Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

34 changes tracked across 21 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR
Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Prot...
The European Data Protection Board has published its formal Opinion approving the updated Europrivacy certification criteria as a European Data Protection Seal. This approval is significant as it a...
Read analysis →
Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Prot...
The European Data Protection Board has published its formal Opinion 14/2026, approving the updated Europrivacy certification criteria as a European Data Protection Seal under Article 42.5 of the GD...
Read analysis →
[NEU] [mittel] Podman HyperV Machine: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administrato...
A new vulnerability has been published concerning Podman's HyperV machine feature. This flaw, tracked within the CERT-Bund advisory WID-SEC-2026-1115, could allow an attacker to execute arbitrary c...
Read analysis →
[NEU] [hoch] Podman Desktop: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
A new high-severity vulnerability has been published concerning Podman Desktop, a container management tool. The flaw, identified as WID-SEC-2026-0992 by the German Federal Office for Information S...
Read analysis →
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
CISA has published a Cybersecurity Advisory (AA26-097a) detailing ongoing exploitation of programmable logic controllers (PLCs) by Iranian-affiliated cyber actors. The advisory warns that these act...
Read analysis →
EDPB-EDPS Joint Opinion on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 Directive
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on two legislative proposals: the Cybersecurity Act 2 and amendments to the NIS 2 Directive. T...
Read analysis →
Towards trustworthy AI in the EU public administration: The EDPS Compass for its new role under the AI Act
On 17 March 2026, the European Data Protection Supervisor (EDPS) published a strategic document titled "The EDPS Compass." This outlines the supervisory authority's intended approach and priorities...
Read analysis →
New episode on the Digital Identity Wallets is out!
The European Data Protection Supervisor (EDPS) has published a new informational episode concerning the implementation of the eIDAS2 framework, specifically focused on Digital Identity Wallets. Thi...
Read analysis →
NIS 2 : l’ANSSI poursuit et renforce sa dynamique d’accompagnement
The French National Agency for the Security of Information Systems (ANSSI) has published new guidance and support initiatives to aid in the implementation of the transposed NIS2 Directive. This upd...
Read analysis →
NIS 2 : les entités assujetties peuvent se pré-enregistrer
The French National Cybersecurity Agency (ANSSI) has announced the opening of a pre-registration portal for entities in scope of the NIS 2 Directive. This is a key procedural step ahead of the form...
Read analysis →
Cyber Resilience Act: BSI übernimmt den Vorsitz der AdCo CRA
The German Federal Office for Information Security (BSI) has officially assumed the chairmanship of the Administrative Cooperation Group (AdCo) for the Cyber Resilience Act (CRA). This group is the...
Read analysis →
Cyber Resilience Act: BSI wird marktüberwachende Behörde
The German Federal Office for Information Security (BSI) has been officially designated as the national market surveillance authority for the Cyber Resilience Act (CRA). This announcement confirms ...
Read analysis →
Press release - Artificial Intelligence Act: delayed application, ban on nudifier apps
The European Parliament has published a press release confirming a delayed application timeline for the EU AI Act. The core prohibition on banned AI practices, including the specific ban on 'nudifi...
Read analysis →
Press release - Global Gateway: MEPs deplore lack of transparency and democratic accountability
The European Parliament has issued a critical press release concerning the EU's Global Gateway strategy, operating under the framework of the recently enacted Cyber Resilience Act (CRA). MEPs forma...
Read analysis →
[UPDATE] [mittel] Red Hat Enterprise Linux (Gatekeeper): Mehrere Schwachstellen ermöglichen Denial of Service
A new security advisory has been published regarding multiple vulnerabilities in Red Hat Enterprise Linux (RHEL) that could enable Denial of Service (DoS) attacks. The advisory, identified as WID-S...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board has published the agenda for the IAPP Global Summit 2026, serving as a key forward-looking resource on the operationalization of the EU AI Act. This agenda outlin...
Read analysis →
Patrick Montagner: Banking supervision in a fragmented credit market: interconnections matter
In an interview published on 24 March 2026, ECB Supervisory Board member Patrick Montagner outlined evolving supervisory expectations regarding risk management in a fragmented credit market. The fo...
Read analysis →
IAPP Global Summit 2026: Privacy, AI governance, Cybersecurity law
The European Data Protection Board (EDPB) has published its agenda for the IAPP Global Summit 2026, highlighting key regulatory priorities. This agenda signals the EDPB's focus on the operational c...
Read analysis →
EDPB-EDPS Joint Opinion 4/2026 on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 ...
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on the proposed Cybersecurity Act 2 and amendments to the NIS 2 Directive. This opinion provid...
Read analysis →
EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
The EDPB and EDPS have issued a joint opinion endorsing the European Commission's draft implementing acts for the NIS2 Directive. This opinion supports measures designed to standardize and clarify ...
Read analysis →