BlackTree Security · Infrastructure · Automation · AI

Legislation & Acts

Legislation & Acts

Healthcare Cybersecurity in Europe: From Guidance to Operational Readiness

The European Commission's action plan, launched in January 2025, aims to enhance cybersecurity in hospitals and healthcare providers, recognising its vital role in patient safety. The plan focuses on prevention, detection, response, recovery, and deterrence, providing guidance and resources tailored to the sector's unique needs, while integrating existing regulations like GDPR and NIS2.

Romania Transposed NIS2 by Emergency Ordinance

Romania’s NIS2 framework arrived on the final day of 2024 through an emergency ordinance, turning a delayed transposition into an immediate scope, registration and governance exercise. Emergency Ordinance No. 155 of 30 December 2024 was published and entered into force…

The Cyber Resilience Act Is Here: Security Becomes a Product Requirement

The Cyber Resilience Act, effective from 10 December 2024, mandates cybersecurity requirements for connected hardware and software in Europe. It shifts product security from optional to essential, emphasising risk management throughout a product's lifecycle. Manufacturers must ensure secure design, document vulnerabilities, and maintain transparency about support periods, fundamentally altering product quality expectations.

Software Is Now a Product: Europe’s New Liability Rules Reach AI, Updates and Data

The revised EU Product Liability Directive (EU 2024/2853), effective from 9 December 2026, includes software and AI as products subject to liability. It outlines that defects can arise post-release, linking cybersecurity to product safety, and introduces mechanisms for evidence disclosure. Manufacturers must prepare by assessing software, security, and ongoing safety responsibilities.