LEARN
Deep-dive guides on EU compliance frameworks and regulatory requirements.

What Is NIS2 and Who Must Comply in 2026?
What is NIS2 and who must comply? The 2026 scope guide: sectors, size thresholds, essential vs important, obligations and penalties. Reviewed July 2026.

What Is HIPAA Compliance? Covered Entities and BAAs
HIPAA compliance explained: covered entities, business associates, BAAs, the Privacy, Security and Breach Notification Rules, penalties. Reviewed July 2026.

PCI DSS: Who Must Comply and Which SAQ Applies
PCI DSS applies to any business that stores, processes or transmits cardholder data. Learn who must comply and which SAQ fits your setup. Reviewed July 2026.

What Is SOC 2? Type 1 vs Type 2, Explained
SOC 2 explained: what the AICPA attestation report is, the five Trust Services Criteria, Type 1 vs Type 2, and which SaaS vendors need it. Reviewed July 2026.

ISO 27001 Annex A: The 93 Controls Explained (2022)
ISO 27001 Annex A controls explained: the 93 controls, four themes, the Statement of Applicability, 2022 changes, and who must comply. Reviewed July 2026.

eIDAS 2.0 Scope: Who Must Accept the EUDI Wallet?
Use this role-based decision tree to see when eIDAS 2.0 applies, when EUDI Wallet acceptance is mandatory, and which SME exemptions matter.

The eIDAS 2.0 Deadline: What Happens by 24 December 2027
eIDAS 2.0 (Regulation (EU) 2024/1183) entered into force on 20 May 2024. By 24 December 2027, private relying parties legally or contractually required to use strong user authentication must accept the EU Digital Identity Wallet. Here is who it binds and the full timeline.

How to Become Compliant: A Step-by-Step Guide (2026)
A practical, framework-agnostic guide to becoming compliant: work out which regulations apply to you, run a gap analysis, remediate, collect evidence once, pass the audit, and stay compliant without drowning in spreadsheets.

Who Must Comply With the Cyber Resilience Act?
CRA scope follows the product, not the sector. See the products-with-digital-elements test, the three economic operators, Annex III and IV classification, the 11 Sep 2026 and 11 Dec 2027 deadlines, the Article 14 reporting clock, and the penalties.

The Cyber Resilience Act Deadlines: 2026 and 2027
The CRA entered into force on 10 December 2024. Reporting obligations begin on 11 September 2026 and the regulation applies in full on 11 December 2027. Here is the full timeline.

Solvency II Software: A Pillar 2 Buyer's Guide
Solvency II software compared: the three tool categories, what a Pillar 2 governance platform needs, and how a crosswalk cuts duplicate work.

EU AI Act vs DORA: Comply With Both, One Programme
EU AI Act and DORA overlap in five zones. Run both from one compliance programme instead of two, and see exactly where the requirements meet.

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027
The 2 August 2026 EU AI Act high-risk deadline was postponed by the Digital Omnibus (adopted 29 June 2026) to 2 December 2027 for standalone systems and 2 August 2028 for product-embedded ones. Here is what actually binds in August 2026 and what high-risk providers must still build.

EU AI Act Conformity Assessment for High-Risk AI in Financial Services
How the Article 43 conformity assessment works for high-risk financial AI - credit scoring and insurance pricing - and why the Digital Omnibus moved the deadline from August 2026 to 2 December 2027.

DORA vs NIS2: Key Differences and Who's Covered
DORA vs NIS2: two EU cyber regulations with confusingly close names and very different obligations. See which one applies to your organisation, and why.

DORA TLPT: Threat-Led Penetration Testing in 2026
Threat-led penetration testing under DORA Articles 26 and 27: who competent authorities designate, the TIBER-EU based phases in RTS 2025/1190, and how to plan the engagement.
Key Risk Indicators (KRIs): 14 to Track in 2026
Key Risk Indicators explained for CISOs and CROs, with thresholds, formulas and a 14-KRI starter pack mapped to ISO 27001, NIS2, DORA and NIST CSF.
DORA Key Risk Indicators: Article-by-Article Guide
Fourteen DORA key risk indicators, each mapped to the article of Regulation (EU) 2022/2554 it helps evidence, with every article number checked against the text.

ISO 42001 vs EU AI Act: Do You Need Both?
One is voluntary certification, one is binding law. See exactly where they overlap so you build AI governance once, not twice, and what each requires.

