Skip to content

21 April 2026 | 13 min

NIS 2: Why Germany Is Falling Behind

NIS-2 has been enforceable law in Germany since December 2025. No transition period, no grace period, no exceptions. Around 29,500 companies across 18 sectors are required to implement risk management, report security incidents, and register with the BSI. And yet: at the 21st German IT Security Congress of the Federal Office for Information Security, the BSI was forced to admit that implementation is falling far short of expectations. Registration numbers are disappointing, awareness of the directive is alarmingly low, and a significant number of affected companies have made a deliberate choice not to register at all.

What is driving this? And more importantly: how can companies finally clear the compliance hurdle without overstretching their operational resources? The answer lies, to a large degree, in modern GRC software solutions.

  • According to the BSI, nearly half of all German companies had never heard of NIS-2 by the end of 2024.
  • The NIS-2 Implementation Act has been in force since December 6, 2025, with no transition period. The BSI registration deadline expired on March 6, 2026.
  • The main reasons for non-compliance: lack of awareness, perceived complexity, resource constraints, and a deliberate wait-and-see approach.
  • Non-compliance can result in fines of up to 10 million euros or 2% of global annual turnover.
  • Managing directors and executives face personal liability for meeting cybersecurity obligations.
  • GRC software demonstrably reduces implementation effort by up to 40–50% and delivers structure, automation, and audit-readiness in a single tool.

The Wake-Up Call from the BSI Congress: Germany Is Asleep at the Wheel

At the 21st BSI Security Congress, Manuel Bach of the BSI’s Cybersecurity in Business division spoke plainly: registration numbers in the BSI’s reporting portal remain well below expectations. Worse still, the BSI is aware of companies that — after consulting their legal counsel — have made a conscious decision not to register, hoping to stay below the radar.

And then came perhaps the most alarming statistic: nearly half of all German companies had never heard the term “NIS-2” at the time of a BSI study conducted at the end of 2024. Not unfamiliar as an obligation — simply unknown as a concept.

Younes Ahmadzei, who examined NIS-2 implementation in German SMEs as part of his bachelor’s thesis at the Technical University of Munich, painted a similar picture: many of the companies he surveyed had only begun engaging seriously with the topic at the start of 2026 — after the law had already come into force without a transition period. And even those who are aware of the directive often doubt whether implementing it would actually improve their company’s IT security. NIS-2 is being perceived as a bureaucratic checkbox exercise, not as a strategic opportunity.

This finding is alarming — and, at the same time, entirely explainable.

Why So Many Companies Are Ignoring NIS-2: The Five Biggest Barriers

1. Lack of Awareness and Uncertainty About Being Affected

The first and most fundamental reason is simply a lack of awareness. Many companies do not know that NIS-2 applies to them. The directive has dramatically expanded the circle of organizations under obligation: from around 4,500 companies under the old NIS directive to more than 29,500 in Germany alone. Now covered are mid-sized companies across 18 sectors — including energy, transport, healthcare, manufacturing, digital services, financial services, and public administration.

As a general rule: companies with at least 50 employees or more than 10 million euros in annual revenue may fall within scope. Those who do not actively ask whether this applies to their organization risk overlooking their own legal obligations.

2. The Perceived Complexity of the Regulatory Framework

NIS-2 is complex. Germany attempted to address multiple regulatory challenges simultaneously within a single piece of legislation — the result is a layered rulebook that even experts find challenging. For many mid-sized businesses, the legal text feels abstract and difficult to translate into concrete operational measures.

According to the study “Cybersecurity & Digital Resilience 2026,” 47 percent of surveyed companies rate the implementation of NIS-2 as difficult or very difficult. The most commonly cited barriers — each named by around 39 percent of respondents — are the high effort required to adapt processes and policies, and the sheer complexity of the requirements themselves. A further third cite unclear regulatory guidance and integration challenges with existing IT systems.

Governance obligations, risk management, incident response, supplier assessments — many of these requirements feel as though they were written for large corporations with dedicated compliance teams. For a mechanical engineering firm with 80 employees in southern Germany, the reality looks very different.

3. Resource Constraints in SMEs

Large companies have dedicated IT departments, security teams, and in-house compliance expertise. Small and medium-sized enterprises — precisely the group that NIS-2 brings into scope for the first time — simply do not. In interviews with affected business representatives, the workload was estimated at a minimum of one person spending two to three days per week on this topic alone — a realistic assessment that many SMEs cannot absorb without significant additional cost.

There is another layer to this: many companies are technically reasonably well set up, but fall short when it comes to organizational structures and documentation. Missing process frameworks, no embedded security culture, barely any reporting structures in place — all of this makes compliance work laborious and draining.

4. The Wait-and-See Strategy

For as long as the national implementation law was not finalized, many companies chose to wait. This hesitation was a deliberate strategic calculation: investing too early might mean heading in a direction that the final legislation would correct. This posture led to a dangerous standstill — and when the law came into force in December 2025 without a transition period, many companies were completely unprepared.

That argument is now obsolete. The law is in effect. The registration deadline passed on March 6, 2026. Any company that has not yet registered is already risking a fine.

5. Underestimating Personal Liability

NIS-2 is the first German cybersecurity law to hold managing directors personally accountable. Section 38 of the new BSIG requires company management to, among other things, regularly undergo training in four core areas — at least every three years. And any executive who ignores their organization’s reporting obligations faces personal liability.

Manuel Bach of the BSI drew a sharp analogy at the congress: you cannot simply decide for yourself that you are not subject to tax obligations. The same logic applies here. Just because a company believes it falls outside the scope of NIS-2 does not make that belief legally valid.

The Cost of Inaction: What Companies Are Risking

The fine frameworks under NIS-2 are substantial. For particularly important entities, sanctions can reach up to 10 million euros or 2 percent of global annual turnover — whichever is higher. For important entities, the framework is up to 7 million euros or 1.4 percent of global revenue.

On top of that comes the personal liability of senior management, the full weight of which many executive teams have yet to appreciate. Companies with inadequate security measures also face significant reputational damage if a security incident becomes public and it is clear that no appropriate steps had been taken.

And finally: companies that are part of a supply chain are increasingly being scrutinized by larger customers and partners for compliance status. NIS-2 compliance is becoming a competitive differentiator.

Why Manual Implementation Hits a Wall

The traditional approach — bringing in consultants, maintaining Excel spreadsheets, assembling documentation in Word files — works for large corporations with the necessary resources. For mid-sized businesses, it is simply too time-consuming, too error-prone, and too difficult to scale.

