Komplyo blog

European regulations

NIS2, the Cyber Resilience Act, DORA and the AI Act create direct obligations for European SMEs. A company can be in scope without being a regulated entity itself, for instance when it supplies a service to one that is. The articles in this section set out the scope of each text, the dates that apply and the measures expected.

6 min read

The AI Act on 2 August 2026: what actually applies and what is postponed for SMEs

2 August 2026 is the general application date of Regulation (EU) 2024/1689, but Regulation (EU) 2026/1744, published on 24 July 2026, postpones the Annex III high-risk obligations to 2 December 2027. A verified overview for SMEs: Article 50 transparency, AI content marking, postponed deadlines, penalties.

  • AI Act
  • EU regulation
  • Governance
  • NIST CSF
Read article
4 min read

ENISA's SME maturity model and the CRA: what it measures, what it does not

In July 2026 ENISA published a cyber maturity self-assessment model for SMEs that manufacture products with digital elements: 5 domains, 25 questions scored 1 to 5, three profiles, about two hours. Useful for locating your processes, insufficient for a CRA file. How to combine the two.

  • CRA
  • EU regulation
  • ENISA
  • Maturity
Read article
3 min read

NIS2: essential or important entity? The classification test explained

How to determine whether your company is an essential or important entity under NIS2: Annex I and II sectors, size thresholds, size-independent special cases, and what classification actually changes (supervision, penalties, reporting).

  • NIS2
  • Compliance
  • Classification
Read article
16 min read

The Cyber Resilience Act for SMEs: manufacturer obligations and timeline

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies to products with digital elements placed on the EU market. The product classes, the manufacturer obligations, the 24h/72h/14-day reporting rule and a 24-month compliance roadmap.

  • CRA
  • Compliance
Read article
16 min read

NIS2 Directive for SMEs: scope, Article 21 measures and deadlines

Is your SME in scope for NIS2? The size and sector criteria, the 10 Article 21 measures, the 24h/72h/1-month reporting rule, the penalty framework and a 12-month compliance roadmap.

  • NIS2
  • Compliance
  • NIST CSF
Read article

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.