Compliance

The 2026 rulebook all points to one question.

DORA, NIS2 and the EU AI Act converge on the same demand: know where your data lives, control who can touch it, and prove you can operate through faults and audits. We map your exposure to each — and produce the evidence.

01The regimes

The regimes that matter. One sovereignty posture.

Each block: what it demands, and where you're typically exposed. We track the full landscape of thirteen UK, EU and US regimes in the Regulatory Change Tracker.

01

DORA

Digital Operational Resilience Act

In force · January 2025

Regulated financial entities must withstand, respond to and recover from ICT disruption — and prove it.

Typical exposure

Most critical workloads sit with US hyperscalers and processors, with no concentration register and no tested exit.

Read the official text — Regulation (EU) 2022/2554

What it requires

  • Full audit rights and contractual control over outsourced ICT
  • Active management of concentration risk across providers
  • Demonstrably sovereign incident response and data recovery
  • A tested exit strategy for every critical provider
02

NIS2

Network & Information Security Directive 2

Transposing · registrations through 2026

Essential and important entities are accountable for the security and sovereignty of their whole supply chain.

Typical exposure

No end-to-end supply-chain map, and critical suppliers sitting under foreign jurisdiction.

Read the official text — Directive (EU) 2022/2555

What it requires

  • Supply-chain security and sub-processor accountability
  • Entity registration with national authorities
  • Incident reporting within strict deadlines
  • Management-level accountability for security posture
03

EU AI Act

Regulation (EU) 2024/1689

Full application · 2 August 2026 · fines to 7% of turnover

High-risk AI systems require documented data governance, quality controls and complete audit trails.

Typical exposure

Staff paste customer data into US-hosted AI tools with no audit log of what was sent or returned.

Read the official text — Regulation (EU) 2024/1689

What it requires

  • Data-governance frameworks with documented sources
  • Quality controls and complete audit trails
  • Transparency and human-oversight obligations
  • Records of where AI processing happens
04

GDPR / Schrems II

General Data Protection Regulation

In force · transfers contested since 2020

International transfers to US-jurisdiction infrastructure remain legally contested and a fine risk.

Typical exposure

EU personal data stored on US-controlled infrastructure post-Schrems II remains ambiguous.

Read the official text — Regulation (EU) 2016/679

What it requires

  • A lawful basis and safeguards for international transfers
  • Data-processing agreements with every processor
  • Demonstrable control over where personal data is processed
  • Up to €20m / 4% turnover exposure for breaches
05

EUCS

EU Cloud Services scheme & Sovereignty Framework

Framework published · October 2025

A common yardstick for cloud sovereignty: residency, key control, transparency and resistance to foreign compulsion.

Typical exposure

Cloud providers headquartered outside the EU, exposed to foreign government access.

Read the official text — EU Cloud Sovereignty Framework

What it requires

  • EU-certified data residency
  • BYOK / HYOK customer-controlled key management
  • Sub-processor transparency
  • Contractual resistance to extraterritorial legal compulsion
06

eIDAS 2.0

EU Digital Identity Regulation

In force · EU Digital Identity Wallet rolling out

A sovereign European identity layer — the EU Digital Identity Wallet — that you'll be expected to support.

Typical exposure

Identity and SSO concentrated on US providers such as Okta and Auth0.

Read the official text — Regulation (EU) 2024/1183

What it requires

  • Readiness to accept the EU Digital Identity Wallet
  • Sovereign, auditable identity and access management
  • Reduced reliance on US identity providers
07

EU Data Act

Regulation (EU) 2023/2854

Applicable since 12 September 2025

Cloud customers gain a right to switch providers, and providers must shield EU data from unlawful third-country government access.

Typical exposure

Lock-in to a single US hyperscaler, and exposure to extraterritorial demands such as the US CLOUD Act.

Read the official text — Regulation (EU) 2023/2854

What it requires

  • Remove all barriers to switching cloud providers
  • A switching right written into every customer contract
  • Block unlawful non-EU government access to EU data
  • Assess and challenge disproportionate foreign access requests
08

Cloud & AI Development Act

CADA · part of the Technological Sovereignty Package

Proposed · 3 June 2026 · targeted ~Q4 2027

A single EU framework grading cloud and AI sovereignty across four assurance levels, with implications for procurement and critical infrastructure.

Typical exposure

Infrastructure subject to foreign extraterritorial law may lose public-procurement and high-security eligibility.

Read the official text — CADA proposal · European Commission

What it requires

  • Sovereignty graded across four assurance levels
  • Independence from third-country control for sensitive tiers
  • Supply-chain transparency
  • EU-origin criteria for critical infrastructure
02The convergence

“Know where data lives, control who can touch it, and prove you can operate through faults and audits.”

By 2026, GDPR, NIS2, DORA and the EU AI Act all resolve to the same outcome. Get that right once and you satisfy them together — which is exactly what the platform and our audits are built to do.

Get audit-ready

Turn the rulebook into evidence.

Start with a free assessment, or talk to us about mapping your full position against DORA, NIS2 and the AI Act.