NIS-2 is not a one-time project you can tick off and forget. It demands continuous risk management, regular review of security measures, structured incident response within strict reporting deadlines — significant security incidents must be reported to the BSI within 24 hours — and ongoing documentation of supply chain security.

That is not a workload you can manage with a checklist in a drawer.

How GRC Software Closes the Compliance Gap

Governance, Risk & Compliance — or GRC — software was built precisely for this problem: translating complex regulatory requirements into structured, scalable, and traceable action. For NIS-2, GRC software is not a nice-to-have. It is a strategic tool.

A Structured Starting Point Instead of Disorientation

Modern GRC platforms deliver pre-configured NIS-2 frameworks that include all relevant control areas, compliance objectives, and documentation templates. Instead of starting from scratch, a company begins with a structured gap assessment: where does the organization stand today? Which requirements are already met? Where do gaps remain?

This gap analysis is the foundation for a prioritized action plan — and exactly what many companies have been missing: a clear picture of where to start.

Automated Risk Management

NIS-2 demands the continuous identification, assessment, and mitigation of risks. Handled manually, that means recurring workshops, spreadsheet maintenance, and internal coordination rounds. A GRC platform automates these processes: risks are captured, assessed, linked to specific measures, and documented in a living risk register — one that updates automatically as the threat landscape or organizational structure evolves.

Incident Management with Integrated Reporting Workflows

The 24-hour reporting deadline for significant security incidents is one of the toughest operational requirements in NIS-2. Without structured processes, it is nearly impossible to meet. GRC software provides integrated incident management modules: incidents are recorded in a structured way, automatically classified, relevant stakeholders are notified, and reporting pathways to the BSI can be prepared in advance. Comprehensive documentation also protects management in the event of a liability claim.

Supply Chain Security and Third-Party Management

NIS-2 also requires companies to secure their supply chains. That means: suppliers and service providers must be assessed for their security practices. A GRC platform allows this third-party management to be mapped systematically — with automated questionnaires, structured assessment workflows, and a central overview of all relevant partners.

Audit-Readiness at the Push of a Button

Particularly important entities must demonstrate their measures to the BSI within three years. Organizations that map their NIS-2 compliance in a GRC platform are audit-ready at any time: all evidence, documents, risk assessments, and action logs are stored in one central location, versioned, and retrievable on demand.

Relieving the Burden on Management and IT

An often-underestimated benefit: GRC software takes pressure off executive leadership. Instead of being overwhelmed by compliance details, decision-makers get clear dashboards that show at a glance where the organization stands on NIS-2 conformity. IT teams are relieved because routine tasks are automated — by up to 40 percent, according to research data.

Multi-Framework Coverage: NIS-2 Does Not Stand Alone

Companies required to implement NIS-2 often carry other regulatory obligations as well: GDPR, ISO 27001, DORA (for financial entities), TISAX (for the automotive industry), or the forthcoming KRITIS Umbrella Act. Well-integrated GRC platforms can map these frameworks in parallel and leverage synergies — organizations that are already ISO 27001 certified have a significant head start on NIS-2 compliance.

Zazoon: GRC Software That Does Not Overwhelm

At Zazoon, we have observed the realities of the mid-market up close. Companies do not need another checklist or another consultant’s slide deck. They need a software solution that breaks NIS-2 down into manageable steps, guides the implementation, and does not demand more IT expertise than realistically exists within the organization.

Our GRC platform delivers exactly that: a structured NIS-2 onboarding experience, integrated risk management, automated documentation, and a central dashboard for both management and IT — without requiring a dedicated compliance team to be built from scratch.

Conclusion: The Cost of Waiting Is Too High

NIS-2 is not a bureaucratic construct you can wait out. It is enforceable law with substantial penalties and personal liability for management. The sobering figures from the BSI Congress show that a significant portion of German business has yet to grasp this reality — or is deliberately choosing to ignore it.

The good news: it is not too late to get started in a structured way. And GRC software makes it realistic for the first time to achieve NIS-2 compliance without a large compliance team and without six-figure consulting budgets. Companies that act now are not just protecting themselves from fines and liability risks. They are building the foundation for a more resilient IT infrastructure, strengthening the trust of their customers and partners, and positioning themselves as dependable links in a security-conscious supply chain.

The effort is real. But it is manageable — with the right tools.

Frequently Asked Questions (FAQ)

Does NIS-2 apply to my company if we are not a technology business?
Yes, in many cases. NIS-2 covers companies across 18 sectors, including energy, transport, healthcare, mechanical engineering, chemicals, food production, and public administration. As a general rule: organizations with at least 50 employees or more than 10 million euros in annual revenue should actively check whether they fall within scope. This assessment should be carried out as soon as possible.

What happens if my company missed the registration deadline?
The BSI registration deadline expired on March 6, 2026. Companies that have not yet registered are at risk of fines and should complete registration without delay. The BSI has indicated that it is actively monitoring compliance with the obligations.

How significant are the potential fines?
For particularly important entities, fines can reach up to 10 million euros or 2 percent of global annual turnover. For important entities, the framework allows for fines of up to 7 million euros or 1.4 percent of global revenue.

What is the difference between “important” and “particularly important” entities?
Particularly important entities are larger organizations in critical sectors such as energy, water, financial market infrastructure, and healthcare. Important entities include mid-sized companies and organizations from additional sectors such as manufacturing, food, and digital services. The precise classification depends on sector, company size, and market position.

Does ISO 27001 certification help with NIS-2 implementation?
Yes, significantly. ISO 27001 and NIS-2 overlap in many areas — particularly around the information security management system (ISMS), risk analysis, and the documentation of security measures. Organizations that are already ISO 27001 certified have a meaningful head start. Good GRC platforms map both frameworks in parallel and use existing work as the foundation for NIS-2 compliance.

How long does NIS-2 implementation take with GRC software?
It depends on the organization’s starting point. With a GRC platform that includes structured templates, gap analyses, and automated workflows, well-prepared companies can reduce the time to compliance by up to 50 percent compared to a purely manual approach. Realistic timelines for reaching an initial solid compliance baseline are three to six months.

What exactly do I need to do as a managing director or executive?
Under Section 38 of the new BSIG, company management must actively oversee and approve the implementation of risk management measures. Regular training in four core areas is also mandatory — at a minimum every three years. Those who neglect these obligations face personal liability. A GRC platform helps document and evidence these activities in a structured and verifiable way.

