Cybersecurity 2026 Legal and Regulatory Outlook
EU cybersecurity law is shifting from principles to enforcement, requiring integrated compliance across NIS2, DORA, product security, AI, and data protection regim
EU cybersecurity law is shifting from principles to enforcement, requiring integrated compliance across NIS2, DORA, product security, AI, and data protection regim
DORA has entered its enforcement phase, exposing gaps in ICT risk management, third‑party oversight, and resilience testing across EU financial institutions.
The EU is advancing a Single Entry Point to centralize security incident reporting across GDPR, NIS2, and other regimes, aiming to reduce complexity while keeping existing legal obligations largely unchanged.
The EU’s digital legal framework is extensive and layered: GDPR and ePrivacy govern personal data and communications; the Data Act, Data Governance Act and Open Data Directive regulate data access and reuse; NIS2, DORA and eIDAS drive security and trust; DMA and DSA govern platforms and markets. The Commission’s proposed […]
The upcoming DORA deadline urges financial entities to swiftly negotiate ICT contract changes, focusing on pragmatic solutions for compliance amidst ongoing regulatory uncertainties.
The ESAs’ final report on RTS under DORA outlines key elements for financial entities to assess when subcontracting ICT services, enhancing digital operational resilience in the financial sector.