// Blog / Security
24.09.2026

Regulatory landscape 2026–2030: NIS2, DORA, CRA, AI Act and more at a glance

Regulatory requirements for digital systems are becoming more extensive. Cybersecurity, operational resilience, artificial intelligence, supply chains, data access, and accessibility are now either governed by various European and national requirements, or corresponding legislation is planned and in preparation.

For companies, the key questions are therefore: What do the acronyms stand for? Which regulations already apply, which obligations are being added, and which areas of IT are affected? We provide a brief overview of the most important laws and regulations.

NIS2: Cybersecurity becomes mandatory for more companies

The NIS2 Directive extends European cybersecurity requirements to additional sectors and companies. In Germany, the implementing legislation entered into force on December 6, 2025. Key areas include risk management, cybersecurity measures, reporting obligations for security incidents, and the responsibility of company management. Risks in supply chains and among service providers also play an important role.

For affected companies, this means that scattered, individual security tools alone are not enough anymore. Information security must be embedded organizationally, documented, and verifiable.

DORA: Digital resilience in the financial sector

The Digital Operational Resilience Act, or DORA, has applied directly across the EU since January 17, 2025. It applies to numerous companies in the financial sector and creates a uniform framework for managing risks arising from the use of information and communication technologies (ICT).

DORA covers, among other areas, ICT risk management, incident reporting, resilience testing, and the management of risks from ICT third-party service providers. For banks, insurers, financial service providers, and relevant technology partners, this makes clear how closely IT security and regulatory requirements are connected.

When selecting external services, it is therefore becoming increasingly important to determine whether providers transparently support security and control requirements.

Tip: netfiles supports you in implementing DORA compliance.

Cyber Resilience Act: New obligations for digital products

The Cyber Resilience Act (CRA) applies to manufacturers of hardware and software products with digital elements. It introduces binding cybersecurity requirements throughout the product lifecycle – from development and deployment to vulnerability handling. The CRA therefore follows a lifecycle approach: manufacturers must continuously take security and vulnerability management into account.

Important note: The first reporting obligations apply from September 11, 2026. The CRA will become fully applicable on December 11, 2027.

AI Act: Rules for artificial intelligence

The EU AI Act follows a risk-based approach and is intended to regulate the development and operation of artificial intelligence (AI) more closely. Depending on the use case, different requirements apply to providers and deployers of AI systems.

Since August 2, 2026, key provisions and transparency obligations have applied. Among other things, users of certain systems must be able to recognize when they are interacting with AI or when content has been artificially generated or modified.

The AI Act is therefore not only an issue for AI providers. The use of AI within companies also requires clear responsibilities, classification of the systems used, and appropriate governance.

Data Act: More control and switching options for data

The EU Data Act has applied since September 12, 2025. Among other things, it regulates access to data from connected products and includes requirements for data processing and cloud services. Particularly relevant are rules intended to make it easier to switch between providers and promote interoperability. From January 12, 2027, switching charges for data processing services are generally set to be abolished.

This also means the Data Act touches on digital sovereignty: companies should be able to transfer data and applications more easily and reduce dependencies on individual providers.

Learn more about CLOUD Act risks and digital sovereignty in our article.

German Accessibility Strengthening Act: Making digital services more accessible

The German Accessibility Strengthening Act (BFSG) implements the European Accessibility Act in Germany. It applies to certain products and services offered to consumers since June 28, 2025 – including certain banking services and e-commerce services.

Important for B2B providers: Not every enterprise software solution automatically falls within the scope of the BFSG. Regardless of whether there is a direct legal obligation, an accessible interface designed to minimize barriers is becoming an important quality feature of digital applications.

Supply chains: Requirements remain in flux

The legal situation also remains dynamic with regard to corporate due diligence obligations. The German Supply Chain Due Diligence Act (LkSG, also commonly referred to simply as the “Supply Chain Act”) continues to apply to companies within its defined scope. At the same time, the European Corporate Sustainability Due Diligence Directive (CSDDD) must be transposed into national law. Following the amendments adopted in 2026, member states must transpose the new requirements by July 26, 2028; application is planned from July 26, 2029.

Although these requirements do not primarily concern IT security, they are also relevant to compliance processes, supplier documentation, and traceable collaboration with business partners.

What companies need to keep in mind through 2030 and beyond

The regulations discussed in this article share one important development: security, resilience, data control, and compliance are increasingly subject to legislative oversight as well. As a result, they are becoming more clearly what they should have been all along: an ongoing management responsibility, not a “problem” for individual specialist departments. At the same time, regulation is currently highly dynamic and continually responding to new developments. This is especially true in AI and cybersecurity.

For IT, this means above all:

  • manage responsibilities and access in a traceable manner

  • document security incidents and risks

  • take external service providers and dependencies into account

  • keep data flows and interfaces transparent

  • select systems that can adapt to new requirements

Regulatory requirements are becoming a central force in digital transformation. Good digital infrastructure meets current requirements and provides the foundation for continuing to operate as new requirements emerge.

Secure digital collaboration – tailored to your requirements

New regulatory requirements raise very practical questions for companies: How can sensitive data be exchanged securely? How can external participants be involved, access controlled, and activities documented in a traceable manner? Our netfiles experts will be happy to advise you on how a secure data room can support your processes. Talk to us about your requirements – together, we will find the right solution.

Note: This article provides a concise overview and does not constitute legal advice.