Can GRC software also cover supply chain security?
Yes. Modern GRC platforms offer third-party management modules that allow suppliers and service providers to be systematically assessed and documented. This is particularly important given that NIS-2 explicitly requires supply chain security as part of an organization’s overall risk management obligations.

Related posts

14 April 2026 | 5 min

EU Anti-Corruption Directive 2026: A Unified Criminal Law Framework Reshaping Compliance in Europe

Corruption remains one of the most significant structural risks for both companies and governments across Europe. Despite numerous national laws, a core issue has persisted: lack of consistency. Diverging definitions, penalties, and enforcement mechanisms have enabled corruption to operate across borders and exploit regulatory gaps.

With the EU Anti-Corruption Directive 2026, this fragmented landscape is fundamentally changing. For the first time, the European Union establishes a unified minimum criminal law framework, requiring all Member States to combat corruption based on the same principles.

  • EU-wide minimum criminal law framework for anti-corruption
  • Harmonised definitions of core corruption offences
  • Alignment of minimum penalties and sanctions
  • Significantly expanded corporate liability
  • Mandatory national anti-corruption strategies
  • Stronger cooperation between EU and national authorities
  • Implementation into national law within 2 to 3 years

Why the EU Is Acting Now

Corruption is no longer a purely national issue. It is closely linked to organised crime, money laundering, and the misuse of public funds. At the same time, inconsistent national regulations have allowed corruption networks to exploit weaker legal systems within the EU.

The result has been ineffective enforcement, limited deterrence, and substantial economic damage. The directive is a direct response to these structural weaknesses.

The Core of the Directive: Harmonisation Over Fragmentation

The EU’s approach is clear: not full legal unification, but binding minimum standards that all Member States must implement.

Harmonised Definition of Corruption Offences

A major step forward is the establishment of a consistent EU-wide catalogue of corruption offences, including:

  • Bribery in both the public and private sectors
  • Embezzlement
  • Trading in influence
  • Obstruction of justice
  • Illicit enrichment
  • Concealment of assets

This harmonisation significantly reduces interpretative gaps and limits the ability to exploit regulatory differences.

Minimum Penalties and Sanctions

The directive also introduces aligned sanction frameworks to ensure consistent deterrence across the EU.

Key measures include:

  • Minimum prison sentences of several years depending on the offence
  • Substantial financial penalties for companies, often linked to turnover
  • Additional sanctions such as exclusion from public procurement
  • Penalties targeting responsible executives

This reduces the risk of “soft jurisdictions” within the EU.

Companies in Focus: Increased Liability Risks

One of the most impactful aspects of the directive is the expansion of corporate liability. Companies will be held accountable more directly than before.

Liability applies when:

  • Corruption is committed for the company’s benefit
  • Adequate preventive and control measures are lacking

This marks a shift from individual accountability to structural corporate responsibility.

Practical Impact on Compliance

Companies will need to strengthen their compliance frameworks significantly:

  • Enhancement of internal control systems
  • Stronger third-party and supply chain oversight
  • Implementation of effective whistleblowing systems
  • Demonstration of a functioning compliance culture
  • Comprehensive documentation of preventive measures

Organisations without robust anti-corruption programmes will face significantly increased risk.

Prevention as a Strategic Pillar

The directive goes beyond criminal law by embedding prevention and governance requirements.

Member States must:

  • Develop national anti-corruption strategies
  • Conduct regular risk assessments
  • Establish independent oversight bodies
  • Improve transparency through structured data

This creates a systematic approach that not only punishes corruption but actively prevents it.

Stronger EU-Wide Cooperation

Another key improvement is enhanced cooperation between authorities.

The directive promotes:

  • Increased information exchange between Member States
  • Closer collaboration with EU institutions
  • Better coordination in cross-border investigations

This directly addresses a major historical weakness: lack of coordination.

Limitations and Criticism

Despite its scope, the directive remains a political compromise.

Key points of criticism include:

  • Some provisions have been weakened compared to earlier drafts
  • Focus on minimum standards rather than full harmonisation
  • Potential differences in implementation speed across Member States

Nevertheless, the directive represents a landmark step and lays the foundation for future regulatory developments.

Implications for GRC and Corporate Strategy

For GRC professionals, the directive has strong strategic implications.

Key developments include:

  • Increased regulatory consistency across the EU
  • Greater visibility and comparability of risks
  • More coordinated and effective enforcement
  • Need for EU-wide consistency in compliance systems

The ability to demonstrate compliance effectiveness will become a critical success factor.

Conclusion

The EU Anti-Corruption Directive 2026 marks a turning point in European regulation. It closes long-standing gaps, introduces consistent minimum standards, and significantly increases enforcement pressure on companies.

For organisations, this means corruption risks will not only be more tightly regulated but also more actively enforced.

Those who invest early in robust compliance frameworks will gain a strategic advantage. Those who delay face growing regulatory and financial exposure.

FAQ

When will the directive take effect?

Member States generally have 2 to 3 years to transpose the directive into national law. The new requirements will apply once implemented.

Does the directive apply directly to companies?

No. It must first be transposed into national law. Its impact on companies will come through national legislation.

Which companies are most affected?

All companies may be affected, especially those operating internationally, in regulated sectors, or with significant public sector exposure.

What are the key changes compared to the current framework?

The main shift is harmonisation. Definitions, sanctions, and enforcement will become more aligned across the EU, reducing loopholes.

What role will compliance play going forward?

Compliance will become a central management function. Companies must be able to demonstrate effective preventive measures.

What are the main risks of non-compliance?

High financial penalties, reputational damage, exclusion from public contracts, and potential criminal liability for responsible individuals.

Is this the beginning of further EU criminal law initiatives?

Highly likely. The directive signals a broader willingness by the EU to harmonise criminal law in areas such as GRC and financial crime.

24 March 2026 | 5 min

Regulation Overload 2026: How Companies Can Manage NIS2, the AI Act and DORA at the Same Time

In March 2026, “regulation overload” is no longer an exaggeration – it is operational reality. NIS2 has entered the implementation phase, DORA is already fully applicable, and the AI Act is being rolled out in stages with major obligations coming into force in 2026.

Companies are no longer dealing with a single regulatory deadline, but with multiple frameworks that differ in structure, scope and supervisory expectations. The real challenge is not any individual regulation, but the combination of all three.