VARA CISO Appointment and Staff Competency Rules
The CISO rule sits in VARA's Technology and Information Rulebook, not the Company Rulebook. What Part I Sections I and J actually require, and what they do not.

VARA Cybersecurity Policy: The 19 Mandatory Criteria
VARA's Technology and Information Rulebook lists 19 minimum cybersecurity policy criteria, (a) to (s), not 18. Here is each one in the rulebook's own words, with the two that generic ISO 27001 templates always miss.

VARA Penetration Testing and Smart Contract Audits
Rule I.E.1 has two triggers, not one: at least annually AND before any new system, application or product ships. What VARA binds, and what is only Guidance.

VARA Compliance Guide for Dubai VASPs 2026
What a Dubai VASP licence actually requires: the four compulsory rulebooks, the 19 cybersecurity policy criteria, the 72 hour and 24 hour clocks, and the capital floors, with the rule reference for each.

VARA Key and Wallet Management: What the Rules Say
VARA key and wallet duties come in three tiers: four binding Rules in Part I Section D, Schedule 1 Guidance, and custody-only rules. What each one requires.

VARA Incident Reporting: The 72-Hour Clock
VARA's 72-hour notification runs from detection, under Rule I.K.1 of the Technology and Information Rulebook. Here is what triggers it, what the report must contain, and the 24-hour personal data clock that runs alongside it.

VARA Data Protection: UAE PDPL Rules for VASPs
VARA's Technology and Information Rulebook binds every VASP to the UAE PDPL, a mandatory DPO, and a notify-VARA step within 24 hours of reporting an incident. Here is what the rulebook actually requires.

DORA Supervisory Assessments: 2026 Guide
DORA has applied since 17 January 2025 and is supervised by national competent authorities and the ESAs. How DORA supervision is structured, what a supervisor can request, and the evidence to have ready.

DORA ICT Risk Management Framework: Article-by-Article Guide
What DORA Chapter II and RTS (EU) 2024/1774 actually require an ICT risk management framework to contain, chapter by chapter, with every article citation checked against the official text.

DORA ICT Third-Party Risk: Build a Compliant Vendor Register
DORA Chapter V, Section I, in full: the register of information, the nine contract clauses every ICT contract needs plus six more for critical functions, the subcontracting RTS, and the exit tests.

DORA Major Incident Classification: 7 Criteria
A payment system fails on a Friday afternoon. Whether you owe your regulator a report in 4 hours turns on a precise test in Delegated Regulation (EU) 2024/1772: the criticality gateway plus either a malicious intrusion or two materiality thresholds. Here is the exact logic, every number, and the 4h/72h/1-month clock.

DORA Operational Resilience Testing: Article 24
What DORA Article 24 actually requires of a resilience testing programme, where the board approval obligation really comes from, and which widely quoted numbers are not in the regulation at all.

DORA 'Significant': The Critical ICT Provider Test
Will the ESAs designate your firm a critical ICT third-party provider? See the thresholds behind DORA's 'significant' test and where it bites.

EU AI Act for Healthcare: Which AI Must Comply
Most medical and diagnostic AI is high-risk under the EU AI Act - as a regulated medical device (Annex I) or a standalone Annex III use case. The Digital Omnibus moved the deadlines to 2 August 2028 and 2 December 2027. Here is which systems fall where, and what each route demands.

EU AI Act: Who's in Scope and the 2025-28 Deadlines
Not sure the EU AI Act applies to you? Map your systems to the risk tiers and the phased 2025-2028 deadlines - including the Digital Omnibus postponement of high-risk to 2 December 2027 - to see if you are in scope.

Does the EU AI Act Apply Outside the EU?
Selling AI into the EU from outside it usually puts you in scope. See which non-EU companies the Act catches, the 'output used in the EU' trigger, the authorised representative rule, and the deadlines after the 2026 Digital Omnibus moved high-risk to December 2027.

Why Your DORA Register of Information Gets Rejected
The ESAs publish which register of information errors actually reject a submission and which do not. The seven rejecting rule codes, what causes them, and how to clear the cascade.

DORA Register of Information: 15 Official Templates Explained
The DORA Register of Information is built from 15 official templates set by Commission Implementing Regulation (EU) 2024/2956. This guide explains each template, how they connect, and how to file one clean submission.

DORA Gap Assessment: Score Your Readiness
Score your DORA readiness across seven domains, each anchored to the article it comes from, then weight the gaps so you know what to fix first.
