---
title: "EU Regulations"
description: "Incident reporting, supply chain security, and operational readiness."
canonical: https://www.orbiqhq.com/eu-regulations
html: https://www.orbiqhq.com/eu-regulations
publisher: Orbiq GmbH
language: en
---
# EU Regulations

Incident reporting, supply chain security, and operational readiness.

- [GDPR Compliance 2026: Principles, Rights & Proof](/eu-regulations/gdpr-compliance.md) - GDPR compliance explained for 2026: the 7 principles, 6 lawful bases, data subject rights, the compliance checklist, 2025–26 fines, and UK/Norway divergence.
- [NIS2 Art. 21 & 23: Reporting and Supply Chain Beyond ISMS](/eu-regulations/incident-reporting-supply-chain-nis2-articles-21-23.md) - NIS2 Article 21 and 23 require operational incident reporting (24h and 72h) and supply chain risk management. An ISMS helps governance, but not day to day execution.
- [NIS2 Compliance: How to Achieve and Maintain It (2026)](/eu-regulations/nis2-compliance.md) - A practical guide to NIS2 compliance — step-by-step requirements, gap analysis, implementation roadmap, and tools you need. Learn how to achieve and maintain NIS2 compliance for your organisation.
- [GDPR Compliance for B2B SaaS: Articles 28–34 Explained](/eu-regulations/gdpr-article-28-32-33-34.md) - A B2B SaaS reference to GDPR Articles 28, 32, 33 & 34 — DPAs, security of processing, and breach notification — with a compliance checklist and links to each deep-dive.
- [What Is NIS2? The Complete Guide to the EU NIS2 Directive (2026)](/eu-regulations/what-is-nis2.md) - What is NIS2? The EU NIS2 Directive (2022/2555) requires organisations in 18 critical sectors to implement cybersecurity measures, report incidents, and manage supply chain security. Complete guide covering requirements, penalties, timeline, and how to comply.
- [Subprocessor Management Under GDPR Art. 28](/eu-regulations/subprocessor-management-gdpr-article-28.md) - What do controllers, DPOs, and procurement teams actually expect from your subprocessor management? A practical guide beyond GDPR Article 28 minimum compliance — covering sub-processor lists, change notifications, data flow transparency, and ongoing due diligence.
- [Vendor Assurance Under NIS2: What Article 21 Requires](/eu-regulations/vendor-assurance-nis2.md) - NIS2 Article 21(2)(d) requires continuous supply chain security. Point-in-time vendor assessments are no longer sufficient. Learn what the directive expects and how to meet it operationally.
- [DORA Compliance Guide 2026: Requirements & Deadlines](/eu-regulations/dora-compliance.md) - DORA compliance in 2026: ICT risk management, incident reporting, resilience testing & Register of Information deadlines. See the requirements checklist.
- [DORA Art. 19, 28 & 30: When an ISMS Is No Longer Enough](/eu-regulations/incident-reporting-provider-monitoring-dora-article-19-28-30.md) - DORA requires operational client communication during incidents, an up-to-date ICT provider register, and continuous monitoring. An ISMS alone cannot deliver this.
- [Cyber Resilience Act (CRA): 2026 Compliance Guide](/eu-regulations/cyber-resilience-act.md) - The EU Cyber Resilience Act explained: mandatory requirements for products with digital elements, CE marking, SBOM duties and the September 2026 deadline.
- [GDPR Article 33: 72-Hour Breach Notification Rule (2026)](/eu-regulations/gdpr-article-33.md) - GDPR Article 33: when the 72-hour breach clock starts, exactly what to report, the fines for missing it, how to prove compliance, and the UK & Norway position.
- [Cyber Resilience Act Art. 13 & 14: Why an ISMS Isn't Enough](/eu-regulations/cyber-resilience-act-article-13-14.md) - The CRA requires Security by Design, vulnerability reporting within 24 hours, SBOMs, and CE marking. An ISMS supports governance, but not product-level compliance.
- [GDPR Art. 34: Communicating a Breach to Data Subjects (2026)](/eu-regulations/gdpr-article-34.md) - GDPR Article 34: when you must tell individuals about a breach, the high-risk threshold, the three exceptions that get you out of it, and how to prove it.
- [EU AI Act Compliance: Complete Guide for 2026](/eu-regulations/eu-ai-act-compliance.md) - EU AI Act compliance explained: prohibited AI, high-risk Annex III duties, GPAI obligations, the August 2026 deadline and penalties up to €35M.
- [GDPR Article 32: Security of Processing Requirements (2026)](/eu-regulations/gdpr-article-32.md) - GDPR Article 32 explained: the technical and organisational measures required, whether encryption is mandatory, the risk-based test, fines, and how to prove it.
- [NIS2 Supply Chain Security: Requirements and Gaps (2026)](/eu-regulations/nis2-supply-chain-security.md) - NIS2 supply chain security requirements under Article 21(2)(d) demand continuous vendor oversight — not annual questionnaires. Learn what's required, where your ISMS falls short, and how to build the operational layer you need.
- [NIS2 Requirements: Complete Guide to What You Must Do (2026)](/eu-regulations/nis2-requirements.md) - All NIS2 requirements in one place — the 10 Article 21 risk management measures, incident reporting timelines, management liability, registration obligations, and 2026 enforcement updates.