  • In 2026, companies face three major regulatory frameworks at the same time: NIS2, DORA and the AI Act.
  • These regulations follow different logics but overlap significantly in governance, risk management and compliance requirements.
  • The biggest challenge is not understanding each regulation individually, but managing them together.
  • Many organizations still approach them as separate projects, creating unnecessary complexity.
  • A unified GRC approach is essential to handle overlapping requirements efficiently.
  • The key to success lies in integration, not duplication.

Why 2026 Is a Stress Test for GRC

The regulatory landscape has reached a level of complexity where traditional approaches no longer work. Organizations must deal with:

  • Horizontal cybersecurity requirements under NIS2
  • Sector-specific resilience requirements under DORA
  • Risk-based AI regulation under the AI Act

Each framework introduces its own terminology, processes and reporting obligations. However, in practice, they all impact the same underlying systems, processes and governance structures.

This creates a structural challenge: different regulations, but the same operational reality.

Three Frameworks, Three Logics

NIS2: Broad Cybersecurity Governance

NIS2 significantly expands the scope of cybersecurity regulation across multiple sectors. It requires organizations to implement structured risk management, incident reporting and supply chain security.

From a GRC perspective, one of its most important aspects is the clear responsibility of management. Cybersecurity is no longer a technical topic – it is a governance issue.

DORA: Operational Resilience in the Financial Sector

DORA focuses specifically on financial institutions and their ability to remain operational under digital stress.

It introduces detailed requirements for:

  • ICT risk management
  • Incident reporting
  • Resilience testing
  • Third-party risk management

Compared to NIS2, DORA is more granular and operationally demanding, especially in reporting and documentation.

AI Act: Risk-Based Regulation for Artificial Intelligence

The AI Act introduces a completely different regulatory approach. Instead of focusing on infrastructure or resilience, it regulates the use of AI systems based on risk levels.

High-risk AI systems must meet strict requirements, including:

  • documented risk management
  • transparency
  • human oversight
  • technical documentation and logging

For many companies, this is the first time AI becomes a formal compliance topic.

Where the Regulations Overlap

1. Governance and Accountability

All three frameworks shift responsibility to senior management. Decisions around cybersecurity, operational resilience and AI usage must be governed at the highest level.

2. Risk Management

Each regulation requires structured risk management, but in different contexts:

  • cyber risk under NIS2
  • ICT and operational risk under DORA
  • system and model risk under the AI Act

The underlying principle is the same: risks must be identified, assessed and controlled continuously.

3. Incident Management

Incident reporting is a key requirement across all three frameworks.

Organizations must be able to:

  • detect incidents quickly
  • classify them correctly
  • report them within strict timelines

Managing this across multiple regulatory regimes requires a unified approach.

4. Third-Party Risk

Supply chains and external dependencies are a major focus area.

  • NIS2 emphasizes supply chain security
  • DORA introduces strict requirements for ICT providers
  • The AI Act indirectly addresses dependencies in AI value chains

This makes third-party risk management a central GRC function.

5. Documentation and Evidence

All three frameworks require extensive documentation.

The real challenge is not implementation, but proof. Companies must demonstrate that controls exist, are effective and are continuously monitored.

Why Many Organizations Struggle

A common mistake is treating each regulation as a separate project.

This leads to:

  • duplicate controls
  • inconsistent processes
  • fragmented reporting
  • increased complexity

Another issue is organizational silos. Different teams handle different regulations without coordination, even though they address the same underlying risks.

Finally, many companies underestimate the operational impact. These regulations do not only affect compliance functions, but also IT, operations, product development and management.

How Companies Should Respond

The key to managing regulation overload is integration.

Instead of building separate compliance programs, organizations should:

  • establish a unified GRC framework
  • define a common control structure
  • align risk management across domains
  • create centralized incident handling processes
  • build a shared evidence and reporting model

This approach reduces duplication and creates consistency across regulatory requirements.

Equally important is prioritization. Companies should focus on overlapping areas first, as improvements there will have the greatest impact across all frameworks.

Conclusion

Regulation overload in 2026 is not just a question of volume, but of structure. Companies do not fail because there are too many rules. They fail because they manage them in isolation.

NIS2, DORA and the AI Act must be understood as part of a single GRC challenge. Organizations that integrate governance, risk and compliance across these frameworks will not only meet regulatory expectations more efficiently, but also become more resilient and better controlled.

FAQ

Do all companies need to comply with all three regulations?
No. However, many organizations are affected by at least one framework, and in complex structures, multiple regulations may apply simultaneously.

Which regulation takes precedence?
This depends on the sector. For financial institutions, DORA often overrides overlapping cybersecurity requirements, but a proper legal assessment is required.

What is the biggest challenge in 2026?
Managing overlapping requirements across different regulations without creating unnecessary complexity.

Can companies handle each regulation separately?
Technically yes, but practically this leads to inefficiency and fragmentation. Integration is the more sustainable approach.

Where should companies start?
With a unified GRC framework that maps all regulatory requirements onto a shared control and risk management structure.

17 March 2026 | 5 min

After the NIS2 Deadline: Why Two-Thirds of Companies Are Falling Behind – and What Really Matters Now

The NIS2 Directive is one of the most important regulatory developments in the field of cybersecurity and GRC. Its goal is to significantly raise the level of cybersecurity across Europe and to place greater responsibility on organizations. However, shortly after key deadlines have passed, a clear picture is emerging: a large proportion of affected companies are not sufficiently prepared.

Many organizations underestimated the requirements, misjudged whether they are in scope, or started implementing measures too late. At the same time, pressure is increasing due to regulatory scrutiny, stricter enforcement and the risk of significant penalties.

The key question is no longer whether companies should address NIS2, but how they can now catch up in a structured and effective way.

  • A large proportion of affected companies have missed the NIS2 deadlines.
  • NIS2 significantly expands the scope of regulated organizations and tightens requirements.
  • Cyber risks are becoming a central governance and management topic.
  • Executive management carries direct responsibility and potential liability.
  • Many organizations show gaps in risk management, documentation and accountability.
  • The priority now is gap analysis, prioritization and structured implementation.
  • NIS2 is not a one-time project but requires a sustainable GRC system.

Why So Many Companies Are Behind

The high number of unprepared organizations is not a coincidence. NIS2 introduces several structural challenges.

First, the scope has been significantly expanded. Unlike the original NIS Directive, NIS2 applies not only to critical infrastructure operators but also to a wide range of medium-sized and large companies across multiple sectors.

Second, many organizations are uncertain whether they are in scope. The criteria are complex and depend on sector, size and specific activities.

