Komplyo blog
European regulations
NIS2, the Cyber Resilience Act, DORA and the AI Act create direct obligations for European SMEs. A company can be in scope without being a regulated entity itself, for instance when it supplies a service to one that is. The articles in this section set out the scope of each text, the dates that apply and the measures expected.
The AI Act on 2 August 2026: what actually applies and what is postponed for SMEs
2 August 2026 is the general application date of Regulation (EU) 2024/1689, but Regulation (EU) 2026/1744, published on 24 July 2026, postpones the Annex III high-risk obligations to 2 December 2027. A verified overview for SMEs: Article 50 transparency, AI content marking, postponed deadlines, penalties.
- AI Act
- EU regulation
- Governance
- NIST CSF
ENISA's SME maturity model and the CRA: what it measures, what it does not
In July 2026 ENISA published a cyber maturity self-assessment model for SMEs that manufacture products with digital elements: 5 domains, 25 questions scored 1 to 5, three profiles, about two hours. Useful for locating your processes, insufficient for a CRA file. How to combine the two.
- CRA
- EU regulation
- ENISA
- Maturity
NIS2: essential or important entity? The classification test explained
How to determine whether your company is an essential or important entity under NIS2: Annex I and II sectors, size thresholds, size-independent special cases, and what classification actually changes (supervision, penalties, reporting).
- NIS2
- Compliance
- Classification
The Cyber Resilience Act for SMEs: manufacturer obligations and timeline
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies to products with digital elements placed on the EU market. The product classes, the manufacturer obligations, the 24h/72h/14-day reporting rule and a 24-month compliance roadmap.
- CRA
- Compliance
NIS2 Directive for SMEs: scope, Article 21 measures and deadlines
Is your SME in scope for NIS2? The size and sector criteria, the 10 Article 21 measures, the 24h/72h/1-month reporting rule, the penalty framework and a 12-month compliance roadmap.
- NIS2
- Compliance
- NIST CSF
Get the security policy template
An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.