Skip to content

16 June 2026 | 12 min

Cyber Europe 2026: Why Cyber Resilience Is Becoming a Management Priority

Cyber Europe 2026 was the eighth major European cyber crisis exercise organised by the European Union Agency for Cybersecurity, ENISA. The exercise took place on 10 and 11 June 2026 and tested how well Europe can respond in a coordinated way to large-scale cyber incidents.

The focus was on the railway and maritime sectors. The exercise simulated the handling of parallel cyber incidents affecting critical transport and logistics infrastructure. It was not only about technical defence, but also about crisis coordination, business continuity, communication with authorities, situational awareness, decision-making processes and the continuity of essential services.

Participants included European authorities, national cybersecurity bodies, operators of critical infrastructure and other organisations from the European cyber ecosystem. Switzerland also took part. Under the lead of the Federal Office for Cybersecurity, BACS, various national and cantonal authorities as well as operators of critical infrastructure participated in the exercise.

For companies, Cyber Europe 2026 sends an important signal: cyber resilience is no longer measured only by the existence of security policies. What matters is whether organisations can remain operational during an incident, make clear decisions, coordinate their response and document their actions in a reliable way.

Cyber Europe 2026 was a Europe-wide cyber crisis exercise organised by ENISA, with a focus on railway and maritime transport.

The exercise tested responses to parallel cyber incidents, coordination between authorities and operators, and the ability to maintain essential services.

Switzerland participated under the lead of BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

For companies, the exercise shows that cyber resilience goes far beyond IT security. Incident response, business continuity management, crisis communication, vendor management and management responsibility must work together.

In the context of NIS2, critical infrastructure and rising cyber risks, operational evidence is becoming increasingly important. Companies must not only plan, but also exercise, document and improve.

What Is Cyber Europe 2026?

Cyber Europe is a regular European cyber crisis exercise organised by ENISA. It brings together authorities, critical sectors and cybersecurity organisations. The goal is to simulate realistic cyber crises and test how well collaboration, escalation and crisis response work in practice.

Cyber Europe 2026 focused on transport networks, especially rail and maritime infrastructure. Both sectors are highly connected, internationally dependent and essential for the economy, supply chains and mobility. A cyberattack on such infrastructure can have consequences far beyond a single company.

For this reason, the exercise was not designed as an isolated technical test. It aimed to show how organisations work together under pressure, exchange information, make decisions and keep operations as stable as possible.

What Was Tested During Cyber Europe 2026?

The exercise centred on several parallel cyber incidents. Such scenarios are particularly demanding because they put organisations under pressure at the technical, operational and strategic levels at the same time.

The exercise tested, among other things, how quickly incidents are detected and assessed, how information flows between the parties involved, how crisis teams make decisions and how essential services can be maintained despite cyberattacks.

Business continuity was also a key element. A cyber incident is not just an IT problem when timetables, logistics processes, port operations, communication systems or safety-related operational processes are affected. Companies need to know which processes are critical, which dependencies exist and which alternatives are available in an emergency.

Another focus was coordination. Cyber crises can quickly cross organisational and national boundaries. Operators, service providers, authorities, regulators, crisis teams and communication teams must work together under time pressure. In real crises, these interfaces are often the biggest weakness.

Why the Railway and Maritime Sectors Were in Focus

Railway and maritime transport are central components of European mobility and supply chains. They connect passenger transport, goods flows, ports, industry, energy supply and international trade routes.

At the same time, these sectors are becoming increasingly digital. Operational control systems, communication networks, booking platforms, port management, logistics data, sensors and automated processes increase efficiency, but also create new attack surfaces.

A successful cyberattack can therefore have far-reaching consequences. It can delay supply chains, disrupt passenger transport, increase safety risks and damage public trust.

Cyber Europe 2026 therefore illustrates a challenge that applies to many critical sectors: the more connected organisations become, the more important robust cyber resilience, clear responsibilities and tested crisis processes become.

Why Switzerland’s Participation Matters

Switzerland participated in Cyber Europe 2026 and tested its cyber resilience in the railway and maritime sectors. The exercise was led in Switzerland by the Federal Office for Cybersecurity, BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

This is relevant for two reasons. First, cyber risks are cross-border by nature. Even though Switzerland is not a member of the EU, it is closely connected to European transport, energy, financial and supply chains. An incident in a neighbouring country can affect Swiss organisations, and vice versa.

Second, Switzerland’s participation shows that cyber resilience is not only a matter for national authorities. It is created through cooperation between the state, the private sector, critical operators and specialised service providers. In major incidents, it matters whether this cooperation has already been tested.

For Swiss companies, the message is clear: cyber crises must not only be prepared for technically. They require crisis leadership, reporting channels, roles, supplier contacts, recovery plans and documented decision-making processes.

Cyber Europe 2026 and NIS2: What Companies Should Take Away

Cyber Europe 2026 fits directly into current developments around NIS2. The directive strengthens requirements for cybersecurity, risk management, incident reporting and management responsibility in important and essential entities.

The exercise shows what matters in practice. Companies must not only meet requirements, but also demonstrate that their processes work during an actual incident. This is especially relevant for incident response, business continuity management, crisis communication and the management of external dependencies.

NIS2 is becoming increasingly operational. A policy alone is not enough. A company must know who makes decisions during an incident, which systems are critical, which service providers need to be involved, which reporting deadlines apply and which evidence must be available afterwards.

Cyber Europe 2026 makes one thing clear: cybersecurity readiness must be exercised. Only then can companies see whether roles are clear, escalation paths work and measures are effective in practice.

Why Cyber Resilience Is More Than IT Security

Cyber resilience describes an organisation’s ability to prevent, detect, manage and recover from cyber incidents. This goes far beyond traditional IT security.

Technical protection measures remain important. But during a crisis, organisational factors are just as decisive. These include clear responsibilities, fast decision-making, crisis communication, emergency processes, supplier coordination and the ability to continue critical business processes.

A company can be technically well positioned and still fail during a crisis if it is unclear who decides, who communicates or which systems need to be restored first.

Conversely, an organisation with strong governance can respond faster, limit damage and learn from incidents. Cyber resilience is therefore a management topic and a central part of modern GRC structures.

The Role of Business Continuity Management

Business continuity management, or BCM, plays a central role in cyber crises. It answers the question of how critical processes can continue when systems, service providers or locations fail.

Cyber Europe 2026 shows that BCM should not be viewed separately from cybersecurity. A cyber incident can disrupt business processes just as severely as a natural disaster, power outage or supply chain disruption.

Companies should therefore review whether their BCM plans are realistic from a cyber perspective. Are recovery priorities defined? Are critical processes known? Are dependencies on service providers documented? Are alternative communication channels available? Have crisis roles been tested?

BCM proves its value not on paper, but in exercises. Companies that regularly simulate cyber crises identify weaknesses before a real incident exposes them.

Incident Response: From Plan to Tested Reaction

Many companies have incident response plans. The decisive question is whether these plans work under pressure.

Cyber Europe 2026 shows that incident response is dynamic. Information is incomplete, decisions must be made quickly and multiple stakeholders are involved at the same time. This is why a static process document is not enough.

Effective incident response requires clear roles, defined escalation levels, communication rules, technical analysis capabilities and links to management, legal, data protection, communications and business departments.

Post-incident review is just as important. Every incident and every exercise should be documented and evaluated. Which decisions were made? Which measures worked? Where were there delays? Which controls need to be improved?

This turns incident response into a continuous improvement process.

Suppliers and External Dependencies as a Risk Factor

Cyber crises rarely affect only one organisation. Many critical processes depend on IT service providers, cloud providers, software vendors, network operators, logistics partners or specialised platforms.

Such dependencies are particularly important in the railway and maritime sectors. But the same principle applies in other industries: companies that do not know their critical third parties will struggle to respond quickly and effectively during an incident.

Companies should therefore know which service providers are relevant for critical processes, which contact and escalation channels exist, which contractual obligations apply and which evidence is available.

Vendor risk management is becoming a permanent part of cyber resilience. It is not enough to assess suppliers once. Dependencies must be monitored continuously and included in crisis exercises.

Why Evidence and Documentation Are Critical

After a cyber crisis, it is not only important what was done. It is also important whether the company can show what was done in a reliable and traceable way.

Documentation is therefore not an administrative side issue. It is central for audits, regulatory inquiries, internal lessons learned, insurance claims, customer communication and possible legal assessments.

In an emergency, companies must be able to trace when an incident was detected, who was informed, which decisions were made, which measures were implemented and which systems were affected.

Cyber Europe 2026 shows that evidence is part of resilience. Companies that cannot document their response will later struggle to demonstrate effectiveness, due care and improvement.

What Companies Should Do Now

Companies should use Cyber Europe 2026 as an opportunity to review their own crisis readiness. The most important step is an honest assessment of the current state.

Are critical processes known? Are incident response plans up to date? Are roles and escalation paths clear? Have crisis exercises been conducted? Are suppliers integrated into emergency processes? Is there a connection between cybersecurity, BCM, risk management and management reporting?

Tabletop exercises are particularly useful. They allow organisations to run through a realistic crisis scenario without affecting production systems. Such exercises quickly show whether responsibilities are clear and whether decision-making paths work.

Companies should also review their evidence management. Risks, controls, measures, incidents, exercises and lessons learned should not be scattered across individual files, but managed in a structured way.

Common Weaknesses in Cyber Crises

Many organisations underestimate organisational weaknesses. In practice, crisis response rarely fails only because of missing technology. More often, the problem lies in unclear responsibilities, outdated contact lists, slow escalation, incomplete situational awareness or inconsistent communication.

Another weakness is the separation of IT and business processes. If technical teams do not know which processes are business-critical, recovery priorities may be set incorrectly.

External dependencies are also often considered too late. If a critical service provider cannot be reached or contractual reporting channels are unclear, the company loses valuable time.

Cyber Europe 2026 therefore shows that resilience is not created by individual measures. It is created through the interaction of people, processes, technology, governance and practice.

Conclusion

Cyber Europe 2026 was an important practical test of Europe’s cyber resilience. The focus was on railway and maritime transport, two sectors whose disruption can have far-reaching consequences for mobility, supply chains and public safety.

The exercise clearly shows that cybersecurity is no longer a purely technical task. Companies must be able to manage cyber incidents organisationally, operationally and strategically. This includes incident response, business continuity management, crisis communication, vendor management, management responsibility and reliable evidence.