Third, the requirements are often underestimated. NIS2 is not just an IT security initiative but requires a comprehensive cybersecurity risk management framework.

Fourth, many companies lack integrated GRC structures to systematically implement regulatory requirements.

NIS2 as a Game Changer for GRC

NIS2 fundamentally changes the role of governance, risk and compliance.

Cybersecurity is no longer treated as a purely technical issue but as an integral part of corporate management. The directive requires, among other things:

  • structured cybersecurity risk management
  • clear responsibilities at management level
  • documented security measures
  • incident reporting obligations
  • training for executive management
  • supply chain and third-party security

This makes NIS2 a classic GRC topic that connects governance, risk and compliance.

The Role of Executive Management

A key aspect of NIS2 is the direct responsibility of senior leadership.

Executive management is not only indirectly responsible but must actively ensure:

  • implementation of security measures
  • monitoring of compliance
  • adherence to reporting obligations
  • establishment of an effective risk management system

In some cases, personal liability may arise if these obligations are not fulfilled.

Cyber risk is therefore clearly a board-level issue.

Typical Weaknesses in Organizations

The current situation reveals recurring weaknesses across many companies.

One common issue is lack of transparency. Many organizations do not have a clear overview of their critical systems, data or third-party dependencies.

Another problem is the lack of integration of cyber risks into enterprise risk management. Risks are often handled within IT but not embedded into overall governance structures.

Documentation is frequently insufficient. Without proper evidence, regulatory requirements cannot be met.

Finally, responsibilities are often unclear. Without defined ownership, implementation becomes fragmented and ineffective.

What Companies Must Do Now

After the deadlines, the focus shifts from preparation to catch-up.

A structured approach includes several steps.

First, companies must determine whether and to what extent they are affected by NIS2. This is followed by a gap analysis comparing the current state with regulatory requirements.

Based on this, measures should be prioritized. Not all requirements must be implemented at once, but critical gaps must be addressed quickly.

At the same time, governance structures must be established. This includes clear responsibilities, reporting lines and decision-making processes.

Another key step is the implementation or enhancement of an integrated GRC system. Only then can risks, controls and compliance requirements be managed sustainably.

NIS2 as an Opportunity, Not Just an Obligation

Despite regulatory pressure, NIS2 also offers opportunities.

A structured cybersecurity risk management framework improves not only compliance but also operational resilience. Security incidents can be detected and managed more effectively.

Transparency within the organization increases. Risks become visible, responsibilities clearer and decision-making more informed.

In addition, a strong cybersecurity posture enhances trust among customers, partners and investors.

Companies that take NIS2 seriously can turn compliance into a competitive advantage.

Conclusion

The NIS2 deadline has highlighted that many organizations are not yet sufficiently prepared. At the same time, pressure from regulators and cyber threats continues to grow.

NIS2 is not a short-term compliance project but a long-term transformation. Companies must integrate cyber risks into governance, strengthen risk management and continuously manage compliance.

Those who act now in a structured way can not only reduce regulatory risk but also significantly improve resilience and competitiveness.

FAQ

What is the main objective of NIS2?
To achieve a higher and more consistent level of cybersecurity across Europe and to increase organizational accountability for cyber risks.

Why are so many companies behind?
Because the scope has expanded, requirements are complex and many organizations lack integrated GRC structures.

Who is responsible within the organization?
Executive management is responsible for implementation, oversight and compliance.

What happens in case of non-compliance?
Organizations may face regulatory action, fines and potentially personal liability for management.

How should companies get started now?
By conducting a scope assessment, performing a gap analysis and building a structured GRC system to manage compliance requirements.

3 February 2026 | 5 min

EU Anti-Money Laundering Reform and AMLA: What Companies Need to Know and Do Now

The European Union is undergoing the most far-reaching reform of its anti-money laundering framework since the creation of the single market. With the new EU Anti-Money Laundering Package, consisting of the Anti-Money Laundering Regulation (AMLR), the 6th Anti-Money Laundering Directive (AMLD6) and the new supervisory authority AMLA, the EU is fundamentally reshaping how financial crime is prevented and enforced.

The objective is clear: end fragmented national rules, close regulatory loopholes and significantly strengthen the fight against money laundering and terrorist financing. However, the impact goes far beyond the EU itself and affects many Swiss and international companies that operate in or with the European Union.

For businesses, one thing is certain: this is no longer a topic to observe – it is a topic to prepare for.

  • The EU is fully harmonising its anti-money laundering framework
  • From July 2027, uniform and directly applicable rules will apply across all EU member states
  • AMLA introduces a central EU authority with direct supervisory powers
  • Requirements for KYC, CDD, data quality and governance will increase significantly
  • Non-EU companies with EU exposure are also affected
  • 2026 is the critical preparation phase for companies

What Is the EU Anti-Money Laundering Reform Package?

The reform consists of three core elements:

1. The EU Anti-Money Laundering Regulation (AMLR)

The AMLR is a directly applicable regulation. Unlike previous directives, it does not need to be transposed into national law. As a result, the same rules will apply uniformly across all EU member states.

It regulates, among other things:

  • Customer identification and risk assessment
  • Beneficial ownership
  • Ongoing monitoring of business relationships
  • Internal controls and documentation requirements

2. The 6th Anti-Money Laundering Directive (AMLD6)

AMLD6 complements the regulation, particularly with regard to:

  • Criminal liability for money laundering offences
  • Corporate and management liability
  • Cooperation between authorities

Its aim is to ensure consistent enforcement and sanctions across the EU.

3. The New EU Authority: AMLA

The Anti-Money Laundering Authority (AMLA) is the centrepiece of the reform. It:

  • Directly supervises selected large or high-risk institutions
  • Coordinates national supervisory authorities
  • Develops technical standards and guidance
  • Sets new benchmarks for inspections and enforcement

Why Is This Reform Happening?

Fragmentation as a Structural Weakness

Until now, EU anti-money laundering rules were based on directives that allowed significant national discretion. This resulted in:

  • Inconsistent supervisory standards
  • Regulatory arbitrage
  • Weak cross-border enforcement

Criminal networks have systematically exploited these differences.

Financial Crime Is Cross-Border by Nature

Modern money laundering and terrorist financing schemes are:

  • Digital
  • International
  • Highly networked

National supervision alone is no longer sufficient to address these risks effectively.

