Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

51 changes tracked across 21 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR
[NEU] [hoch] Podman Desktop: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
A new high-severity vulnerability has been published concerning Podman Desktop, a container management tool. The flaw, identified as WID-SEC-2026-0992 by the German Federal Office for Information S...
Read analysis →
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
CISA has published a Cybersecurity Advisory (AA26-097a) detailing ongoing exploitation of programmable logic controllers (PLCs) by Iranian-affiliated cyber actors. The advisory warns that these act...
Read analysis →
EDPB-EDPS Joint Opinion on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 Directive
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on two legislative proposals: the Cybersecurity Act 2 and amendments to the NIS 2 Directive. T...
Read analysis →
Towards trustworthy AI in the EU public administration: The EDPS Compass for its new role under the AI Act
On 17 March 2026, the European Data Protection Supervisor (EDPS) published a strategic document titled "The EDPS Compass." This outlines the supervisory authority's intended approach and priorities...
Read analysis →
New episode on the Digital Identity Wallets is out!
The European Data Protection Supervisor (EDPS) has published a new informational episode concerning the implementation of the eIDAS2 framework, specifically focused on Digital Identity Wallets. Thi...
Read analysis →
NIS 2 : l’ANSSI poursuit et renforce sa dynamique d’accompagnement
The French National Agency for the Security of Information Systems (ANSSI) has published new guidance and support initiatives to aid in the implementation of the transposed NIS2 Directive. This upd...
Read analysis →
NIS 2 : les entités assujetties peuvent se pré-enregistrer
The French National Cybersecurity Agency (ANSSI) has announced the opening of a pre-registration portal for entities in scope of the NIS 2 Directive. This is a key procedural step ahead of the form...
Read analysis →
Cyber Resilience Act: BSI übernimmt den Vorsitz der AdCo CRA
The German Federal Office for Information Security (BSI) has officially assumed the chairmanship of the Administrative Cooperation Group (AdCo) for the Cyber Resilience Act (CRA). This group is the...
Read analysis →
Cyber Resilience Act: BSI wird marktüberwachende Behörde
The German Federal Office for Information Security (BSI) has been officially designated as the national market surveillance authority for the Cyber Resilience Act (CRA). This announcement confirms ...
Read analysis →
Press release - Artificial Intelligence Act: delayed application, ban on nudifier apps
The European Parliament has published a press release confirming a delayed application timeline for the EU AI Act. The core prohibition on banned AI practices, including the specific ban on 'nudifi...
Read analysis →
Press release - Global Gateway: MEPs deplore lack of transparency and democratic accountability
The European Parliament has issued a critical press release concerning the EU's Global Gateway strategy, operating under the framework of the recently enacted Cyber Resilience Act (CRA). MEPs forma...
Read analysis →
[UPDATE] [mittel] Red Hat Enterprise Linux (Gatekeeper): Mehrere Schwachstellen ermöglichen Denial of Service
A new security advisory has been published regarding multiple vulnerabilities in Red Hat Enterprise Linux (RHEL) that could enable Denial of Service (DoS) attacks. The advisory, identified as WID-S...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board has published the agenda for the IAPP Global Summit 2026, serving as a key forward-looking resource on the operationalization of the EU AI Act. This agenda outlin...
Read analysis →
Patrick Montagner: Banking supervision in a fragmented credit market: interconnections matter
In an interview published on 24 March 2026, ECB Supervisory Board member Patrick Montagner outlined evolving supervisory expectations regarding risk management in a fragmented credit market. The fo...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board (EDPB) has published its agenda for the IAPP Global Summit 2026, highlighting key regulatory priorities. This agenda signals the EDPB's focus on the operational c...
Read analysis →
EDPB-EDPS Joint Opinion 4/2026 on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 ...
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on the proposed Cybersecurity Act 2 and amendments to the NIS 2 Directive. This opinion provid...
Read analysis →
EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
The EDPB and EDPS have issued a joint opinion endorsing the European Commission's draft implementing acts for the NIS2 Directive. This opinion supports measures designed to standardize and clarify ...
Read analysis →
CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR
The European Data Protection Board (EDPB) has launched its 2026 Coordinated Enforcement Framework (CEF) action, focusing on the practical application of GDPR transparency and information obligation...
Read analysis →
DORA – Register of Information collection – Update
The CSSF has published an update regarding the collection of information for the DORA Register. This involves the formal issuance of templates and technical specifications that financial entities m...
Read analysis →
ESMA consults on post-trade risk reduction services under EMIR 3
ESMA has launched a public consultation on proposed technical standards for post-trade risk reduction (PTRR) services under the revised EMIR framework (EMIR 3). This initiative, developed within th...
Read analysis →