Not Sure Which EU Regulations Apply to You?
GDPR, the Cyber Resilience Act and the AI Act each have different triggers — start with an applicability assessment before building a program.
Beyond NIS2 and DORA, the EU regulates personal-data privacy (GDPR), the security of connected products (Cyber Resilience Act) and AI system governance (AI Act) — each with its own scope and timeline. Cyberox provides readiness and governance support across all three, delivered remotely for organizations without an EU office.
Last reviewed: September 2026. Verify current requirements against the official regulator before acting — sources linked below.
The General Data Protection Regulation remains the EU's foundational privacy law, applicable to any organization processing the personal data of individuals in the EU, regardless of where the organization itself is based. Core obligations include lawful basis, data-subject rights, breach notification, and accountability through documentation.
The CRA regulates the cybersecurity of “products with digital elements” — hardware and software placed on the EU market. Vulnerability and active-exploitation reporting obligations begin in September 2026, with full essential-requirements compliance required by December 11, 2027. Medical devices, vehicles and other product types with their own dedicated safety/security regimes are generally excluded.
The AI Act reached its general-application date on August 2, 2026, bringing the bulk of its substantive obligations into active enforcement — including risk-tiered requirements for AI systems classified as high-risk, and governance obligations for providers and deployers.
ISO/IEC 42001 (AI Management System) is a useful governance framework for AI risk and controls, but as of 2026 it is not a harmonized standard under the AI Act — certification does not by itself grant a presumption of conformity. It remains valuable as a structured foundation for AI governance regardless.
Software and hardware vendors selling into the EU (CRA), any organization processing EU personal data (GDPR), and any organization developing or deploying AI systems used in or affecting the EU market (AI Act) should each assess applicability separately — the three regimes have different triggers and timelines.
All three regimes continue to evolve through delegated acts, implementing guidance and (for CRA and the AI Act) phased timelines. Confirm current obligations and deadlines directly against official EU sources (European Commission, ENISA, EUR-Lex) or qualified EU legal counsel.
We help organizations determine which of these three regimes actually apply to them, then build a governance program that addresses the overlapping requirements together.
The EU's broader cybersecurity directive for essential and important sector entities.
Learn morePrivacy information management system certification that complements GDPR compliance work.
Learn moreNeighboring market requirement for organizations also targeting UK public-sector or supply-chain contracts.
Learn moreGDPR, the Cyber Resilience Act and the AI Act each have different triggers — start with an applicability assessment before building a program.