Political and Public Pressure

High-profile money laundering cases over recent years have:

  • Undermined trust in financial systems
  • Increased political pressure for centralisation
  • Demonstrated that voluntary harmonisation does not work

The reform is therefore also a political statement: the EU intends to enforce its rules consistently.

What Will Change for Companies?

Uniform and Stricter Requirements

Companies should expect:

  • Less room for interpretation
  • More clarity, but higher standards

Practices that are currently acceptable in certain jurisdictions may no longer be sufficient under EU-wide rules.

Key areas affected include:

  • KYC and CDD processes
  • Risk scoring models
  • Documentation depth
  • Transaction monitoring mechanisms

Increased Focus on Data Quality and Transparency

The reform strongly emphasises:

  • Structured, reliable data
  • Register-based verification
  • Consistent customer information across systems

Legacy data issues and fragmented data landscapes will become a significant compliance risk.

Stronger Supervision and Sanctions

With AMLA, companies face:

  • A higher likelihood of supervisory reviews
  • More consistent enforcement across jurisdictions
  • Increased personal accountability for senior management

AML compliance becomes a strategic leadership issue, not just a regulatory function.

Who Is Particularly Affected?

  • Banks and insurance companies
  • Asset managers and investment funds
  • Payment service providers and fintechs
  • Crypto-asset service providers
  • Real estate and corporate service providers
  • Non-EU companies with EU subsidiaries or EU-based clients

Even companies headquartered outside the EU are affected if they conduct business within the EU framework.

How Should Companies Respond Now?

1. Conduct an Early Gap Analysis

Companies should assess:

  • Current AML obligations and practices
  • Differences between existing frameworks and the future EU standards
  • High-risk processes and areas of exposure

This creates a realistic foundation for planning.

2. Rethink Processes and Governance

The reform is not merely a technical or IT issue. It requires:

  • Clear accountability and ownership
  • Stronger coordination between compliance, IT and business units
  • Management-level oversight and escalation structures

3. Modernise Data and Systems

Future-proof AML frameworks require:

  • High-quality master data
  • Centralised data architectures
  • Automated monitoring and control mechanisms

Manual workarounds will no longer be sufficient.

4. Invest in Training and Culture

Employees must:

  • Understand new regulatory expectations
  • Be able to identify risks
  • Take ownership of compliance responsibilities

AML increasingly becomes a matter of corporate culture, not just policy adherence.

Conclusion

The EU Anti-Money Laundering Reform is not a marginal regulatory update – it represents a fundamental system change. With uniform rules and a central supervisory authority, the EU is raising the bar for transparency, consistency and enforcement.

Companies that act early can:

  • Reduce regulatory and operational risk
  • Handle supervisory reviews more confidently
  • Strengthen trust with customers and partners

Those who wait risk last-minute remediation, operational disruption and reputational damage.

Now is the right time to rethink AML strategically.

FAQ – Frequently Asked Questions on the EU AML Reform

When will the new rules apply?

The core requirements will apply from July 2027. However, preparation in 2025–2026 is essential.

Does the reform apply to non-EU companies?

Yes, if they operate in the EU, serve EU clients or maintain EU subsidiaries.

Will AMLA supervise every company directly?

No. AMLA will directly supervise selected large or high-risk institutions and coordinate national authorities for all others.

Is it sufficient to slightly adjust existing AML processes?

In many cases, no. The reform requires structural changes to data, governance and operating models.

Is this only relevant for compliance teams?

No. It affects senior management, IT, operations and strategic planning across the organisation.

6 January 2026 | 4 min

EU AI Act: The Strategic Final Sprint for High-Risk AI Systems

It is January 2026. The initial dust surrounding the enactment of the EU AI Regulation (EU AI Act) has settled. The bans on unacceptable risks have been effective for almost a year, and the rules for General Purpose AI (GPAI) have been in force since August 2025. However, for most enterprises, the most critical phase is beginning right now. In August 2026, the 24-month transition period for high-risk AI systems under Annex III comes to an end. This means: In just under seven months, systems in areas such as HR, critical infrastructure, or credit scoring must be fully compliant. Companies still stuck in the analysis phase risk losing market access.

  • The deadline for high-risk AI systems according to Annex III expires in August 2026.
  • A robust Risk Management System (RMS) must now be operational and fully documented.
  • Data governance is no longer just an IT topic but a central compliance requirement for training, validation, and testing data.
  • Technical documentation must be completed before placing the system on the market, not just in time for an audit.

Operational Challenges

The clock is ticking relentlessly. While many GRC professionals focused primarily on identifying and inventorying their AI landscape in 2025, 2026 demands a hard transition into operational implementation. It is no longer sufficient to know which systems are classified as high-risk. The focus now lies entirely on the demonstrability of compliance.

One of the biggest practical hurdles currently appearing is the Quality Management System (QMS). The AI Act requires not just an isolated QMS for AI, but ideally its integration into existing structures such as ISO 9001 or ISO 42001. Many companies are discovering that their existing software development processes lack the granularity required by the legislator for AI systems. In particular, the documentation of the entire lifecycle – from the first design decision to the post-market monitoring strategy – often reveals gaps during audits.

Another critical point is data governance. For high-risk AI systems that train models, the regulation prescribes strict criteria regarding data quality. Datasets must be relevant, representative, free of errors, and complete. In practice, this is a massive challenge, as historical data was often not collected with these aspects in mind. GRC teams must now work closely with data scientists to conduct bias analyses and close gaps in data lineage. If proof of training data quality is missing, the conformity of the entire system is at risk.

Furthermore, the human factor must not be underestimated. The requirement for Human Oversight dictates that the individuals supervising AI systems must possess the necessary competence to do so. This means that training measures must start now. It is not enough to pro forma designate an employee as an overseer; they must be capable of recognizing malfunctions and stopping the system if necessary (“kill switch”).

The coming months will be characterized by high pressure on internal departments. Legal, IT Security, and Compliance must finally break down their silos. An integrated GRC approach that treats AI risks not as an isolated technical problem but as a company-wide governance topic is the only way to master the August 2026 deadline without operational disruptions.

FAQ

When exactly does the transition period for high-risk AI systems end?

For most high-risk AI systems falling under Annex III of the regulation (e.g., systems in education, employment, critical infrastructure), the transition period ends on August 2, 2026. All requirements must be met by this date.

What happens if a company misses the deadline?

Systems that are not compliant may no longer be placed on the market or put into service after the deadline. Additionally, severe fines apply, which can amount to up to 35 million euros or 7 percent of the total worldwide annual turnover, depending on the infringement.

