penalties reach the greater of 10 million naira and 2% of annual gross revenue. The 2% applies in both tiers, and only the naira floor changes.

EU AI Act Deadlines: Every Date That Applies
Learn

EU AI Act Deadlines: Every Date That Applies

Every EU AI Act date after the 2026 amendment: what 2 August 2026 binds, where the high risk deadlines went, and the Article 111 transitionals.

EU AI Act Article 5: Prohibited Practices
Learn

EU AI Act Article 5: Prohibited Practices

Article 5 now lists ten lettered points, not eight. Regulation (EU) 2026/1744 inserted two more, and they start to apply on 2 December 2026.

What UAE IA Compliance Actually Costs
Learn

What UAE IA Compliance Actually Costs

The UAE IA Regulation publishes no price. It publishes the mandates that create one: an always applicable core, justified exclusions, and P1 first.

Saudi NCA ECC Requirements Explained
Learn

Saudi NCA ECC Requirements Explained

ECC-2:2024 is 4 domains, 28 subdomains and 108 controls, not the 114 across 5 that most guides still quote. What each domain asks, and what 2024 moved.

Incident Reporting Deadlines by Regulation
Learn

Incident Reporting Deadlines by Regulation

DORA gives you 4 hours, NIS2 24, GDPR 72 and the EU AI Act up to 15 days. Every clock, what starts it, and which one binds when several apply at once.

Choosing a CRA Compliance Tool
Learn

Choosing a CRA Compliance Tool

What a CRA compliance tool must actually do: the five jobs, the 24 and 72 hour clock that rules out a spreadsheet, and 12 questions to put to any vendor.

SAMA CSF Requirements Explained
Learn

SAMA CSF Requirements Explained

The SAMA Cyber Security Framework sets four domains, 32 subdomains and maturity level 3 as the floor. What each domain asks for, and what SAMA raised.

SAMA CSF Compliance Cost: What Drives It
Learn

SAMA CSF Compliance Cost: What Drives It

SAMA never published a price for CSF compliance. It published the mandates that create one: a cleared full time CISO, maturity level 3, annual pen tests.

NIS2 Audit: What to Expect
Learn

NIS2 Audit: What to Expect

Essential entities can be audited with no incident first, important entities only after evidence of a breach. What Articles 32 and 33 actually allow.

Cyber Resilience Act Compliance Cost
Learn

Cyber Resilience Act Compliance Cost

The Commission put CRA compliance at EUR 29 billion across 615,272 manufacturers. Do the division: about EUR 47,000 each, and here is where it goes.

eIDAS 2.0 Compliance Cost: What to Budget
Learn

eIDAS 2.0 Compliance Cost: What to Budget

The Commission priced a relying party's first year at EUR 60,000 to 70,000. What that estimate covers, what it leaves out, and how to size your own.

Cyber Resilience Act Fines and Penalties
Learn

Cyber Resilience Act Fines and Penalties

CRA fines reach 15 million euros or 2.5% of worldwide annual turnover, whichever is higher. The three tiers, what triggers each, and who issues them.

Cyber Resilience Act Compliance Timeline
Learn

Cyber Resilience Act Compliance Timeline

How long does Cyber Resilience Act compliance take? For most manufacturers 12 to 24 months. The phases, what drives the range, and the date to plan against.

EU AI Act Compliance Cost: What It Depends On
Learn

EU AI Act Compliance Cost: What It Depends On

The Act prices roles and risk classes, not companies. What the cost is made of, where the quoted figures came from, and the step that removes most of it.

Vendor Security Questionnaires: A Guide
Learn

Vendor Security Questionnaires: A Guide

Questionnaires come back late for three fixable reasons. How to size one to the supplier, send it so it gets answered, and stop chasing by hand.

Third-Party Risk Management Process Flow
Learn

Third-Party Risk Management Process Flow

The flow is simple and it stalls in the same place every time: waiting on the supplier. Where each stage hands off, and how to stop the queue building.

How to Perform a Third-Party Risk Assessment
Learn

How to Perform a Third-Party Risk Assessment

Assessing every supplier the same way is why most programmes stall. Tier first, set depth by tier, and the work becomes finishable. Seven steps.

How to Create a Risk Register
Learn

How to Create a Risk Register

A risk register that survives an audit needs two scores, a named owner and a link to controls. The seven steps, the columns, and the mistakes to avoid.