For companies in Europe and Switzerland, the most important lesson is this: cyber resilience must be exercised. Plans, policies and controls are necessary, but only realistic exercises show whether they work in practice.

Cyber Europe 2026 is not just an isolated public-sector event. It is a clear signal to all organisations: the next stage of cybersecurity is operational resilience.

FAQ on Cyber Europe 2026

What is Cyber Europe 2026?

Cyber Europe 2026 was a Europe-wide cyber crisis exercise organised by ENISA. Its goal was to test Europe’s collective response capability during major cyber incidents and strengthen the cyber resilience of essential services.

When did Cyber Europe 2026 take place?

Cyber Europe 2026 took place on 10 and 11 June 2026.

Which sectors were in focus?

The exercise focused on the railway and maritime sectors. It tested the handling of cyber incidents that could affect transport and logistics infrastructure.

Did Switzerland participate in Cyber Europe 2026?

Yes. Switzerland participated under the lead of the Federal Office for Cybersecurity, BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

What was tested during Cyber Europe 2026?

The exercise tested incident response, crisis coordination, business continuity, information exchange, communication with authorities and the ability to maintain essential services despite cyber incidents.

Why is Cyber Europe 2026 relevant for companies?

The exercise shows that cyber resilience does not depend only on technical security measures. Companies must also be organisationally prepared, have clear roles, coordinate incidents and document their response.

What does Cyber Europe 2026 have to do with NIS2?

NIS2 strengthens requirements for cybersecurity, risk management, incident reporting and management responsibility. Cyber Europe 2026 shows in practical terms why these capabilities are essential in realistic crisis scenarios.

Why does business continuity management play such an important role?

Cyber incidents can interrupt critical business processes. Business continuity management helps companies maintain essential processes even during system outages, attacks or supplier disruptions.

What should companies do after Cyber Europe 2026?

Companies should review their incident response plans, BCM processes, crisis roles, supplier dependencies and evidence management. Regular tabletop exercises and realistic crisis simulations are especially valuable.

What is the main lesson from Cyber Europe 2026?

The main lesson is that cyber resilience is not created by policies alone. Companies must exercise their crisis capabilities, clarify responsibilities, understand dependencies and act in a traceable way during an incident.

Related posts

19 May 2026 | 10 min

AI Risk Becomes a Supervisory Topic: What the BaFin Warning Means for DORA, BCM and Vendor Risk

In mid-May, BaFin made it clear that cyber risks for financial institutions continue to increase. One point is particularly relevant: attackers are using artificial intelligence more often to identify vulnerabilities faster, prepare attacks more effectively and target IT systems with greater precision.

For banks, insurers and other regulated companies, this is more than a technical warning. If AI makes attacks faster and more scalable, the requirements for risk management, business continuity, third-party oversight and evidence documentation also increase. In short: AI risk is becoming a supervisory topic.

This does not only affect companies that use AI themselves. It also affects companies whose IT, suppliers, cloud services or software products may become more vulnerable to AI-driven attacks. This is exactly where DORA, BCM and vendor risk management come into play.

AI is changing the cyber threat landscape. Attackers can identify vulnerabilities faster, create more realistic phishing messages and automate attacks more effectively. This increases the pressure on companies to detect and close security gaps more quickly.

For financial institutions, this is especially relevant because DORA makes digital operational resilience a binding requirement. Companies need to manage and document risks, ICT systems, service providers, incidents and recovery processes more effectively.

Business continuity management and vendor risk management are also becoming more important. An AI-driven cyberattack rarely affects only one system. It can impact service providers, critical processes, data, customer communication and ongoing operations at the same time.

Why AI increases cyber risks

Cyberattacks are not new. What is new is the speed and quality with which attackers can use AI.

In the past, many steps had to be performed manually: analysing systems, searching for vulnerabilities, preparing attacks, writing phishing messages or adapting technical attack patterns. With AI, many of these steps can be accelerated or partly automated.

This does not mean that every attack will automatically be successful. But it does mean that companies must expect more attempts, better prepared attacks and shorter response windows.

Typical risks include:

  • faster identification of vulnerabilities in IT systems
  • more realistic phishing and social engineering attacks
  • automated analysis of publicly available information
  • more targeted attacks on employees, service providers or executives
  • faster adaptation of attack methods
  • higher pressure on security, IT and incident teams

For GRC teams, the key point is this: AI-driven cyberattacks are not just an IT security issue. They affect governance, risk, compliance, suppliers, emergency planning and management reporting.

What this has to do with DORA

DORA requires financial institutions to manage their digital operational resilience systematically. At its core, DORA is about ensuring that companies remain operational even during IT disruptions, cyberattacks or problems with external service providers.

AI-driven attacks increase pressure in exactly this area.

Companies need to know which ICT systems are critical, which risks exist, which controls are in place, which service providers are involved and which measures are triggered in the event of an incident. At the same time, they need to prove that this information is up to date and manageable.

DORA is therefore not only about technical security. It requires a reliable management system for digital risks.

In practice, this means:

  • ICT risks must be assessed regularly
  • critical systems and processes must be known
  • security measures must be documented and reviewed
  • incidents must be detected, assessed and reported
  • service providers must be managed according to risk and criticality
  • recovery and emergency processes must work in practice

If AI makes attacks faster, the quality of these processes becomes more important. Companies cannot afford to start searching for information only once an incident has already happened.

Why BCM is becoming more important

Business continuity management often only becomes visible when something fails. That is exactly the problem.

An AI-driven cyberattack may not only affect individual IT systems. It can also disrupt critical business processes, customer communication, data access or external service providers.

In that situation, having an emergency plan in a folder is not enough. Companies need to know:

  • Which processes are truly critical?
  • Which systems support these processes?
  • Which service providers are involved?
  • What alternatives exist if a system or provider fails?
  • Who makes decisions during a crisis?
  • How quickly do systems need to be restored?
  • What internal and external communication is required?

BCM therefore needs to be more closely connected with cyber risk, incident management and vendor risk management. Only then can companies gain a realistic view of their actual resilience.

Why vendor risk management is critical

Many companies no longer operate their most important systems entirely by themselves. They rely on cloud providers, software solutions, outsourcing partners, managed services and specialised IT providers.

This is normal and often efficient. But it changes the risk profile.

If a critical service provider is attacked, the company itself may still be affected. If a software provider has a vulnerability, it can create risk for many customers. If a cloud service fails, core business processes may come to a halt.

AI-driven attacks make this problem more serious because attackers can analyse supply chains more precisely and identify weak points faster.

That is why a simple supplier list is no longer enough. Companies need structured vendor risk management. They need to know which providers are critical, what services they deliver, which data is affected, which security requirements apply and which evidence is available.

Particularly important are:

  • criticality assessments of service providers
  • documentation of ICT dependencies
  • security requirements in contracts
  • regular supplier assessments
  • evidence of controls and certifications
  • exit strategies for critical providers
  • connection with BCM and incident management

Vendor risk is therefore not just a procurement topic. It is a central part of cyber resilience.

The real problem: information is often scattered

Many companies already have much of the information they need. It is simply not available where it is needed in an emergency.

Risks are documented in spreadsheets. Supplier information sits with procurement. Emergency plans are maintained separately. Incidents are handled in a ticketing system. Controls are documented in audit files. Evidence is stored in folders. Management reports are created manually.

As long as nothing happens, this may seem manageable. During a cyber incident, it becomes a problem.

At that point, companies need to know quickly which systems are affected, which processes are critical, which service providers are involved, which reporting obligations apply and which measures have already been planned or implemented.

If this information is scattered, companies lose time. And in a cyberattack, time is one of the most important factors.

What companies should do now

Companies do not need to launch a massive new programme immediately. But they should review their existing processes in a targeted way.

The first step is transparency. Which critical systems, processes and service providers exist? Which risks are known? Which measures are already in progress? Where is evidence missing?

The second step is connection. Risks, controls, suppliers, incidents and BCM plans should not be managed in isolation. They need to be linked.

The third step is auditability. Supervisors, auditors and management need clear answers. Not at some point in the future, but quickly and reliably.

For many companies, these questions are especially important:

  • Are AI-related cyber risks included in risk management?
  • Are critical ICT systems and service providers fully documented?
  • Are BCM plans connected to real system and supplier dependencies?
  • Are there clear processes for cyber incidents and reporting obligations?
  • Can controls, measures and evidence be found quickly?
  • Is there up-to-date reporting for management and supervisors?

These questions are simple. But they quickly show whether a company is truly in control.

The role of Zazoon GRC

Zazoon GRC helps companies manage cyber risks, DORA requirements, BCM, vendor risk and evidence centrally.

Instead of maintaining risks, controls, service providers, incidents and measures in different tools, companies can connect this information in one shared GRC structure. This creates a clearer picture: Which risks affect which systems? Which providers are critical? Which measures are still open? Which evidence is available? Which requirements are being fulfilled?

This transparency is especially important for AI-driven cyber risks. The faster the threat landscape changes, the more important up-to-date data, clear responsibilities and traceable processes become.

Zazoon helps companies view compliance not as an isolated obligation, but as a foundation for better resilience and better decision-making.

Conclusion: AI makes cyber risk faster, GRC needs to become more structured

The BaFin warning makes one thing clear: AI is changing the cyber threat landscape. Attacks can become faster, more targeted and more scalable. For regulated companies, this increases pressure on DORA, BCM, vendor risk and incident management.

The answer is not more manual documentation. The answer is better structure.

Companies need to know which risks exist, which systems are critical, which service providers are involved, which measures are effective and which evidence is available. This is the core of modern GRC processes.

AI risk is therefore no longer a future topic. It is a current supervisory topic and a clear reason to connect digital resilience, third-party oversight and business continuity more closely.

FAQ

What does AI risk mean in cybersecurity?

AI risk describes risks that arise from or are amplified by the use of artificial intelligence. In cybersecurity, this mainly means that attackers can use AI to identify vulnerabilities faster, create more realistic phishing attacks or automate attack processes more effectively.

Why is the BaFin warning important for companies?

BaFin makes it clear that AI-driven cyberattacks are not only a technical problem. They can threaten the stability of companies, the availability of services and digital resilience. For regulated companies, this increases the pressure to manage and document cyber risks more effectively.

