
NIS2·
NIS2 and the CRA: two clocks on one factory
NIS2 regulates the plant you run. The CRA regulates what leaves it. Two 24-hour clocks, two different triggers — and in most factories, no owner.

DORA·
Your DORA register got accepted. Now supervisors read it.
Two DORA register of information filings in, 'accepted' means the file parsed. What supervisors now read from it, and what to fix before 31 December.

ISO 42001·
ISO 42001, Sized for SMBs: The AI Certificate Your Buyers Will Ask For Before the Regulator Does
ISO 42001 is the first certifiable AI management system standard. What's inside, what it costs an SMB, and why buyers will ask before the regulator does.

Cyber Resilience Act·
CRA reporting is live. You may be the manufacturer.
CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

AI Act·
On 2 August, Your Chatbot Must Say It's a Bot. The AI Deadline the Omnibus Didn't Move.
Everyone heard the AI Act was delayed sixteen months. Article 50 wasn't. From 2 August 2026, your chatbot must say it's a bot — fines up to €15M or 3%.

AI Act·
AI Omnibus: The 16-Month AI Act Reprieve, and Why Your Real Deadline Just Got Closer
The AI Omnibus is law. It moved the high-risk deadline to December 2027 — and created a new one on 2 December 2026, in the €35M/7% penalty band.

DORA·
You're Not a Bank. DORA Still Applies. And the First Inspections Have Started.
DORA has been fully applicable since 17 January 2025. Most non-banks read that as someone else's problem. In 2026, that misread becomes a supervisory problem.

NIS2·
NIS2 Enforcement Has Started: 8 Questions Your Board Must Answer in the First 30 Days
NIS2 is now enforced across most of the EU. Article 20 puts directors personally on the hook. Eight questions every board must answer in 30 days.