Do all AI systems need to be certified?

No. Many high-risk AI systems are subject to an internal conformity assessment. Mandatory third-party assessment by a Notified Body is primarily required for specific systems, particularly those utilizing biometrics.

22 December 2025 | 5 min

GRC Regulation 2026: New Laws and Key Dates in the DACH Region

The turn of the year traditionally marks the starting point for new regulatory requirements in the field of Governance, Risk, and Compliance. While 2025 was heavily characterized by the final implementation of major EU frameworks such as DORA and NIS 2, the year 2026 is defined by expansion and technological deepening. For companies in the DACH region (Germany, Austria, Switzerland), January 1, 2026, specifically means: Grace periods are over, new reporting standards in the crypto sector take effect, and sustainability reporting reaches the next escalation level regarding the breadth of affected companies.

  • In Switzerland, the automatic exchange of information on crypto-assets (CARF) enters into force on January 1, 2026.
  • The CSRD reporting obligation expands to large, non-capital-market-oriented companies starting with the 2026 financial year.
  • For DORA and NIS 2, the implementation phase ends; from 2026 onwards, supervisory authorities will focus on auditing and sanctioning.
  • The EU AI Act approaches decisive deadlines, making 2026 the central year for AI governance implementation.

Switzerland: Transparency Push via CARF and Expanded AEOI

A central focus at the start of 2026 lies on Switzerland. On January 1, 2026, the Federal Council enacts the Crypto-Asset Reporting Framework (CARF) as well as amendments to the Common Reporting Standard (AIA/AEOI). This is a decisive step for tax transparency in the realm of digital assets.

The CARF framework obliges Swiss crypto service providers to record transaction data of their clients and information on held crypto-assets. This data must be reported to the Federal Tax Administration (FTA), which in turn exchanges it with partner states. The goal is to close tax loopholes that existed due to the previous non-recording of crypto-assets in the classic AEOI. For GRC managers at Swiss financial institutions and crypto service providers, this means that due diligence processes and KYC procedures (Know Your Customer) must be fully adapted to the new asset classes and reporting standards by the January 2026 deadline.

In parallel, amendments to the AEOI Act come into force, implementing recommendations of the Global Forum on Transparency and Exchange of Information for Tax Purposes. This affects, among other things, more precise due diligence obligations for Non-Reporting Financial Institutions.

CSRD: The Second Wave Rolls In

At the European level, January 1, 2026, is a crucial date for the Corporate Sustainability Reporting Directive (CSRD). While previously primarily capital-market-oriented companies were subject to reporting obligations, the obligation for large limited liability companies that are not capital-market-oriented begins with the 2026 financial year.

Companies fall under this second wave if they exceed at least two of the three following criteria: more than 250 employees, more than 50 million euros in net turnover, or more than 25 million euros in balance sheet total (taking into account inflation-related threshold adjustments). For compliance departments in these companies, the start of the 2026 financial year means that data collection for the report to be published in 2027 must now be operational. The time for preparation is over; from now on, ESG data must be recorded in an audit-proof manner. This requires functioning Internal Control Systems (ICS) for sustainability information.

DORA and NIS 2: From Project Mode to Regular Operations

Both the Digital Operational Resilience Act (DORA) and the NIS 2 Directive formally entered into force before 2026. Nevertheless, January 2026 marks a watershed moment. The phase of “Day 1 Compliance,” which was often still characterized by transitional solutions, is over.

From 2026 onwards, it is expected that national supervisory authorities – such as BaFin in Germany or FMA in Austria – will intensify their auditing activities. For DORA, this means that ICT third-party risk management must not only exist on paper, but contractual adjustments with IT service providers must be concluded. Registers of information relationships must be current and complete. GRC experts should use the year 2026 to test the processes implemented in the previous year for their operational effectiveness (e.g., through TLPT – Threat Led Penetration Testing), as real sanctions now loom.

Outlook: Supply Chain Acts and CSDDD

In Germany, the Supply Chain Due Diligence Act (LkSG) remains relevant, but the focus is increasingly shifting towards harmonization with the European Corporate Sustainability Due Diligence Directive (CSDDD). Although the national implementation laws of the CSDDD will only fully enter into force later, companies must strategically align their risk analyses with the more far-reaching requirements of the EU Directive from 2026 onwards to avoid double work. In particular, the climate transition plans, which are part of the CSDDD, require a lead time that should begin in January 2026.

FAQ

Who does the new CARF law in Switzerland affect starting January 2026?

It primarily affects Crypto-Asset Service Providers (CASPs/VASPs) resident in Switzerland. They must record client data and transactions and report them to the tax authorities.

Does my company have to create a CSRD report starting in 2026?

If your company is not capital-market-oriented but meets two of the three criteria (Balance sheet > 25m EUR, Turnover > 50m EUR, > 250 employees), the duty to collect data begins for the financial year 2026. The report itself will then appear in 2027.

What changes in 2026 regarding DORA?

Regulatorily, nothing new changes, but the grace period is over. From 2026, the first in-depth audits by supervisory authorities are expected to take place, and processes must be “lived and tested.”

What role does the EU AI Act play in January 2026?

The AI Act is already in force, but many obligations for high-risk AI systems only become strictly effective in mid-2026. January 2026 is therefore the starting signal for the final implementation phase of these requirements.

11 December 2025 | 6 min

Holiday gifts for business partners in the DACH region

During the Christmas season, many companies take the opportunity to thank their business partners with small gifts. These gestures strengthen relationships, show appreciation and are often part of a company’s culture. At the same time, tax rules, compliance requirements and internal guidelines must be respected – and these differ between Germany, Austria and Switzerland.

This article provides a current and balanced overview of the legal and practical framework for holiday gifts in all three DACH countries. It explains what companies should consider in order to give appropriately, avoid risks and maintain trust.

  • In all three countries, the same core principles apply: gifts must be business related, appropriate and transparent.
  • Germany has a tax threshold of 50 euros per recipient and calendar year for business gifts.
  • Austria and Switzerland do not use a single statutory value limit, but focus on appropriateness, business purpose and documentation.
  • Clear internal guidelines and consistent documentation are recommended throughout the DACH region.
  • Gifts to people in the public sector or highly regulated industries require particular caution.

Why clear rules are important in all three countries

Regardless of whether a company is based in Austria, Switzerland or Germany, gifts must never give the impression that they are intended to influence business decisions improperly. Compliance standards, anti-corruption rules and tax legislation are designed to ensure clean business relationships.

