Europe Series

Romania Transposed NIS2 by Emergency Ordinance

Romania’s NIS2 framework arrived on the final day of 2024 through an emergency ordinance, turning a delayed transposition into an immediate scope, registration and governance exercise. Emergency Ordinance No. 155 of 30 December 2024 was published and entered into force…

The Cyber Resilience Act Is Here: Security Becomes a Product Requirement

The Cyber Resilience Act, effective from 10 December 2024, mandates cybersecurity requirements for connected hardware and software in Europe. It shifts product security from optional to essential, emphasising risk management throughout a product's lifecycle. Manufacturers must ensure secure design, document vulnerabilities, and maintain transparency about support periods, fundamentally altering product quality expectations.

Software Is Now a Product: Europe’s New Liability Rules Reach AI, Updates and Data

The revised EU Product Liability Directive (EU 2024/2853), effective from 9 December 2026, includes software and AI as products subject to liability. It outlines that defects can arise post-release, linking cybersecurity to product safety, and introduces mechanisms for evidence disclosure. Manufacturers must prepare by assessing software, security, and ongoing safety responsibilities.

NIS2 Covers Cyber. The CER Directive Covers the Rest of the Failure

The Critical Entities Resilience (CER) Directive enhances Europe’s resilience strategies beyond the NIS2 framework, addressing broader risks such as natural disasters and human threats. Critical entities in various sectors must conduct assessments and report disruptions promptly. This regulatory shift emphasizes the need for comprehensive risk management and operational resilience in essential services.

The AI Act Does Not Replace GDPR: How Europe’s Digital Rules Fit Together

The EU AI Act introduces a risk-based framework for governing artificial intelligence but does not replace existing laws like GDPR. Organisations must navigate overlapping regulations, ensuring compliance across multiple obligations. Effective governance requires a unified approach that integrates risk management, transparency, security, and accountability throughout the AI system's lifecycle.

DORA Is No Longer a Deadline. It Is an Operating Model

The Digital Operational Resilience Act (DORA) is vital for maintaining continuous financial services amidst technological failures. Effective implementation requires a comprehensive approach to ICT risk management, incident handling, testing, supplier oversight, and information sharing. Organisations must prioritise resilience as an ongoing cycle rather than a one-off compliance exercise to adapt to evolving risks.