What does AI risk have to do with DORA?

DORA requires financial institutions to manage digital risks in a structured way. If AI makes cyberattacks faster and more complex, companies need better control over their ICT risks, controls, incidents, service providers and recovery processes.

Why is BCM important for AI-driven cyberattacks?

Business continuity management ensures that critical business processes can continue or be restored quickly during disruptions. In an AI-driven cyberattack, one incident can affect several systems, providers and processes at the same time. That is why BCM must be closely connected with cyber risk and incident management.

What role does vendor risk management play?

Many cyber risks do not arise only inside the company. They can also come from service providers, cloud providers or software suppliers. Vendor risk management helps companies identify critical providers, assess risks and document security requirements in a traceable way.

Do companies now need separate AI risk programmes?

Not necessarily. The first step should be to integrate AI-related cyber risks into existing GRC, DORA, BCM and vendor risk processes. What matters most is that risks, controls, measures and evidence can be managed centrally.

Is a technical security solution enough?

No. Technical security solutions are important, but they are not enough on their own. Companies also need clear responsibilities, documented processes, supplier oversight, emergency plans, incident management and reliable evidence.

How does Zazoon GRC support AI risk management?

Zazoon GRC helps companies manage risks, controls, measures, suppliers, incidents and evidence centrally and connect them with each other. This makes it easier to understand where risks arise, which measures are effective and which regulatory requirements are being fulfilled.

11 May 2026 | 17 min

NIS2, DORA, CRA: Three Regulations, One Common Challenge

Why companies need integrated GRC processes instead of parallel compliance projects

NIS2, DORA and the Cyber Resilience Act are among the most important European regulations for cybersecurity, digital resilience and risk management. At first glance, they address different target groups: NIS2 applies to many essential and important entities, DORA focuses on the financial sector and its ICT service providers, while the Cyber Resilience Act places stronger obligations on manufacturers and providers of digital products.

In practice, however, it quickly becomes clear that these three regulations have more in common than many companies initially assume. They require structured risk management, clear responsibilities, documented measures, functioning reporting processes, controlled supply chains and reliable evidence.

The real problem arises when companies treat each regulation as a separate project. One project is created for NIS2, another for DORA, another for the CRA, alongside existing ISO 27001, data protection or audit initiatives. Each team works with its own lists, controls, evidence and responsibilities. This leads to duplicated work, inconsistent information and unnecessary complexity.

This is exactly why companies do not need another compliance silo. They need integrated GRC processes. By connecting risks, controls, suppliers, incidents, assets, measures and evidence in one central system, companies can meet regulatory requirements more efficiently while strengthening their cyber resilience.

NIS2, DORA and the CRA differ in terms of target groups, scope and specific obligations. What they have in common, however, is that they require companies to strengthen cyber resilience, improve risk management and maintain reliable documentation.

Companies that implement each regulation separately quickly create parallel processes. Risks are recorded multiple times, controls are documented twice, suppliers are assessed differently and evidence is distributed across different systems. This increases effort without necessarily improving security or governance.

An integrated GRC approach solves this problem. Requirements, risks, controls, measures, suppliers, incidents and evidence are managed in one shared system and linked with each other. This makes it much easier to manage NIS2, DORA, CRA and other standards such as ISO 27001, GDPR or BSI IT-Grundschutz efficiently.

Three regulations with different priorities

NIS2: Cybersecurity becomes a leadership responsibility

The NIS2 Directive significantly expands the number of regulated companies. It affects many organisations in essential and important sectors, including energy, transport, healthcare, digital infrastructure, public administration, manufacturing, food, chemicals and digital services.

At its core, NIS2 focuses on risk management, technical and organisational security measures, reporting obligations and the responsibility of senior management. It makes one thing clear: cybersecurity is not just an IT department issue. It is a management responsibility with direct governance relevance.

Companies must not only implement security measures. They must also be able to demonstrate that these measures are appropriate, documented and effective. This is where GRC becomes essential.

DORA: Digital resilience in the financial sector

DORA, the Digital Operational Resilience Act, applies to financial entities and certain ICT third-party service providers. The regulation is designed to ensure that financial organisations remain operational even in the event of cyberattacks, IT outages or problems with service providers.

The focus is on ICT risk management, incident reporting, digital resilience testing, information sharing and third-party risk management. The handling of external ICT service providers is particularly important. Financial companies must know which providers are critical, what risks exist, which contractual requirements apply and which exit strategies are available.

DORA therefore makes it clear that digital resilience does not end at the company’s own boundaries. It also depends on how well suppliers, service providers and cloud providers are managed.

CRA: Cybersecurity for digital products

The Cyber Resilience Act takes a different approach. It focuses on products with digital elements, such as software, hardware, connected devices and digital components.

Manufacturers and providers must ensure that their products are securely developed, maintained and updated throughout their entire lifecycle. This includes secure development processes, vulnerability management, security updates, technical documentation and reporting obligations for actively exploited vulnerabilities.

As a result, cybersecurity moves deeper into product development, the software lifecycle, supply chains and product responsibility. Here, too, it is not enough to describe individual security measures. Companies need established processes, clear responsibilities and reliable documentation.

The common challenge: too many parallel compliance structures

Many companies respond to new regulation by launching new projects. This is understandable, but in the long term it creates a structural problem.

A separate risk register is created for NIS2. A separate service provider register is built for DORA. For the CRA, product development maintains its own lists of products, vulnerabilities and security updates. Data protection, information security, internal audit and business continuity teams also work with their own documentation.

On paper, this may initially look like progress. In reality, it creates a patchwork of disconnected structures.

The same risk appears multiple times but is assessed differently. A control is documented for several standards but is not maintained consistently. A measure is tracked in several lists without it being clear which status is actually up to date. A supplier is assessed from a data protection perspective but classified differently under DORA. A security incident is handled technically but not properly linked to regulatory reporting obligations.

The result is not more control. It is more complexity. And complexity is one of the biggest enemies of effective compliance.

The shared requirements of NIS2, DORA and CRA

Although the three regulations pursue different objectives, they overlap in several key areas. Companies should make use of these overlaps.

Risk management

All three regulations require companies to systematically identify, assess, treat and monitor risks. NIS2 mainly focuses on risks to network and information systems. DORA focuses on ICT risks and digital operational resilience. The CRA focuses on security risks related to digital products and their lifecycle.

The common denominator is clear: risks must not be viewed in isolation. A risk is almost always connected to systems, processes, suppliers, products, controls and measures. An integrated GRC approach makes these relationships visible.

Controls and measures

Regulatory requirements remain theoretical if they are not translated into concrete measures. Companies must be able to show which security measures have been implemented, who is responsible for them, when they were reviewed and whether they are effective.

Examples include access controls, backup concepts, incident processes, vulnerability management, supplier assessments, business continuity measures, security updates and awareness measures.

The decisive factor is not only that these measures exist. What matters is that they are up to date, traceable, assigned and auditable.

Incident management and reporting obligations

NIS2, DORA and the CRA all contain obligations for handling security incidents. Deadlines, formats and competent authorities may differ depending on the regulation. However, the operational need is very similar: companies must detect, assess, escalate, document and, where necessary, report incidents.

An isolated incident process is not enough. An incident must be linkable to affected systems, products, processes, customers, suppliers, risks and regulatory obligations. Only then can a company quickly decide whether reporting is required, which deadline applies and what information is needed.

Supplier and third-party risks

DORA places particular emphasis on third-party risks. But NIS2 and the CRA also increase pressure on supply chains, service providers and external technology partners.

Companies must know which suppliers are critical, what services they provide, which data or systems are affected, which security requirements apply and which contractual arrangements are in place. Without this transparency, blind spots quickly emerge, especially in relation to cloud services, software providers, managed services and critical ICT service providers.

Integrated vendor risk management is therefore becoming a key function of modern GRC programmes.

Evidence and audit readiness

Regulatory requirements are only truly fulfilled if companies can prove it. This is exactly where many compliance programmes struggle.

The individual policy is not the real problem. The challenge is proving that it has been implemented. The risk assessment alone is not enough. It must be linked to measures, responsibilities, status, reviews and decisions.

Audit readiness is created through consistent documentation. Companies need a central view of requirements, controls, risks, measures and evidence.

Why Excel and email are no longer enough

Many companies start their compliance work with spreadsheets, SharePoint folders, email coordination and PowerPoint reports. For individual tasks, this may work. But as soon as several regulations need to be managed at the same time, this approach quickly reaches its limits.

Excel can record risks, but it cannot manage reliable workflows. Email can distribute tasks, but it cannot ensure a dependable evidence chain. Folder structures can store documents, but they cannot map regulatory dependencies. PowerPoint can present management reports, but it cannot provide an up-to-date overall view.

The problem is not the individual tool. The problem is the missing connection between information.

A risk sits in one spreadsheet. The related measure sits in another. The evidence is stored in a folder. Responsibility was agreed by email. The supplier is assessed separately. The incident is handled in a ticketing system.

During an audit, an incident or a management discussion, all of this information has to be manually collected. This costs time, creates errors and makes decision-making harder.

What integrated GRC processes can deliver

An integrated GRC approach connects governance, risk management and compliance in one shared system. Instead of managing each regulation separately, requirements, risks, controls, measures and evidence are structured centrally.

The goal is not to artificially make NIS2, DORA and the CRA identical. The legal requirements remain different. The goal is to use shared processes intelligently.

For example, an access control may be relevant for ISO 27001, NIS2, DORA and internal security requirements. It should not be documented four times separately. It is much more effective to maintain this control centrally and map it to several requirements.

The same logic applies to risks, suppliers, incidents, policies, assets and measures. An integrated GRC system ensures that information is recorded properly once and then used multiple times.

The biggest benefit: Build once, use many times

The greatest value of integrated GRC processes lies in reusability. Companies do not need to create new structures for every regulation. Instead, they can assign existing content to multiple requirements in a targeted way.

A risk assessment, for example, may be relevant for NIS2, DORA, ISO 27001 and internal security objectives. An access security control may cover several regulatory requirements at the same time. A supplier can be assessed from the perspective of information security, data protection, business continuity and DORA. An incident can be analysed technically, classified from a regulatory perspective and documented organisationally. Evidence can be relevant not just for one audit, but for several reviews.

This is where efficiency is created. Effort decreases because information does not have to be recreated again and again. At the same time, quality improves because everyone works with the same data, assessments and evidence. Companies gain not only compliance, but also better control and governance.

