Top Resources for Business Resilience

This is not a blog.

This is where the questions people actually ask about EU digital regulation get answered, with the primary text cited and the regulatory layers kept distinct. Each tile answers one question.

Where the answer stops being general and starts depending on your product, that is where an engagement begins.

 

Assess

Find out which obligations apply to you, in minutes.

Which EU digital laws apply to my business?

Could national NIS2 rules change what I need to do?

It depends on what you build, sell, and process, not on your sector alone. Most EU-active tech companies fall under several regimes at once. This 5-minute assessment identifies which of the major regulations reach you.

NIS2 is a Directive, not a single rulebook. Each country decides how organisations are classified, supervised and expected to show compliance. This short assessment identifies whether national differences are likely to matter to your business.

Does the Cyber Resilience Act apply to my product?

The CRA applies to products with digital elements made available on the EU market. Whether it reaches you, and in which role (manufacturer, importer, distributor, open-source steward), decides which duties you carry. Reporting obligations begin on 11 September 2026, full requirements on 11 December 2027.

How mature is my vulnerability coordination
governance — a first read?

Maturity here is not a policy on a shelf; it is whether intake, triage, handling, and disclosure actually work under pressure. This free self-assessment scores where you stand against the CRA’s vulnerability-handling requirements.

Prepare

The questions worth getting right before you start.

Which regimes am I actually dealing with, text by text?

Most companies carry several at once, and they are not variations on a theme. Each has its own scope, its own duties, and its own status: some already apply, some are phased, some are still being negotiated. The tracker holds them side by side, with what each text governs, who it reaches, and where it stands right now.

How fast must incidents be reported, and to whom?

An early warning within 24 hours, a notification within 72, a final report within a month (Article 23 NIS2; Article 14 CRA). If other regimes also apply, the clocks and the recipients differ, and a single EU entry point is on the way. This lays the timelines side by side.

What does the CRA require for my products?

The CRA sets essential requirements (Annex I Part I), vulnerability-handling requirements (Annex I Part II), and event-triggered reporting (Article 14). These do not start together: reporting applies from 11 September 2026, the rest from 11 December 2027. The guide separates what you must do, by when, in which role.

How mature is my vulnerability management, really?​

A compliance checklist asks whether a policy exists. This asks whether it would survive contact with a real report, product by product. Five capabilities, from governance to spotting exploitation in the wild, and on one of them, the bar sits higher than most teams expect. What each actually demands, and a first move on each.

Which policies and procedures do the regulations actually require?

Fewer documents than most vendors imply, and different ones. NIS2 asks for risk-management measures, not a template pack; the CRA is largely a process-and-evidence obligation (vulnerability handling, secure-by-design records) for connected products. This guidance shows which artefacts each regime genuinely expects.

Which deadlines apply across EU tech regulation, and which one hits first?

Enough of them now run in parallel that the real question is sequencing, not any single date. NIS2 has applied since October 2024 with transposition still uneven; the CRA is phased through to December 2027; the AI Act, DORA, DSA and others each carry their own staggered milestones. What matters is which one reaches you first, given what you build and where you operate.

Go Deeper

How each obligation works, and how to get on top of all of them.

How do I get a clear, board-ready read on everything that applies to me?

The RegNavigator is an engagement, not a feed. We assess which EU frameworks apply to you, run focused workshops with your teams, and deliver a Board-ready regulatory navigation map that lays out, for each regime that touches you, the urgencies to arbitrate, decide, and start. Your ExCo or Board gets one defensible picture of where you stand and what to move on first.

Where do the 27 NIS2 transpositions diverge?

One directive, 27 national laws, and the differences are not cosmetic. Notification windows, supervision models, registration duties, added sectors, personal liability: each is decided nationally. This sets out the dimensions along which they split, and why a group operating in several member states cannot plan from the directive alone.

todo replace avec un sujet supply chain

todo

Will my CRA technical file survive being questioned?

Self-declaration puts the entire burden of proof on you. The declaration and the CE marking are claims; the technical documentation behind them has to hold for 10 years or the support period and stay current as the product and the standards evolve. This sets out what makes a file defensible.

Must I set up coordinated vulnerability disclosure (CVD)?

A working CVD needs a published intake channel, a triage and handling process, and stated timelines, aligned with ISO/IEC 29147 and 30111. Under the NIS2 Directive and the CRA, this moves from good practice to a documented requirement. The quick-start covers the intake channel and a maturity self-check.

todo data ou IA

A compliance checklist asks whether a policy exists. This asks whether it would survive contact with a real report, product by product. Five capabilities, from governance to spotting exploitation in the wild, and on one of them, the bar sits higher than most teams expect. What each actually demands, and a first move on each.

Stay Ahead

Navigate the landscape, and act before it hardens.

How is EU tech regulation actually moving?

The direction of travel matters as much as today’s text. La tech est politique reads the power relations beneath the neutral, technical framing of EU digital policy, so you can see what is really at stake, not only what is announced.

(todo) How is EU tech regulation actually moving?

The direction of travel matters as much as today’s text. La tech est politique reads the power relations beneath the neutral, technical framing of EU digital policy, so you can see what is really at stake, not only what is announced.

Can I influence a regulation before it is final?

Yes, while it is still being drafted, which is the only point at which the text can still change. RS Strategy works inside EU policy processes rather than reading them afterwards, on questions that have not yet become obligations.

Can you bring the regulatory read to my team?

Yes. Tailored sessions for a specific audience (board, management, product teams) on the regulation that actually touches their decisions, pitched to what that audience needs to do with it.

How do boards and executives meet their regulatory duties?​

Personal accountability at the management body level is spreading across EU digital regulation, not confined to a single text. NIS2 made it explicit that management bodies are liable for approving and overseeing cybersecurity risk measures (Article 20), and the pattern is widening as newer regimes land. Board and C-suite briefings translate that exposure into decisions leadership can defend.

What regulatory support fits my specific business requirements?

If your profile needs something more specific than the tools above, custom regulatory support can be scoped to your sector, products, and exposure.

Need personalised guidance?