- [NIS2 Incident Reporting: Meeting the 24-Hour Deadline (2026)](/eu-regulations/nis2-incident-reporting-24-hour-deadline.md) - NIS2 incident reporting requires a 24-hour early warning, 72-hour notification, and one-month final report. Learn what qualifies as a significant incident, what each report must contain, and how to build the operational capability to report under pressure.
- [GDPR Article 28: DPA Requirements & Processor Duties (2026)](/eu-regulations/gdpr-article-28.md) - GDPR Article 28 explained: the mandatory DPA clauses, controller due-diligence duties, sub-processor authorisation, EDPB Opinion 22/2024, and how to prove it.
- [You're NIS2-Affected — Now What? The Gaps Beyond ISMS](/eu-regulations/nis2-affected-operational-gaps-isms.md) - You've checked whether your organization falls under NIS2. The answer is yes. You have an ISMS. And now you're discovering: between what your ISMS covers and what NIS2 operationally requires, there's a gap. This article shows where it lies – and how to close it.
- [NIS2 Compliance Checklist: Complete Article 21 Requirements (2026)](/eu-regulations/nis2-compliance-checklist-article-21.md) - The complete NIS2 compliance checklist covering all ten Article 21 risk management measures. Assess your readiness, identify gaps between your ISMS and NIS2 requirements, and prioritise your compliance roadmap.
- [Incident Response Plan vs. Management System Under NIS2](/eu-regulations/nis2-incident-response-plan-vs-management-system.md) - Every ISMS has an incident response plan. NIS2 requires an incident management system. The difference isn't semantic – it's operational. What an IMS must concretely deliver, which components it needs, and how to make the transition from plan to system.
- [NIS2 Audit Readiness: From Documentation to Evidence](/eu-regulations/nis2-audit-readiness-continuous-evidence.md) - NIS2 gives supervisory authorities the right to request evidence at any time. Not at your next audit. Not with advance notice. Any time. What this means for your evidence management – and why most organizations aren't prepared for it.
- [ISO 27001 Is Not NIS2 Compliance: What's Actually Missing](/eu-regulations/iso27001-not-nis2-compliance.md) - ISO 27001 provides the governance foundation for NIS2 – but not the operational execution. What's missing between ISMS documentation and actual NIS2 compliance, and why that's been a concrete problem since December 6, 2025.
- [NIS2 Third-Party Risk Docs: What Auditors Want to See](/eu-regulations/nis2-third-party-risk-documentation-audit-evidence.md) - The specific evidence and documentation artifacts auditors check during NIS2 supply chain security assessments. Supplier registers, risk classifications, incident communication records, and how a trust center produces audit-ready third-party risk documentation as a natural byproduct.
- [NIS2 Directive (2026): Requirements, Deadlines & Scope](/eu-regulations/nis2-directive.md) - NIS2 Directive (EU 2022/2555): who's in scope (sectors + size thresholds), Article 21 security measures, 24-hour incident reporting, and how to comply.
- [DORA vs NIS2: Key Differences and Overlaps Explained](/eu-regulations/dora-vs-nis2.md) - DORA and NIS2 compared: scope, legal form, incident reporting timelines, penalties, and how lex specialis resolves the overlap between them.
- [EU Compliance Software: Complete Buyer's Guide (2026)](/eu-regulations/eu-compliance-software.md) - How to choose EU compliance software in 2026. Covers NIS2, DORA, GDPR, and CRA requirements, key features to evaluate, EU data residency risks, and how Orbiq compares.
- [TISAX Compliance: Complete Guide for Automotive Suppliers (2026)](/eu-regulations/tisax-compliance.md) - Complete guide to TISAX compliance in 2026 — assessment levels AL1/AL2/AL3, VDA ISA 6.0, ENX portal, costs, timeline, ISO 27001 overlap, and step-by-step process for automotive suppliers.
- [BSI IT-Grundschutz 2026: Grundschutz++ & Certification](/eu-regulations/bsi-it-grundschutz.md) - BSI IT-Grundschutz explained: 111 building blocks, BSI Standards 200-1 to 200-4, the Grundschutz++ reform, certification, NIS2 link and costs.
- [EU Pay Transparency Directive: Complete Guide (2026)](/eu-regulations/eu-pay-transparency-directive.md) - The EU Pay Transparency Directive must be transposed by 7 June 2026. What it requires, who it affects, key deadlines, and how it compares to UK and Norwegian equivalents.
- [Compliance Software for Germany: Buyer's Guide 2026](/eu-regulations/compliance-software-comparison.md) - Comparing the best compliance software for German companies in 2026. Covers ISMS, GRC, NIS2, DSGVO/GDPR, BSI IT-Grundschutz, and EU data residency requirements.
- [Gender Pay Gap Reporting 2026: UK, EU & Norway Compared](/eu-regulations/gender-pay-gap-reporting.md) - Gender pay gap reporting in 2026: UK Equality Act 250+ employee duty, EU Pay Transparency Directive thresholds, Norway ARP, statistics, fines, and a compliance checklist.
- [Pay Equity Software: Buyer's Guide for EU Compliance (2026)](/eu-regulations/pay-equity-software.md) - Compare the best pay equity software for EU Pay Transparency Directive compliance in 2026 — features, pricing, and how to meet the 7 June 2026 deadline.
- [NIS2: Internal Proof vs External Proof](/eu-regulations/nis2-internal-proof-vs-external-proof.md) - Most organizations focus on internal controls. NIS2 raises the bar by expecting evidence for both your own security posture and the ecosystem you operate in.