Automated Access Review Software Explained
Learn

Automated Access Review Software Explained

What actually gets automated in an access review, what has to stay human, and how to tell the difference before you buy. With the scoring model in full.

EU AI Act AI Literacy Requirements
Learn

EU AI Act AI Literacy Requirements

Article 4 already applies, it binds providers and deployers alike, and it is the cheapest EU AI Act obligation to satisfy and to evidence.

NIS2 vs ISO 27001: How They Overlap
Learn

NIS2 vs ISO 27001: How They Overlap

ISO 27001 covers much of what NIS2 asks for, and satisfies none of it by itself. Where the overlap is real, and the four gaps certification leaves.

EU AI Act Penalties and Fines Explained
Learn

EU AI Act Penalties and Fines Explained

Article 99 sets three tiers, up to 35M EUR or 7% of worldwide turnover. The rule for SMEs inverts the usual formula, and most summaries get it wrong.

EU AI Act Policies and Documentation
Learn

EU AI Act Policies and Documentation

The EU AI Act asks for a document set rather than a policy. Here is what a high-risk provider has to be able to produce, article by article.

NIS2 Compliance Cost: What to Budget
Learn

NIS2 Compliance Cost: What to Budget

Germany priced NIS2 for its own economy: about 2.1bn one-off and 2.2bn a year across 30,000 entities. Here is what that arithmetic means for your budget.

How Long Does DORA Compliance Take?
Learn

How Long Does DORA Compliance Take?

DORA has applied since January 2025, so the real question is how long from a standing start. The honest answer, phase by phase, with the long pole named.

NIS2 Fines and Penalties: What You Actually Risk
Learn

NIS2 Fines and Penalties: What You Actually Risk

NIS2 sets minimum ceilings: EUR 10M or 2% of turnover for essential entities, 7M or 1.4% for important ones, plus personal liability for managers.

DORA Compliance Cost: A Line-by-Line Model (2026)
Learn

DORA Compliance Cost: A Line-by-Line Model (2026)

Published DORA cost estimates disagree by orders of magnitude. Here is the line-by-line model that produces your number, work item by work item.

Bilingual Policies and Evidence for Gulf Regulators
Learn

Bilingual Policies and Evidence for Gulf Regulators

How to run Arabic and English compliance documentation together: which language binds, what needs translating, fixed terminology and per-document language.

NIS2 Solutions for Banks: What Applies vs DORA
Learn

NIS2 Solutions for Banks: What Applies vs DORA

NIS2 solutions for banks: why DORA is the operative regime, where NIS2 still applies across the group, and what your platform must do. Reviewed July 2026.

ISO 27001 Annex A: How the 93 Controls Are Organised
Learn

ISO 27001 Annex A: How the 93 Controls Are Organised

How ISO 27001:2022 Annex A is organised: the four themes, what changed from 2013, how the Statement of Applicability selects controls, and who has to comply.

What Is SOC 2? Type 1 vs Type 2, Explained
Learn

What Is SOC 2? Type 1 vs Type 2, Explained

SOC 2 explained: what the AICPA attestation report is, the five Trust Services Criteria, Type 1 vs Type 2, and which SaaS vendors need it. Reviewed July 2026.

PCI DSS: Who Must Comply and Which SAQ Applies
Learn

PCI DSS: Who Must Comply and Which SAQ Applies

PCI DSS applies to any business that stores, processes or transmits cardholder data. Learn who must comply and which SAQ fits your setup. Reviewed July 2026.

What Is HIPAA Compliance? Covered Entities and BAAs
Learn

What Is HIPAA Compliance? Covered Entities and BAAs

HIPAA compliance explained: covered entities, business associates, BAAs, the Privacy, Security and Breach Notification Rules, penalties. Reviewed July 2026.

What Is NIS2 and Who Must Comply in 2026?
Learn

What Is NIS2 and Who Must Comply in 2026?

What is NIS2 and who must comply? The 2026 scope guide: sectors, size thresholds, essential vs important, obligations and penalties. Reviewed July 2026.

eIDAS Compliance Software: An eIDAS 2.0 Buyer's Guide
Learn

eIDAS Compliance Software: An eIDAS 2.0 Buyer's Guide

eIDAS compliance software compared: the three product categories buyers confuse, and what a real eIDAS 2.0 governance layer must cover before 2027.

The Cyber Resilience Act Deadlines: 2026 and 2027
Learn

The Cyber Resilience Act Deadlines: 2026 and 2027

CRA reporting obligations start on 11 September 2026 and the regulation applies in full on 11 December 2027. The complete timeline and what binds when.