What an integrated GRC system should be able to do

An integrated GRC system should be able to centrally map regulatory requirements from NIS2, DORA, the CRA and other standards. This also includes ISO 27001, GDPR, BSI IT-Grundschutz, ESG requirements and internal policies.

What matters is not just documentation. The decisive factor is connectivity: Which requirement applies to which area? Which control addresses it? Which risks exist? Which measures are in progress? Which evidence is available? Where are the gaps?

A central risk register creates transparency across information security risks, ICT risks, product security risks, supplier risks and operational risks. Risks should not only be described, but also assessed, assigned to responsible owners and linked to concrete measures.

Control management also plays a central role. Controls are the link between requirements and implementation. A good GRC system shows which controls exist, which requirements they are mapped to, when they were last reviewed and whether they are effective.

Structured measure management is equally important. Compliance often fails not because insights are missing, but because implementation is not tracked consistently. Clear tasks, responsibilities, deadlines, status information and escalation mechanisms are therefore essential.

Vendor risk management is particularly important. Suppliers and service providers must be assessed based on criticality, risk, data access, contractual requirements, security evidence and dependencies. Especially under DORA, NIS2 and the CRA, an isolated supplier register is not enough.

An integrated incident process also helps companies assess security incidents not only technically, but also from a regulatory and organisational perspective. Which systems are affected? Which processes are critical? Which customers or suppliers are involved? Are there reporting obligations? Which deadlines apply? Which evidence must be documented?

Finally, management also needs a clear view. NIS2, DORA and the CRA increase pressure on senior leadership. Risks, open measures, critical suppliers, compliance gaps, incident trends and audit status must therefore be presented in a clear and understandable way.

Integrated GRC processes improve more than compliance

Compliance is often seen as a box-ticking exercise. But NIS2, DORA and the CRA are not about paperwork. They are about real resilience.

A company is not more secure simply because it has many documents. It becomes more secure when it understands its risks, implements measures consistently, clarifies responsibilities, manages incidents effectively and learns from problems.

Integrated GRC processes support exactly that. They create transparency around dependencies, weaknesses, open measures and critical areas. They show where regulatory requirements and operational risks intersect.

This is particularly important because modern cyber risks rarely affect only one area. An attack can simultaneously involve IT, data protection, suppliers, business continuity, product responsibility and communication. Companies that manage these areas separately react more slowly. Companies that manage them in an integrated way identify connections earlier and can act more effectively.

Typical implementation mistakes

A common mistake is to view NIS2, DORA and the CRA purely as legal topics. Of course, they are legal requirements. But their implementation is operational. Companies need processes, responsibilities, controls and evidence.

A second mistake is assigning responsibility solely to IT. Cybersecurity is a technical topic, but not only a technical one. Procurement, product development, legal, compliance, data protection, risk management, audit and senior management all need to be involved.

Many companies also create separate control sets for every regulation. This quickly leads to duplication. A central control framework that maps requirements from several regulations is much more effective.

Suppliers are also often involved too late. Yet third-party risks are a central element of modern regulation. Companies that only assess suppliers shortly before an audit risk gaps in contracts, evidence, security requirements and exit strategies.

Another common weakness is evidence management. Audit readiness is not created on the day of the audit. It is created through continuous documentation. Evidence must be up to date, easy to find and linked to requirements.

How companies should approach this now

Companies should not begin by building three separate programmes for NIS2, DORA and the CRA. A shared foundation is the better approach.

The first step is to clarify which regulations are actually relevant. Then companies should review existing processes, controls, risks and evidence. In many organisations, a lot already exists, but it is distributed, inconsistently documented or difficult to find.

The next step is requirement mapping. Which obligations overlap? Which existing controls can be used? Which evidence is already available? Where are processes, responsibilities or documentation missing?

Based on this, companies can build an integrated GRC structure. This includes a shared risk register, a central control framework, structured measure management, integrated supplier management, a traceable incident process and clean evidence management.

The decisive success factor is consistency. Companies need a shared data basis, clear responsibilities and standardised workflows. Only then can regulatory requirements be fulfilled efficiently and managed sustainably.

The role of Zazoon GRC

Zazoon GRC helps companies manage regulatory requirements in an integrated rather than isolated way. Risks, controls, measures, evidence, audits, policies, suppliers and incidents can be managed centrally and connected with each other.

This allows companies to map requirements from NIS2, DORA, the CRA, ISO 27001, GDPR, BSI IT-Grundschutz and other frameworks in a structured way. Instead of maintaining parallel spreadsheets and manual evidence processes, companies create a transparent GRC foundation for compliance, risk management and cyber resilience.

This integrated approach is especially important for organisations that need to meet several regulatory requirements at the same time. It reduces effort, improves traceability and creates a clear foundation for audits, management decisions and continuous improvement.

Conclusion: The future of compliance is integrated

NIS2, DORA and the CRA show where European regulation is heading: away from isolated individual obligations and towards demonstrable resilience, clear responsibility and continuous risk management.

Companies that treat each regulation separately will struggle with growing complexity, duplicated effort and inconsistent evidence. Companies that build integrated GRC processes create a scalable foundation for current and future requirements.

The key point is this: NIS2, DORA and the CRA are not just compliance tasks. They are a wake-up call for better governance.

Companies that centrally connect risks, controls, measures, suppliers, incidents and evidence meet regulatory requirements more efficiently and make their organisation more resilient at the same time.

FAQ

What do NIS2, DORA and the CRA have in common?

NIS2, DORA and the CRA pursue different objectives, but they share many common requirements. All three regulations require structured risk management, clear responsibilities, security measures, documentation, incident processes and reliable evidence. This makes them well suited to being managed through integrated GRC processes.

Why should companies not implement NIS2, DORA and the CRA separately?

Separate implementation often leads to duplicated controls, parallel risk assessments, inconsistent evidence and high manual effort. An integrated approach reduces duplication and ensures that requirements, risks, controls and measures are centrally connected.

What is the difference between NIS2, DORA and the CRA?

NIS2 focuses on cybersecurity and risk management for many essential and important entities. DORA applies to the financial sector and focuses on digital operational resilience and ICT third-party risks. The CRA applies to products with digital elements and sets requirements for secure development, vulnerability management and product responsibility.

What role does GRC play in NIS2, DORA and the CRA?

GRC connects governance, risk management and compliance. For NIS2, DORA and the CRA, this means that requirements are managed centrally, risks are assessed, controls are mapped, measures are tracked and evidence is documented. This creates transparency around regulatory obligations and their operational implementation.

Which companies are affected by NIS2?

NIS2 applies to many companies in essential and important sectors, including energy, healthcare, transport, digital infrastructure, public administration, manufacturing, food, chemicals and digital services. Whether a company is affected depends, among other things, on its sector, size and national implementation.

Who is affected by DORA?

DORA applies to financial entities such as banks, insurers, payment institutions, investment firms and other financial market participants. It also affects certain ICT third-party service providers if they are critical to the financial sector.

Who is affected by the Cyber Resilience Act?

The Cyber Resilience Act applies to manufacturers, importers and providers of products with digital elements. This includes software, hardware, connected products and digital components. Companies must ensure that these products are securely developed, documented and maintained throughout their lifecycle.

Why is vendor risk management so important?

Many companies depend heavily on external service providers, cloud providers, software suppliers and ICT partners. NIS2, DORA and the CRA increase the pressure to make these dependencies transparent. Companies must know which suppliers are critical, what risks exist and which security requirements apply.

Is ISO 27001 enough to comply with NIS2, DORA or the CRA?

ISO 27001 is a very strong foundation for information security management, but it does not replace a regulation-specific assessment. Many controls and processes from ISO 27001 can be used for NIS2, DORA and the CRA. However, companies still need to assess which specific additional requirements apply.

How does Zazoon GRC support implementation?

Zazoon GRC helps companies centrally manage requirements, risks, controls, measures, evidence, audits, policies, suppliers and incidents. This allows multiple standards and regulations to be mapped in one integrated system. It reduces manual effort and improves transparency, audit readiness and governance.

21 April 2026 | 13 min

NIS 2: Why Germany Is Falling Behind

NIS-2 has been enforceable law in Germany since December 2025. No transition period, no grace period, no exceptions. Around 29,500 companies across 18 sectors are required to implement risk management, report security incidents, and register with the BSI. And yet: at the 21st German IT Security Congress of the Federal Office for Information Security, the BSI was forced to admit that implementation is falling far short of expectations. Registration numbers are disappointing, awareness of the directive is alarmingly low, and a significant number of affected companies have made a deliberate choice not to register at all.

What is driving this? And more importantly: how can companies finally clear the compliance hurdle without overstretching their operational resources? The answer lies, to a large degree, in modern GRC software solutions.

  • According to the BSI, nearly half of all German companies had never heard of NIS-2 by the end of 2024.
  • The NIS-2 Implementation Act has been in force since December 6, 2025, with no transition period. The BSI registration deadline expired on March 6, 2026.
  • The main reasons for non-compliance: lack of awareness, perceived complexity, resource constraints, and a deliberate wait-and-see approach.
  • Non-compliance can result in fines of up to 10 million euros or 2% of global annual turnover.
  • Managing directors and executives face personal liability for meeting cybersecurity obligations.
  • GRC software demonstrably reduces implementation effort by up to 40–50% and delivers structure, automation, and audit-readiness in a single tool.

The Wake-Up Call from the BSI Congress: Germany Is Asleep at the Wheel

At the 21st BSI Security Congress, Manuel Bach of the BSI’s Cybersecurity in Business division spoke plainly: registration numbers in the BSI’s reporting portal remain well below expectations. Worse still, the BSI is aware of companies that — after consulting their legal counsel — have made a conscious decision not to register, hoping to stay below the radar.

And then came perhaps the most alarming statistic: nearly half of all German companies had never heard the term “NIS-2” at the time of a BSI study conducted at the end of 2024. Not unfamiliar as an obligation — simply unknown as a concept.

Younes Ahmadzei, who examined NIS-2 implementation in German SMEs as part of his bachelor’s thesis at the Technical University of Munich, painted a similar picture: many of the companies he surveyed had only begun engaging seriously with the topic at the start of 2026 — after the law had already come into force without a transition period. And even those who are aware of the directive often doubt whether implementing it would actually improve their company’s IT security. NIS-2 is being perceived as a bureaucratic checkbox exercise, not as a strategic opportunity.

