Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

782 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
Press release - Artificial Intelligence Act: delayed application, ban on nudifier apps
The European Parliament has published a press release confirming a delayed application timeline for the EU AI Act. The core prohibition on banned AI practices, including the specific ban on 'nudifi...
Read analysis →
Press release - Global Gateway: MEPs deplore lack of transparency and democratic accountability
The European Parliament has issued a critical press release concerning the EU's Global Gateway strategy, operating under the framework of the recently enacted Cyber Resilience Act (CRA). MEPs forma...
Read analysis →
[UPDATE] [mittel] Red Hat Enterprise Linux (Gatekeeper): Mehrere Schwachstellen ermöglichen Denial of Service
A new security advisory has been published regarding multiple vulnerabilities in Red Hat Enterprise Linux (RHEL) that could enable Denial of Service (DoS) attacks. The advisory, identified as WID-S...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board has published the agenda for the IAPP Global Summit 2026, serving as a key forward-looking resource on the operationalization of the EU AI Act. This agenda outlin...
Read analysis →
Patrick Montagner: Banking supervision in a fragmented credit market: interconnections matter
In an interview published on 24 March 2026, ECB Supervisory Board member Patrick Montagner outlined evolving supervisory expectations regarding risk management in a fragmented credit market. The fo...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board (EDPB) has published its agenda for the IAPP Global Summit 2026, highlighting key regulatory priorities. This agenda signals the EDPB's focus on the operational c...
Read analysis →
EDPB-EDPS Joint Opinion 4/2026 on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 ...
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on the proposed Cybersecurity Act 2 and amendments to the NIS 2 Directive. This opinion provid...
Read analysis →
EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
The EDPB and EDPS have issued a joint opinion endorsing the European Commission's draft implementing acts for the NIS2 Directive. This opinion supports measures designed to standardize and clarify ...
Read analysis →
CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR
The European Data Protection Board (EDPB) has launched its 2026 Coordinated Enforcement Framework (CEF) action, focusing on the practical application of GDPR transparency and information obligation...
Read analysis →
DORA – Register of Information collection – Update
The CSSF has published an update regarding the collection of information for the DORA Register. This involves the formal issuance of templates and technical specifications that financial entities m...
Read analysis →
ESMA consults on post-trade risk reduction services under EMIR 3
ESMA has launched a public consultation on proposed technical standards for post-trade risk reduction (PTRR) services under the revised EMIR framework (EMIR 3). This initiative, developed within th...
Read analysis →
ESMA sets out clearing thresholds under EMIR 3
ESMA has published its final report setting the clearing thresholds under the updated EMIR 3 framework, which is part of the broader DORA regulatory initiative. This establishes the quantitative le...
Read analysis →
How does ENISA cooperate with users of the EU Cybersecurity Reserve? Who decides which entity should benefit from ser...
ENISA has published operational details on the cooperation framework for the EU Cybersecurity Reserve, a key mechanism established under the NIS2 Directive. The update clarifies the process for req...
Read analysis →
Claudia Buch: AMLA and ECB Banking Supervision: strengthening cooperation
In a February 2026 speech, ECB supervisory chair Claudia Buch outlined enhanced cooperation between the future Anti-Money Laundering Authority (AMLA) and ECB Banking Supervision. The key change is ...
Read analysis →
DORA – Submission timeframe for register of information for third-country branches of credit institutions having thei...
The CSSF has published a communication specifying the submission timeframe for a key DORA requirement. It mandates that third-country branches of credit institutions, whose head office is outside t...
Read analysis →
How could a cybersecurity company join the EU Cybersecurity Reserve?
ENISA has published guidance on the process for cybersecurity companies to join the newly established EU Cybersecurity Reserve. This voluntary pool of trusted private sector incident response servi...
Read analysis →
How will the EU Cybersecurity Reserve be funded?
ENISA has published guidance clarifying the funding mechanism for the new EU Cybersecurity Reserve, a key operational capability established under the NIS2 Directive. The Reserve is designed to pro...
Read analysis →
Does the EU Cybersecurity Reserve only provide incident reponse and initial recovery actions?
ENISA has published a clarification on the scope of assistance available from the EU Cybersecurity Reserve. This operational tool, established under the NIS2 Directive, is confirmed to provide supp...
Read analysis →
Is any non-EU country eligible to receive support from the EU Cybersecurity Reserve?
ENISA has published a clarification confirming that non-EU countries are eligible to receive support from the EU Cybersecurity Reserve. This operational detail stems from the NIS2 Directive and the...
Read analysis →
The EBA publishes follow-up Report on ICT risk assessment under the Supervisory Review and Evaluation Process
The European Banking Authority (EBA) has published a follow-up report on integrating Information and Communication Technology (ICT) risk into the Supervisory Review and Evaluation Process (SREP). T...
Read analysis →