Who Must Comply With the Cyber Resilience Act?
Learn

Who Must Comply With the Cyber Resilience Act?

CRA scope follows the product, not the sector. The digital-elements test, the three economic operators, Annex III and IV, and the 2026 and 2027 deadlines.

How to Become Compliant: A Step-by-Step Guide (2026)
Learn

How to Become Compliant: A Step-by-Step Guide (2026)

How to become compliant without drowning in spreadsheets: find which rules apply, run a gap analysis, remediate, collect evidence once, pass the audit.

The eIDAS 2.0 Deadline: What Happens by 24 December 2027
Learn

The eIDAS 2.0 Deadline: What Happens by 24 December 2027

By 24 December 2027, private relying parties that require strong authentication must accept the EU Digital Identity Wallet. Who it binds, and the timeline.

eIDAS 2.0 Scope: Who Must Accept the EUDI Wallet?
Learn

eIDAS 2.0 Scope: Who Must Accept the EUDI Wallet?

Use this role-based decision tree to see when eIDAS 2.0 applies, when EUDI Wallet acceptance is mandatory, and which SME exemptions matter.

Solvency II Software: A Pillar 2 Buyer's Guide
Learn

Solvency II Software: A Pillar 2 Buyer's Guide

Solvency II software compared: the three tool categories, what a Pillar 2 governance platform needs, and how a crosswalk cuts duplicate work.

EU AI Act vs DORA: Comply With Both, One Programme
Learn

EU AI Act vs DORA: Comply With Both, One Programme

EU AI Act and DORA overlap in five zones. Run both from one compliance programme instead of two, and see exactly where the requirements meet.

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027
Learn

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027

The August 2026 high-risk deadline moved to December 2027 for standalone systems. What still binds in 2026, and what high-risk providers must build now.

EU AI Act Conformity Assessment for High-Risk AI in Financial Services
Learn

EU AI Act Conformity Assessment for High-Risk AI in Financial Services

Article 43 conformity assessment for high-risk financial AI, covering credit scoring and insurance pricing, and why the deadline moved to December 2027.

DORA vs NIS2: Key Differences and Who's Covered
Learn

DORA vs NIS2: Key Differences and Who's Covered

DORA vs NIS2: two EU cyber regulations with confusingly close names and very different obligations. See which one applies to your organisation, and why.

DORA TLPT: Threat-Led Penetration Testing in 2026
Learn

DORA TLPT: Threat-Led Penetration Testing in 2026

DORA threat-led penetration testing under Articles 26 and 27: who gets designated, the TIBER-EU phases in RTS 2025/1190, and how to plan the engagement.

DORA Key Risk Indicators: Article-by-Article Guide
Learn

DORA Key Risk Indicators: Article-by-Article Guide

Fourteen DORA key risk indicators, each mapped to the article of Regulation 2022/2554 it helps evidence, with every article number checked against the text.

Key Risk Indicators (KRIs): 14 to Track in 2026
Learn

Key Risk Indicators (KRIs): 14 to Track in 2026

Key Risk Indicators explained for CISOs and CROs, with thresholds, formulas and a 14-KRI starter pack mapped to ISO 27001, NIS2, DORA and NIST CSF.

ISO 42001 vs EU AI Act: Do You Need Both?
Learn

ISO 42001 vs EU AI Act: Do You Need Both?

One is voluntary certification, one is binding law. See exactly where they overlap so you build AI governance once, not twice, and what each requires.

VARA Data Protection: UAE PDPL Rules for VASPs
Learn

VARA Data Protection: UAE PDPL Rules for VASPs

VARA binds every VASP to the UAE PDPL, a mandatory DPO, and a notify-VARA step within 24 hours. What the Technology and Information Rulebook requires.

VARA Incident Reporting: The 72-Hour Clock
Learn

VARA Incident Reporting: The 72-Hour Clock

VARA's 72-hour notification runs from detection under Rule I.K.1. What triggers it, what the report must contain, and the 24-hour personal data clock.

VARA Key and Wallet Management: What the Rules Say
Learn

VARA Key and Wallet Management: What the Rules Say

VARA key and wallet duties come in three tiers: four binding Rules in Part I Section D, Schedule 1 Guidance, and custody-only rules. What each one requires.