This finding is alarming — and, at the same time, entirely explainable.

Why So Many Companies Are Ignoring NIS-2: The Five Biggest Barriers

1. Lack of Awareness and Uncertainty About Being Affected

The first and most fundamental reason is simply a lack of awareness. Many companies do not know that NIS-2 applies to them. The directive has dramatically expanded the circle of organizations under obligation: from around 4,500 companies under the old NIS directive to more than 29,500 in Germany alone. Now covered are mid-sized companies across 18 sectors — including energy, transport, healthcare, manufacturing, digital services, financial services, and public administration.

As a general rule: companies with at least 50 employees or more than 10 million euros in annual revenue may fall within scope. Those who do not actively ask whether this applies to their organization risk overlooking their own legal obligations.

2. The Perceived Complexity of the Regulatory Framework

NIS-2 is complex. Germany attempted to address multiple regulatory challenges simultaneously within a single piece of legislation — the result is a layered rulebook that even experts find challenging. For many mid-sized businesses, the legal text feels abstract and difficult to translate into concrete operational measures.

According to the study “Cybersecurity & Digital Resilience 2026,” 47 percent of surveyed companies rate the implementation of NIS-2 as difficult or very difficult. The most commonly cited barriers — each named by around 39 percent of respondents — are the high effort required to adapt processes and policies, and the sheer complexity of the requirements themselves. A further third cite unclear regulatory guidance and integration challenges with existing IT systems.

Governance obligations, risk management, incident response, supplier assessments — many of these requirements feel as though they were written for large corporations with dedicated compliance teams. For a mechanical engineering firm with 80 employees in southern Germany, the reality looks very different.

3. Resource Constraints in SMEs

Large companies have dedicated IT departments, security teams, and in-house compliance expertise. Small and medium-sized enterprises — precisely the group that NIS-2 brings into scope for the first time — simply do not. In interviews with affected business representatives, the workload was estimated at a minimum of one person spending two to three days per week on this topic alone — a realistic assessment that many SMEs cannot absorb without significant additional cost.

There is another layer to this: many companies are technically reasonably well set up, but fall short when it comes to organizational structures and documentation. Missing process frameworks, no embedded security culture, barely any reporting structures in place — all of this makes compliance work laborious and draining.

4. The Wait-and-See Strategy

For as long as the national implementation law was not finalized, many companies chose to wait. This hesitation was a deliberate strategic calculation: investing too early might mean heading in a direction that the final legislation would correct. This posture led to a dangerous standstill — and when the law came into force in December 2025 without a transition period, many companies were completely unprepared.

That argument is now obsolete. The law is in effect. The registration deadline passed on March 6, 2026. Any company that has not yet registered is already risking a fine.

5. Underestimating Personal Liability

NIS-2 is the first German cybersecurity law to hold managing directors personally accountable. Section 38 of the new BSIG requires company management to, among other things, regularly undergo training in four core areas — at least every three years. And any executive who ignores their organization’s reporting obligations faces personal liability.

Manuel Bach of the BSI drew a sharp analogy at the congress: you cannot simply decide for yourself that you are not subject to tax obligations. The same logic applies here. Just because a company believes it falls outside the scope of NIS-2 does not make that belief legally valid.

The Cost of Inaction: What Companies Are Risking

The fine frameworks under NIS-2 are substantial. For particularly important entities, sanctions can reach up to 10 million euros or 2 percent of global annual turnover — whichever is higher. For important entities, the framework is up to 7 million euros or 1.4 percent of global revenue.

On top of that comes the personal liability of senior management, the full weight of which many executive teams have yet to appreciate. Companies with inadequate security measures also face significant reputational damage if a security incident becomes public and it is clear that no appropriate steps had been taken.

And finally: companies that are part of a supply chain are increasingly being scrutinized by larger customers and partners for compliance status. NIS-2 compliance is becoming a competitive differentiator.

Why Manual Implementation Hits a Wall

The traditional approach — bringing in consultants, maintaining Excel spreadsheets, assembling documentation in Word files — works for large corporations with the necessary resources. For mid-sized businesses, it is simply too time-consuming, too error-prone, and too difficult to scale.

NIS-2 is not a one-time project you can tick off and forget. It demands continuous risk management, regular review of security measures, structured incident response within strict reporting deadlines — significant security incidents must be reported to the BSI within 24 hours — and ongoing documentation of supply chain security.

That is not a workload you can manage with a checklist in a drawer.

How GRC Software Closes the Compliance Gap

Governance, Risk & Compliance — or GRC — software was built precisely for this problem: translating complex regulatory requirements into structured, scalable, and traceable action. For NIS-2, GRC software is not a nice-to-have. It is a strategic tool.

A Structured Starting Point Instead of Disorientation

Modern GRC platforms deliver pre-configured NIS-2 frameworks that include all relevant control areas, compliance objectives, and documentation templates. Instead of starting from scratch, a company begins with a structured gap assessment: where does the organization stand today? Which requirements are already met? Where do gaps remain?

This gap analysis is the foundation for a prioritized action plan — and exactly what many companies have been missing: a clear picture of where to start.

Automated Risk Management

NIS-2 demands the continuous identification, assessment, and mitigation of risks. Handled manually, that means recurring workshops, spreadsheet maintenance, and internal coordination rounds. A GRC platform automates these processes: risks are captured, assessed, linked to specific measures, and documented in a living risk register — one that updates automatically as the threat landscape or organizational structure evolves.

Incident Management with Integrated Reporting Workflows

The 24-hour reporting deadline for significant security incidents is one of the toughest operational requirements in NIS-2. Without structured processes, it is nearly impossible to meet. GRC software provides integrated incident management modules: incidents are recorded in a structured way, automatically classified, relevant stakeholders are notified, and reporting pathways to the BSI can be prepared in advance. Comprehensive documentation also protects management in the event of a liability claim.

Supply Chain Security and Third-Party Management

NIS-2 also requires companies to secure their supply chains. That means: suppliers and service providers must be assessed for their security practices. A GRC platform allows this third-party management to be mapped systematically — with automated questionnaires, structured assessment workflows, and a central overview of all relevant partners.

Audit-Readiness at the Push of a Button

Particularly important entities must demonstrate their measures to the BSI within three years. Organizations that map their NIS-2 compliance in a GRC platform are audit-ready at any time: all evidence, documents, risk assessments, and action logs are stored in one central location, versioned, and retrievable on demand.

Relieving the Burden on Management and IT

An often-underestimated benefit: GRC software takes pressure off executive leadership. Instead of being overwhelmed by compliance details, decision-makers get clear dashboards that show at a glance where the organization stands on NIS-2 conformity. IT teams are relieved because routine tasks are automated — by up to 40 percent, according to research data.

Multi-Framework Coverage: NIS-2 Does Not Stand Alone

Companies required to implement NIS-2 often carry other regulatory obligations as well: GDPR, ISO 27001, DORA (for financial entities), TISAX (for the automotive industry), or the forthcoming KRITIS Umbrella Act. Well-integrated GRC platforms can map these frameworks in parallel and leverage synergies — organizations that are already ISO 27001 certified have a significant head start on NIS-2 compliance.

Zazoon: GRC Software That Does Not Overwhelm

At Zazoon, we have observed the realities of the mid-market up close. Companies do not need another checklist or another consultant’s slide deck. They need a software solution that breaks NIS-2 down into manageable steps, guides the implementation, and does not demand more IT expertise than realistically exists within the organization.

Our GRC platform delivers exactly that: a structured NIS-2 onboarding experience, integrated risk management, automated documentation, and a central dashboard for both management and IT — without requiring a dedicated compliance team to be built from scratch.

Conclusion: The Cost of Waiting Is Too High

NIS-2 is not a bureaucratic construct you can wait out. It is enforceable law with substantial penalties and personal liability for management. The sobering figures from the BSI Congress show that a significant portion of German business has yet to grasp this reality — or is deliberately choosing to ignore it.

The good news: it is not too late to get started in a structured way. And GRC software makes it realistic for the first time to achieve NIS-2 compliance without a large compliance team and without six-figure consulting budgets. Companies that act now are not just protecting themselves from fines and liability risks. They are building the foundation for a more resilient IT infrastructure, strengthening the trust of their customers and partners, and positioning themselves as dependable links in a security-conscious supply chain.

The effort is real. But it is manageable — with the right tools.

Frequently Asked Questions (FAQ)

Does NIS-2 apply to my company if we are not a technology business?
Yes, in many cases. NIS-2 covers companies across 18 sectors, including energy, transport, healthcare, mechanical engineering, chemicals, food production, and public administration. As a general rule: organizations with at least 50 employees or more than 10 million euros in annual revenue should actively check whether they fall within scope. This assessment should be carried out as soon as possible.

What happens if my company missed the registration deadline?
The BSI registration deadline expired on March 6, 2026. Companies that have not yet registered are at risk of fines and should complete registration without delay. The BSI has indicated that it is actively monitoring compliance with the obligations.

How significant are the potential fines?
For particularly important entities, fines can reach up to 10 million euros or 2 percent of global annual turnover. For important entities, the framework allows for fines of up to 7 million euros or 1.4 percent of global revenue.

What is the difference between “important” and “particularly important” entities?
Particularly important entities are larger organizations in critical sectors such as energy, water, financial market infrastructure, and healthcare. Important entities include mid-sized companies and organizations from additional sectors such as manufacturing, food, and digital services. The precise classification depends on sector, company size, and market position.

Does ISO 27001 certification help with NIS-2 implementation?
Yes, significantly. ISO 27001 and NIS-2 overlap in many areas — particularly around the information security management system (ISMS), risk analysis, and the documentation of security measures. Organizations that are already ISO 27001 certified have a meaningful head start. Good GRC platforms map both frameworks in parallel and use existing work as the foundation for NIS-2 compliance.

How long does NIS-2 implementation take with GRC software?
It depends on the organization’s starting point. With a GRC platform that includes structured templates, gap analyses, and automated workflows, well-prepared companies can reduce the time to compliance by up to 50 percent compared to a purely manual approach. Realistic timelines for reaching an initial solid compliance baseline are three to six months.

What exactly do I need to do as a managing director or executive?
Under Section 38 of the new BSIG, company management must actively oversee and approve the implementation of risk management measures. Regular training in four core areas is also mandatory — at a minimum every three years. Those who neglect these obligations face personal liability. A GRC platform helps document and evidence these activities in a structured and verifiable way.

Can GRC software also cover supply chain security?
Yes. Modern GRC platforms offer third-party management modules that allow suppliers and service providers to be systematically assessed and documented. This is particularly important given that NIS-2 explicitly requires supply chain security as part of an organization’s overall risk management obligations.

14 April 2026 | 5 min

EU Anti-Corruption Directive 2026: A Unified Criminal Law Framework Reshaping Compliance in Europe

Corruption remains one of the most significant structural risks for both companies and governments across Europe. Despite numerous national laws, a core issue has persisted: lack of consistency. Diverging definitions, penalties, and enforcement mechanisms have enabled corruption to operate across borders and exploit regulatory gaps.

With the EU Anti-Corruption Directive 2026, this fragmented landscape is fundamentally changing. For the first time, the European Union establishes a unified minimum criminal law framework, requiring all Member States to combat corruption based on the same principles.

  • EU-wide minimum criminal law framework for anti-corruption
  • Harmonised definitions of core corruption offences
  • Alignment of minimum penalties and sanctions
  • Significantly expanded corporate liability
  • Mandatory national anti-corruption strategies
  • Stronger cooperation between EU and national authorities
  • Implementation into national law within 2 to 3 years

Why the EU Is Acting Now

Corruption is no longer a purely national issue. It is closely linked to organised crime, money laundering, and the misuse of public funds. At the same time, inconsistent national regulations have allowed corruption networks to exploit weaker legal systems within the EU.

The result has been ineffective enforcement, limited deterrence, and substantial economic damage. The directive is a direct response to these structural weaknesses.

The Core of the Directive: Harmonisation Over Fragmentation

The EU’s approach is clear: not full legal unification, but binding minimum standards that all Member States must implement.

Harmonised Definition of Corruption Offences

A major step forward is the establishment of a consistent EU-wide catalogue of corruption offences, including:

  • Bribery in both the public and private sectors
  • Embezzlement
  • Trading in influence
  • Obstruction of justice
  • Illicit enrichment
  • Concealment of assets

This harmonisation significantly reduces interpretative gaps and limits the ability to exploit regulatory differences.

Minimum Penalties and Sanctions

The directive also introduces aligned sanction frameworks to ensure consistent deterrence across the EU.

Key measures include:

  • Minimum prison sentences of several years depending on the offence
  • Substantial financial penalties for companies, often linked to turnover
  • Additional sanctions such as exclusion from public procurement
  • Penalties targeting responsible executives

This reduces the risk of “soft jurisdictions” within the EU.

Companies in Focus: Increased Liability Risks

One of the most impactful aspects of the directive is the expansion of corporate liability. Companies will be held accountable more directly than before.

Liability applies when:

  • Corruption is committed for the company’s benefit
  • Adequate preventive and control measures are lacking

This marks a shift from individual accountability to structural corporate responsibility.

Practical Impact on Compliance

Companies will need to strengthen their compliance frameworks significantly:

  • Enhancement of internal control systems
  • Stronger third-party and supply chain oversight
  • Implementation of effective whistleblowing systems
  • Demonstration of a functioning compliance culture
  • Comprehensive documentation of preventive measures

Organisations without robust anti-corruption programmes will face significantly increased risk.

Prevention as a Strategic Pillar

The directive goes beyond criminal law by embedding prevention and governance requirements.

Member States must:

  • Develop national anti-corruption strategies
  • Conduct regular risk assessments
  • Establish independent oversight bodies
  • Improve transparency through structured data

This creates a systematic approach that not only punishes corruption but actively prevents it.

Stronger EU-Wide Cooperation

Another key improvement is enhanced cooperation between authorities.

The directive promotes:

  • Increased information exchange between Member States
  • Closer collaboration with EU institutions
  • Better coordination in cross-border investigations

This directly addresses a major historical weakness: lack of coordination.

Limitations and Criticism

Despite its scope, the directive remains a political compromise.

Key points of criticism include:

  • Some provisions have been weakened compared to earlier drafts
  • Focus on minimum standards rather than full harmonisation
  • Potential differences in implementation speed across Member States

Nevertheless, the directive represents a landmark step and lays the foundation for future regulatory developments.

Implications for GRC and Corporate Strategy

For GRC professionals, the directive has strong strategic implications.

Key developments include:

  • Increased regulatory consistency across the EU
  • Greater visibility and comparability of risks
  • More coordinated and effective enforcement
  • Need for EU-wide consistency in compliance systems

The ability to demonstrate compliance effectiveness will become a critical success factor.

Conclusion

The EU Anti-Corruption Directive 2026 marks a turning point in European regulation. It closes long-standing gaps, introduces consistent minimum standards, and significantly increases enforcement pressure on companies.

For organisations, this means corruption risks will not only be more tightly regulated but also more actively enforced.

Those who invest early in robust compliance frameworks will gain a strategic advantage. Those who delay face growing regulatory and financial exposure.

FAQ

When will the directive take effect?

Member States generally have 2 to 3 years to transpose the directive into national law. The new requirements will apply once implemented.

Does the directive apply directly to companies?

No. It must first be transposed into national law. Its impact on companies will come through national legislation.

Which companies are most affected?

All companies may be affected, especially those operating internationally, in regulated sectors, or with significant public sector exposure.

What are the key changes compared to the current framework?

The main shift is harmonisation. Definitions, sanctions, and enforcement will become more aligned across the EU, reducing loopholes.

What role will compliance play going forward?

Compliance will become a central management function. Companies must be able to demonstrate effective preventive measures.

What are the main risks of non-compliance?

High financial penalties, reputational damage, exclusion from public contracts, and potential criminal liability for responsible individuals.

Is this the beginning of further EU criminal law initiatives?

Highly likely. The directive signals a broader willingness by the EU to harmonise criminal law in areas such as GRC and financial crime.

24 March 2026 | 5 min

Regulation Overload 2026: How Companies Can Manage NIS2, the AI Act and DORA at the Same Time

In March 2026, “regulation overload” is no longer an exaggeration – it is operational reality. NIS2 has entered the implementation phase, DORA is already fully applicable, and the AI Act is being rolled out in stages with major obligations coming into force in 2026.

Companies are no longer dealing with a single regulatory deadline, but with multiple frameworks that differ in structure, scope and supervisory expectations. The real challenge is not any individual regulation, but the combination of all three.

  • In 2026, companies face three major regulatory frameworks at the same time: NIS2, DORA and the AI Act.
  • These regulations follow different logics but overlap significantly in governance, risk management and compliance requirements.
  • The biggest challenge is not understanding each regulation individually, but managing them together.
  • Many organizations still approach them as separate projects, creating unnecessary complexity.
  • A unified GRC approach is essential to handle overlapping requirements efficiently.
  • The key to success lies in integration, not duplication.

Why 2026 Is a Stress Test for GRC

The regulatory landscape has reached a level of complexity where traditional approaches no longer work. Organizations must deal with:

  • Horizontal cybersecurity requirements under NIS2
  • Sector-specific resilience requirements under DORA
  • Risk-based AI regulation under the AI Act

Each framework introduces its own terminology, processes and reporting obligations. However, in practice, they all impact the same underlying systems, processes and governance structures.

This creates a structural challenge: different regulations, but the same operational reality.

Three Frameworks, Three Logics

NIS2: Broad Cybersecurity Governance

NIS2 significantly expands the scope of cybersecurity regulation across multiple sectors. It requires organizations to implement structured risk management, incident reporting and supply chain security.

From a GRC perspective, one of its most important aspects is the clear responsibility of management. Cybersecurity is no longer a technical topic – it is a governance issue.

DORA: Operational Resilience in the Financial Sector

DORA focuses specifically on financial institutions and their ability to remain operational under digital stress.

It introduces detailed requirements for:

  • ICT risk management
  • Incident reporting
  • Resilience testing
  • Third-party risk management

Compared to NIS2, DORA is more granular and operationally demanding, especially in reporting and documentation.

AI Act: Risk-Based Regulation for Artificial Intelligence

The AI Act introduces a completely different regulatory approach. Instead of focusing on infrastructure or resilience, it regulates the use of AI systems based on risk levels.

High-risk AI systems must meet strict requirements, including:

  • documented risk management
  • transparency
  • human oversight
  • technical documentation and logging

For many companies, this is the first time AI becomes a formal compliance topic.

Where the Regulations Overlap

1. Governance and Accountability

All three frameworks shift responsibility to senior management. Decisions around cybersecurity, operational resilience and AI usage must be governed at the highest level.

2. Risk Management

Each regulation requires structured risk management, but in different contexts:

  • cyber risk under NIS2
  • ICT and operational risk under DORA
  • system and model risk under the AI Act

The underlying principle is the same: risks must be identified, assessed and controlled continuously.

3. Incident Management

Incident reporting is a key requirement across all three frameworks.

Organizations must be able to:

  • detect incidents quickly
  • classify them correctly
  • report them within strict timelines

Managing this across multiple regulatory regimes requires a unified approach.

4. Third-Party Risk

Supply chains and external dependencies are a major focus area.

  • NIS2 emphasizes supply chain security
  • DORA introduces strict requirements for ICT providers
  • The AI Act indirectly addresses dependencies in AI value chains

This makes third-party risk management a central GRC function.

5. Documentation and Evidence

All three frameworks require extensive documentation.

The real challenge is not implementation, but proof. Companies must demonstrate that controls exist, are effective and are continuously monitored.

Why Many Organizations Struggle

A common mistake is treating each regulation as a separate project.

This leads to:

  • duplicate controls
  • inconsistent processes
  • fragmented reporting
  • increased complexity

Another issue is organizational silos. Different teams handle different regulations without coordination, even though they address the same underlying risks.

Finally, many companies underestimate the operational impact. These regulations do not only affect compliance functions, but also IT, operations, product development and management.

How Companies Should Respond

The key to managing regulation overload is integration.

Instead of building separate compliance programs, organizations should:

  • establish a unified GRC framework
  • define a common control structure
  • align risk management across domains
  • create centralized incident handling processes
  • build a shared evidence and reporting model

This approach reduces duplication and creates consistency across regulatory requirements.