VARA Compliance Guide for Dubai VASPs 2026
Learn

VARA Compliance Guide for Dubai VASPs 2026

What a Dubai VASP licence requires: the four compulsory rulebooks, 19 cybersecurity criteria, the 72 and 24 hour clocks, and the capital floors.

VARA Penetration Testing and Smart Contract Audits
Learn

VARA Penetration Testing and Smart Contract Audits

Rule I.E.1 has two triggers, not one: at least annually AND before any new system, application or product ships. What VARA binds, and what is only Guidance.

VARA Cybersecurity Policy: The 19 Mandatory Criteria
Learn

VARA Cybersecurity Policy: The 19 Mandatory Criteria

VARA's rulebook lists 19 minimum cybersecurity policy criteria, not 18. Each in the rulebook's words, plus the two ISO 27001 templates always miss.

VARA CISO Appointment and Staff Competency Rules
Learn

VARA CISO Appointment and Staff Competency Rules

VARA's CISO rule sits in the Technology and Information Rulebook. What Part I Sections I and J actually require of your compliance team, and what they do not.

DORA Supervisory Assessments: 2026 Guide
Learn

DORA Supervisory Assessments: 2026 Guide

DORA supervision is live. How it is structured across the NCAs and ESAs, what a supervisor can demand, and the evidence to have ready before they ask.

DORA Compliance Gap Assessment: EU Banks
Learn

DORA Compliance Gap Assessment: EU Banks

Enforcement is live and supervisors keep flagging the same five DORA gaps at EU banks. See where they fail and how to close each before your assessment.

DORA 'Significant': The Critical ICT Provider Test
Learn

DORA 'Significant': The Critical ICT Provider Test

Will the ESAs designate your firm a critical ICT third-party provider? See the thresholds behind DORA's 'significant' test and where it bites.

DORA Operational Resilience Testing: Article 24
Learn

DORA Operational Resilience Testing: Article 24

What DORA Article 24 really requires of a resilience testing programme, where the board approval duty comes from, and which quoted numbers are invented.

DORA Major Incident Classification: 7 Criteria
Learn

DORA Major Incident Classification: 7 Criteria

Do you owe your regulator a report in 4 hours? The exact test in Delegated Regulation 2024/1772, every threshold, and the 4h, 72h and 1-month clock.

DORA ICT Third-Party Risk: Build a Compliant Vendor Register
Learn

DORA ICT Third-Party Risk: Build a Compliant Vendor Register

Build a DORA vendor register from scratch: the nine mandatory contract clauses, six more for critical functions, the subcontracting RTS and exit tests.

DORA ICT Risk Management Framework: Article-by-Article Guide
Learn

DORA ICT Risk Management Framework: Article-by-Article Guide

What DORA Chapter II and RTS 2024/1774 require an ICT risk management framework to contain, chapter by chapter, with every citation checked.

EU AI Act for Healthcare: Which AI Must Comply
Learn

EU AI Act for Healthcare: Which AI Must Comply

Most medical and diagnostic AI is high-risk under the EU AI Act. Which systems fall under Annex I or Annex III, and what each route demands by 2027.

Does the EU AI Act Apply Outside the EU?
Learn

Does the EU AI Act Apply Outside the EU?

Selling AI into the EU from outside it usually puts you in scope. The output-used-in-the-EU trigger, the authorised representative rule and the deadlines.

EU AI Act: Who's in Scope and the 2025-28 Deadlines
Learn

EU AI Act: Who's in Scope and the 2025-28 Deadlines

Does the EU AI Act apply to you? Map your systems to the risk tiers and the 2025 to 2028 deadlines, including high-risk moving to 2 December 2027.

DORA Gap Assessment: Score Your Readiness
Learn

DORA Gap Assessment: Score Your Readiness

Score your DORA readiness across seven domains, each anchored to the article it comes from, then weight the gaps so you know what to fix first.

DORA Register of Information: 15 Official Templates Explained
Learn

DORA Register of Information: 15 Official Templates Explained

The DORA Register of Information explained: all 15 templates from Implementing Regulation 2024/2956, how they connect, and how to file one clean submission.

Why Your DORA Register of Information Gets Rejected
Learn

Why Your DORA Register of Information Gets Rejected

The seven ESA rule codes that actually reject a Register of Information submission, what causes each one, and how to clear the validation cascade.

DORA Register of Information Software Ranked
Learn

DORA Register of Information Software Ranked

Your Register of Information is regulatory data, not a spreadsheet. Compare the tools that export clean XBRL OIM-CSV your NCA accepts on the first try.