Equally important is prioritization. Companies should focus on overlapping areas first, as improvements there will have the greatest impact across all frameworks.

Conclusion

Regulation overload in 2026 is not just a question of volume, but of structure. Companies do not fail because there are too many rules. They fail because they manage them in isolation.

NIS2, DORA and the AI Act must be understood as part of a single GRC challenge. Organizations that integrate governance, risk and compliance across these frameworks will not only meet regulatory expectations more efficiently, but also become more resilient and better controlled.

FAQ

Do all companies need to comply with all three regulations?
No. However, many organizations are affected by at least one framework, and in complex structures, multiple regulations may apply simultaneously.

Which regulation takes precedence?
This depends on the sector. For financial institutions, DORA often overrides overlapping cybersecurity requirements, but a proper legal assessment is required.

What is the biggest challenge in 2026?
Managing overlapping requirements across different regulations without creating unnecessary complexity.

Can companies handle each regulation separately?
Technically yes, but practically this leads to inefficiency and fragmentation. Integration is the more sustainable approach.

Where should companies start?
With a unified GRC framework that maps all regulatory requirements onto a shared control and risk management structure.

17 March 2026 | 5 min

After the NIS2 Deadline: Why Two-Thirds of Companies Are Falling Behind – and What Really Matters Now

The NIS2 Directive is one of the most important regulatory developments in the field of cybersecurity and GRC. Its goal is to significantly raise the level of cybersecurity across Europe and to place greater responsibility on organizations. However, shortly after key deadlines have passed, a clear picture is emerging: a large proportion of affected companies are not sufficiently prepared.

Many organizations underestimated the requirements, misjudged whether they are in scope, or started implementing measures too late. At the same time, pressure is increasing due to regulatory scrutiny, stricter enforcement and the risk of significant penalties.

The key question is no longer whether companies should address NIS2, but how they can now catch up in a structured and effective way.

  • A large proportion of affected companies have missed the NIS2 deadlines.
  • NIS2 significantly expands the scope of regulated organizations and tightens requirements.
  • Cyber risks are becoming a central governance and management topic.
  • Executive management carries direct responsibility and potential liability.
  • Many organizations show gaps in risk management, documentation and accountability.
  • The priority now is gap analysis, prioritization and structured implementation.
  • NIS2 is not a one-time project but requires a sustainable GRC system.

Why So Many Companies Are Behind

The high number of unprepared organizations is not a coincidence. NIS2 introduces several structural challenges.

First, the scope has been significantly expanded. Unlike the original NIS Directive, NIS2 applies not only to critical infrastructure operators but also to a wide range of medium-sized and large companies across multiple sectors.

Second, many organizations are uncertain whether they are in scope. The criteria are complex and depend on sector, size and specific activities.

Third, the requirements are often underestimated. NIS2 is not just an IT security initiative but requires a comprehensive cybersecurity risk management framework.

Fourth, many companies lack integrated GRC structures to systematically implement regulatory requirements.

NIS2 as a Game Changer for GRC

NIS2 fundamentally changes the role of governance, risk and compliance.

Cybersecurity is no longer treated as a purely technical issue but as an integral part of corporate management. The directive requires, among other things:

  • structured cybersecurity risk management
  • clear responsibilities at management level
  • documented security measures
  • incident reporting obligations
  • training for executive management
  • supply chain and third-party security

This makes NIS2 a classic GRC topic that connects governance, risk and compliance.

The Role of Executive Management

A key aspect of NIS2 is the direct responsibility of senior leadership.

Executive management is not only indirectly responsible but must actively ensure:

  • implementation of security measures
  • monitoring of compliance
  • adherence to reporting obligations
  • establishment of an effective risk management system

In some cases, personal liability may arise if these obligations are not fulfilled.

Cyber risk is therefore clearly a board-level issue.

Typical Weaknesses in Organizations

The current situation reveals recurring weaknesses across many companies.

One common issue is lack of transparency. Many organizations do not have a clear overview of their critical systems, data or third-party dependencies.

Another problem is the lack of integration of cyber risks into enterprise risk management. Risks are often handled within IT but not embedded into overall governance structures.

Documentation is frequently insufficient. Without proper evidence, regulatory requirements cannot be met.

Finally, responsibilities are often unclear. Without defined ownership, implementation becomes fragmented and ineffective.

What Companies Must Do Now

After the deadlines, the focus shifts from preparation to catch-up.

A structured approach includes several steps.

First, companies must determine whether and to what extent they are affected by NIS2. This is followed by a gap analysis comparing the current state with regulatory requirements.

Based on this, measures should be prioritized. Not all requirements must be implemented at once, but critical gaps must be addressed quickly.

At the same time, governance structures must be established. This includes clear responsibilities, reporting lines and decision-making processes.

Another key step is the implementation or enhancement of an integrated GRC system. Only then can risks, controls and compliance requirements be managed sustainably.

NIS2 as an Opportunity, Not Just an Obligation

Despite regulatory pressure, NIS2 also offers opportunities.

A structured cybersecurity risk management framework improves not only compliance but also operational resilience. Security incidents can be detected and managed more effectively.

Transparency within the organization increases. Risks become visible, responsibilities clearer and decision-making more informed.

In addition, a strong cybersecurity posture enhances trust among customers, partners and investors.

Companies that take NIS2 seriously can turn compliance into a competitive advantage.

Conclusion

The NIS2 deadline has highlighted that many organizations are not yet sufficiently prepared. At the same time, pressure from regulators and cyber threats continues to grow.

NIS2 is not a short-term compliance project but a long-term transformation. Companies must integrate cyber risks into governance, strengthen risk management and continuously manage compliance.

Those who act now in a structured way can not only reduce regulatory risk but also significantly improve resilience and competitiveness.

FAQ

What is the main objective of NIS2?
To achieve a higher and more consistent level of cybersecurity across Europe and to increase organizational accountability for cyber risks.

Why are so many companies behind?
Because the scope has expanded, requirements are complex and many organizations lack integrated GRC structures.

Who is responsible within the organization?
Executive management is responsible for implementation, oversight and compliance.

What happens in case of non-compliance?
Organizations may face regulatory action, fines and potentially personal liability for management.

How should companies get started now?
By conducting a scope assessment, performing a gap analysis and building a structured GRC system to manage compliance requirements.

3 February 2026 | 5 min

EU Anti-Money Laundering Reform and AMLA: What Companies Need to Know and Do Now

The European Union is undergoing the most far-reaching reform of its anti-money laundering framework since the creation of the single market. With the new EU Anti-Money Laundering Package, consisting of the Anti-Money Laundering Regulation (AMLR), the 6th Anti-Money Laundering Directive (AMLD6) and the new supervisory authority AMLA, the EU is fundamentally reshaping how financial crime is prevented and enforced.

The objective is clear: end fragmented national rules, close regulatory loopholes and significantly strengthen the fight against money laundering and terrorist financing. However, the impact goes far beyond the EU itself and affects many Swiss and international companies that operate in or with the European Union.

For businesses, one thing is certain: this is no longer a topic to observe – it is a topic to prepare for.

  • The EU is fully harmonising its anti-money laundering framework
  • From July 2027, uniform and directly applicable rules will apply across all EU member states
  • AMLA introduces a central EU authority with direct supervisory powers
  • Requirements for KYC, CDD, data quality and governance will increase significantly
  • Non-EU companies with EU exposure are also affected
  • 2026 is the critical preparation phase for companies

What Is the EU Anti-Money Laundering Reform Package?

The reform consists of three core elements:

1. The EU Anti-Money Laundering Regulation (AMLR)

The AMLR is a directly applicable regulation. Unlike previous directives, it does not need to be transposed into national law. As a result, the same rules will apply uniformly across all EU member states.

It regulates, among other things:

  • Customer identification and risk assessment
  • Beneficial ownership
  • Ongoing monitoring of business relationships
  • Internal controls and documentation requirements

2. The 6th Anti-Money Laundering Directive (AMLD6)

AMLD6 complements the regulation, particularly with regard to:

  • Criminal liability for money laundering offences
  • Corporate and management liability
  • Cooperation between authorities

Its aim is to ensure consistent enforcement and sanctions across the EU.

3. The New EU Authority: AMLA

The Anti-Money Laundering Authority (AMLA) is the centrepiece of the reform. It:

  • Directly supervises selected large or high-risk institutions
  • Coordinates national supervisory authorities
  • Develops technical standards and guidance
  • Sets new benchmarks for inspections and enforcement

Why Is This Reform Happening?

Fragmentation as a Structural Weakness

Until now, EU anti-money laundering rules were based on directives that allowed significant national discretion. This resulted in:

  • Inconsistent supervisory standards
  • Regulatory arbitrage
  • Weak cross-border enforcement

Criminal networks have systematically exploited these differences.

Financial Crime Is Cross-Border by Nature

Modern money laundering and terrorist financing schemes are:

  • Digital
  • International
  • Highly networked

National supervision alone is no longer sufficient to address these risks effectively.

Political and Public Pressure

High-profile money laundering cases over recent years have:

  • Undermined trust in financial systems
  • Increased political pressure for centralisation
  • Demonstrated that voluntary harmonisation does not work

The reform is therefore also a political statement: the EU intends to enforce its rules consistently.

What Will Change for Companies?

Uniform and Stricter Requirements

Companies should expect:

  • Less room for interpretation
  • More clarity, but higher standards

Practices that are currently acceptable in certain jurisdictions may no longer be sufficient under EU-wide rules.

Key areas affected include:

  • KYC and CDD processes
  • Risk scoring models
  • Documentation depth
  • Transaction monitoring mechanisms

Increased Focus on Data Quality and Transparency

The reform strongly emphasises:

  • Structured, reliable data
  • Register-based verification
  • Consistent customer information across systems

Legacy data issues and fragmented data landscapes will become a significant compliance risk.

Stronger Supervision and Sanctions

With AMLA, companies face:

  • A higher likelihood of supervisory reviews
  • More consistent enforcement across jurisdictions
  • Increased personal accountability for senior management

AML compliance becomes a strategic leadership issue, not just a regulatory function.

Who Is Particularly Affected?

  • Banks and insurance companies
  • Asset managers and investment funds
  • Payment service providers and fintechs
  • Crypto-asset service providers
  • Real estate and corporate service providers
  • Non-EU companies with EU subsidiaries or EU-based clients

Even companies headquartered outside the EU are affected if they conduct business within the EU framework.

How Should Companies Respond Now?

1. Conduct an Early Gap Analysis

Companies should assess:

  • Current AML obligations and practices
  • Differences between existing frameworks and the future EU standards
  • High-risk processes and areas of exposure

This creates a realistic foundation for planning.

2. Rethink Processes and Governance

The reform is not merely a technical or IT issue. It requires:

  • Clear accountability and ownership
  • Stronger coordination between compliance, IT and business units
  • Management-level oversight and escalation structures

3. Modernise Data and Systems

Future-proof AML frameworks require:

  • High-quality master data
  • Centralised data architectures
  • Automated monitoring and control mechanisms

Manual workarounds will no longer be sufficient.

4. Invest in Training and Culture

Employees must:

  • Understand new regulatory expectations
  • Be able to identify risks
  • Take ownership of compliance responsibilities

AML increasingly becomes a matter of corporate culture, not just policy adherence.

Conclusion

The EU Anti-Money Laundering Reform is not a marginal regulatory update – it represents a fundamental system change. With uniform rules and a central supervisory authority, the EU is raising the bar for transparency, consistency and enforcement.

Companies that act early can:

  • Reduce regulatory and operational risk
  • Handle supervisory reviews more confidently
  • Strengthen trust with customers and partners

Those who wait risk last-minute remediation, operational disruption and reputational damage.

Now is the right time to rethink AML strategically.

FAQ – Frequently Asked Questions on the EU AML Reform

When will the new rules apply?

The core requirements will apply from July 2027. However, preparation in 2025–2026 is essential.

Does the reform apply to non-EU companies?

Yes, if they operate in the EU, serve EU clients or maintain EU subsidiaries.

Will AMLA supervise every company directly?

No. AMLA will directly supervise selected large or high-risk institutions and coordinate national authorities for all others.

Is it sufficient to slightly adjust existing AML processes?

In many cases, no. The reform requires structural changes to data, governance and operating models.

Is this only relevant for compliance teams?

No. It affects senior management, IT, operations and strategic planning across the organisation.

6 January 2026 | 4 min

EU AI Act: The Strategic Final Sprint for High-Risk AI Systems

It is January 2026. The initial dust surrounding the enactment of the EU AI Regulation (EU AI Act) has settled. The bans on unacceptable risks have been effective for almost a year, and the rules for General Purpose AI (GPAI) have been in force since August 2025. However, for most enterprises, the most critical phase is beginning right now. In August 2026, the 24-month transition period for high-risk AI systems under Annex III comes to an end. This means: In just under seven months, systems in areas such as HR, critical infrastructure, or credit scoring must be fully compliant. Companies still stuck in the analysis phase risk losing market access.

  • The deadline for high-risk AI systems according to Annex III expires in August 2026.
  • A robust Risk Management System (RMS) must now be operational and fully documented.
  • Data governance is no longer just an IT topic but a central compliance requirement for training, validation, and testing data.
  • Technical documentation must be completed before placing the system on the market, not just in time for an audit.

Operational Challenges

The clock is ticking relentlessly. While many GRC professionals focused primarily on identifying and inventorying their AI landscape in 2025, 2026 demands a hard transition into operational implementation. It is no longer sufficient to know which systems are classified as high-risk. The focus now lies entirely on the demonstrability of compliance.

One of the biggest practical hurdles currently appearing is the Quality Management System (QMS). The AI Act requires not just an isolated QMS for AI, but ideally its integration into existing structures such as ISO 9001 or ISO 42001. Many companies are discovering that their existing software development processes lack the granularity required by the legislator for AI systems. In particular, the documentation of the entire lifecycle – from the first design decision to the post-market monitoring strategy – often reveals gaps during audits.

Another critical point is data governance. For high-risk AI systems that train models, the regulation prescribes strict criteria regarding data quality. Datasets must be relevant, representative, free of errors, and complete. In practice, this is a massive challenge, as historical data was often not collected with these aspects in mind. GRC teams must now work closely with data scientists to conduct bias analyses and close gaps in data lineage. If proof of training data quality is missing, the conformity of the entire system is at risk.

Furthermore, the human factor must not be underestimated. The requirement for Human Oversight dictates that the individuals supervising AI systems must possess the necessary competence to do so. This means that training measures must start now. It is not enough to pro forma designate an employee as an overseer; they must be capable of recognizing malfunctions and stopping the system if necessary (“kill switch”).

The coming months will be characterized by high pressure on internal departments. Legal, IT Security, and Compliance must finally break down their silos. An integrated GRC approach that treats AI risks not as an isolated technical problem but as a company-wide governance topic is the only way to master the August 2026 deadline without operational disruptions.

FAQ

When exactly does the transition period for high-risk AI systems end?

For most high-risk AI systems falling under Annex III of the regulation (e.g., systems in education, employment, critical infrastructure), the transition period ends on August 2, 2026. All requirements must be met by this date.

What happens if a company misses the deadline?

Systems that are not compliant may no longer be placed on the market or put into service after the deadline. Additionally, severe fines apply, which can amount to up to 35 million euros or 7 percent of the total worldwide annual turnover, depending on the infringement.

Do all AI systems need to be certified?

No. Many high-risk AI systems are subject to an internal conformity assessment. Mandatory third-party assessment by a Notified Body is primarily required for specific systems, particularly those utilizing biometrics.

22 December 2025 | 5 min

GRC Regulation 2026: New Laws and Key Dates in the DACH Region

The turn of the year traditionally marks the starting point for new regulatory requirements in the field of Governance, Risk, and Compliance. While 2025 was heavily characterized by the final implementation of major EU frameworks such as DORA and NIS 2, the year 2026 is defined by expansion and technological deepening. For companies in the DACH region (Germany, Austria, Switzerland), January 1, 2026, specifically means: Grace periods are over, new reporting standards in the crypto sector take effect, and sustainability reporting reaches the next escalation level regarding the breadth of affected companies.

  • In Switzerland, the automatic exchange of information on crypto-assets (CARF) enters into force on January 1, 2026.
  • The CSRD reporting obligation expands to large, non-capital-market-oriented companies starting with the 2026 financial year.
  • For DORA and NIS 2, the implementation phase ends; from 2026 onwards, supervisory authorities will focus on auditing and sanctioning.
  • The EU AI Act approaches decisive deadlines, making 2026 the central year for AI governance implementation.

Switzerland: Transparency Push via CARF and Expanded AEOI

A central focus at the start of 2026 lies on Switzerland. On January 1, 2026, the Federal Council enacts the Crypto-Asset Reporting Framework (CARF) as well as amendments to the Common Reporting Standard (AIA/AEOI). This is a decisive step for tax transparency in the realm of digital assets.

The CARF framework obliges Swiss crypto service providers to record transaction data of their clients and information on held crypto-assets. This data must be reported to the Federal Tax Administration (FTA), which in turn exchanges it with partner states. The goal is to close tax loopholes that existed due to the previous non-recording of crypto-assets in the classic AEOI. For GRC managers at Swiss financial institutions and crypto service providers, this means that due diligence processes and KYC procedures (Know Your Customer) must be fully adapted to the new asset classes and reporting standards by the January 2026 deadline.

In parallel, amendments to the AEOI Act come into force, implementing recommendations of the Global Forum on Transparency and Exchange of Information for Tax Purposes. This affects, among other things, more precise due diligence obligations for Non-Reporting Financial Institutions.

CSRD: The Second Wave Rolls In

At the European level, January 1, 2026, is a crucial date for the Corporate Sustainability Reporting Directive (CSRD). While previously primarily capital-market-oriented companies were subject to reporting obligations, the obligation for large limited liability companies that are not capital-market-oriented begins with the 2026 financial year.

Companies fall under this second wave if they exceed at least two of the three following criteria: more than 250 employees, more than 50 million euros in net turnover, or more than 25 million euros in balance sheet total (taking into account inflation-related threshold adjustments). For compliance departments in these companies, the start of the 2026 financial year means that data collection for the report to be published in 2027 must now be operational. The time for preparation is over; from now on, ESG data must be recorded in an audit-proof manner. This requires functioning Internal Control Systems (ICS) for sustainability information.

DORA and NIS 2: From Project Mode to Regular Operations

Both the Digital Operational Resilience Act (DORA) and the NIS 2 Directive formally entered into force before 2026. Nevertheless, January 2026 marks a watershed moment. The phase of “Day 1 Compliance,” which was often still characterized by transitional solutions, is over.

From 2026 onwards, it is expected that national supervisory authorities – such as BaFin in Germany or FMA in Austria – will intensify their auditing activities. For DORA, this means that ICT third-party risk management must not only exist on paper, but contractual adjustments with IT service providers must be concluded. Registers of information relationships must be current and complete. GRC experts should use the year 2026 to test the processes implemented in the previous year for their operational effectiveness (e.g., through TLPT – Threat Led Penetration Testing), as real sanctions now loom.

Outlook: Supply Chain Acts and CSDDD

In Germany, the Supply Chain Due Diligence Act (LkSG) remains relevant, but the focus is increasingly shifting towards harmonization with the European Corporate Sustainability Due Diligence Directive (CSDDD). Although the national implementation laws of the CSDDD will only fully enter into force later, companies must strategically align their risk analyses with the more far-reaching requirements of the EU Directive from 2026 onwards to avoid double work. In particular, the climate transition plans, which are part of the CSDDD, require a lead time that should begin in January 2026.

FAQ

Who does the new CARF law in Switzerland affect starting January 2026?

It primarily affects Crypto-Asset Service Providers (CASPs/VASPs) resident in Switzerland. They must record client data and transactions and report them to the tax authorities.

Does my company have to create a CSRD report starting in 2026?

If your company is not capital-market-oriented but meets two of the three criteria (Balance sheet > 25m EUR, Turnover > 50m EUR, > 250 employees), the duty to collect data begins for the financial year 2026. The report itself will then appear in 2027.

What changes in 2026 regarding DORA?

Regulatorily, nothing new changes, but the grace period is over. From 2026, the first in-depth audits by supervisory authorities are expected to take place, and processes must be “lived and tested.”

What role does the EU AI Act play in January 2026?

The AI Act is already in force, but many obligations for high-risk AI systems only become strictly effective in mid-2026. January 2026 is therefore the starting signal for the final implementation phase of these requirements.