Companies should therefore apply clear and comprehensible principles in every country in which they operate. This prevents misunderstandings, reduces legal and tax risks and creates a uniform standard for all employees.

Current regulations at a glance

Germany

Germany is the only DACH country with a clearly defined tax limit for gifts to business partners. Business gifts are tax deductible up to 50 euros per recipient and calendar year if they are business related and properly documented.

For gifts that exceed this amount, the tax deduction may be denied unless the gift is clearly and exclusively usable for business purposes.

Austria

Austria does not work with a uniform fixed value limit. Instead, the following aspects are crucial:

  • the gift must serve a clear business purpose
  • the value must be reasonable in relation to the relationship and the occasion
  • the gift must be documented in a comprehensible way

As in the other DACH countries, gifts must not be used to gain improper advantages. Particular care is required in the public sector and in strongly regulated industries.

Switzerland

Switzerland also has no statutory standard limit for gifts to business partners. The focus is on:

  • usual appropriateness according to Swiss business practice
  • transparency and traceability
  • compliance with internal rules and industry-specific regulations

Swiss business culture tends to favour modest, high-quality but unobtrusive gifts rather than expensive luxury items.

Common basic principles for the entire DACH region

Despite the legal differences, companies in Germany, Austria and Switzerland can follow a common set of basic rules.

Appropriateness

The gift should match the business relationship, the role of the recipient and the occasion. Very expensive or flashy gifts can quickly appear inappropriate.

Business purpose

Holiday gifts should always serve a legitimate business purpose, such as maintaining a good relationship or thanking partners for successful cooperation. They must not be used to steer decisions or promises of business.

Documentation

For every gift, companies should record at least the following:

  • name of the recipient and company
  • occasion
  • date
  • value
  • business purpose

This documentation helps during tax audits and internal or external compliance checks.

Caution with public sector recipients

For employees of authorities, public hospitals, universities, municipalities and similar organisations, stricter requirements usually apply in all three countries. Often only very small tokens are permitted, and in some cases gifts are completely prohibited. When in doubt, it is better to ask in advance or avoid gifts altogether.

Recommendations for companies in the DACH region

  1. Create a clear, written gifting policy that applies in all locations.
  2. Define maximum values for gifts per person and per year.
  3. Ensure consistent documentation of all gifts to business partners.
  4. Pay special attention to sensitive sectors such as the public sector, healthcare or regulated industries.
  5. Plan gifts early and avoid borderline cases in terms of value or type of gift.
  6. Consider alternatives such as charitable donations in the name of a business partner instead of material gifts.

Why restraint is often the best strategy

No matter in which of the three countries a company operates, gifts that are too expensive or too personal can send the wrong signal. They may be perceived as an attempt to influence decisions and can trigger tax or compliance issues.

Modest, tasteful gifts or a personal handwritten card are often more effective and credible than high-value items. What counts in the long term is trust and partnership – not the material value of a present.

FAQ – Frequently asked questions in the DACH region

Is there a single value limit that applies to the whole DACH region?

No. Germany has a defined tax threshold of 50 euros per recipient and calendar year for business gifts. Austria and Switzerland use the principles of appropriateness, business purpose and documentation instead of fixed legal limits.

May I give expensive gifts in Austria or Switzerland if they seem appropriate?

In principle this is possible, but it is usually not advisable. High-value gifts increase the risk of compliance concerns, negative perceptions and disputes during audits. In practice, modest gifts are safer and more in line with expectations.

How should a business gift be documented correctly?

For each gift you should record who received it, for which company the person works, the date, the occasion, the value and the business reason. This information should be stored centrally, for example in a simple gifts register.

Are gifts to employees treated in the same way as gifts to business partners?

No. Gifts to employees are subject to different tax and payroll regulations in all three countries. Companies should therefore treat gifts to staff separately from gifts to external business partners and observe the respective rules.

How should I handle gifts to governmental bodies or public organisations?

With particular caution. In all DACH countries there are strict rules for the public sector, and many organisations either prohibit gifts completely or limit them to very small amounts. If you are unsure, ask for written guidance or refrain from giving a gift.

23 September 2025 | 4 min

CBAM – The EU Carbon Border Adjustment Mechanism from 2026: What Companies Need to Know

The European Union is pursuing ambitious climate goals as part of its Green Deal. A key instrument in this effort is the Carbon Border Adjustment Mechanism (CBAM), also known as the CO₂ border levy. From January 1, 2026, the definitive phase will begin. At that point, financial and organizational obligations will apply that go far beyond the current reporting-only requirements.

This article explains the background of CBAM, which industries are affected, what challenges companies face, and how businesses can start preparing today.

  • CBAM complements the EU Emissions Trading System (EU ETS) and aims to prevent “carbon leakage.”
  • Applies to imports of certain carbon-intensive goods: cement, iron and steel, aluminum, fertilizers, electricity, and hydrogen (with more sectors under discussion).
  • From 2026, importers must purchase CBAM certificates reflecting the embedded emissions of imported products.
  • Since 2023, there has been a transition phase with mandatory emissions reporting only.
  • Supply chain transparency and data accuracy are critical to avoid excessive costs and ensure compliance.

Why the EU Introduced CBAM

The EU wants to avoid a scenario where strict climate policies lead to carbon leakage—the relocation of carbon-intensive production outside the EU to regions with lower environmental standards.

CBAM imposes a carbon price on certain goods produced outside the EU. This ensures a level playing field between EU producers subject to the EU ETS and foreign producers exporting to the EU.

Which Products Are Covered

Currently, CBAM applies to the following sectors:

  • Cement
  • Iron and steel
  • Aluminum
  • Fertilizers
  • Electricity
  • Hydrogen

The EU is considering extending CBAM to other product groups such as organic chemicals or plastics in the future.

Transition Phase and Full Implementation in 2026

  • Since October 2023: Importers must report quarterly emissions data of covered goods but no payments are required yet.
  • From January 1, 2026: The permanent CBAM regime begins. Importers will need to purchase CBAM certificates at prices linked to the EU ETS.
  • Gradual phase-out of free allowances: EU manufacturers will receive fewer free EU ETS allowances over time, aligning domestic and imported goods under the same carbon price rules.

Challenges for Businesses

  1. Data quality and supply chain transparency
    Many companies lack verified emissions data from non-EU suppliers. Without data, default values will apply—usually more expensive.
  2. Administrative burden
    CBAM requires a new system for reporting, certificate purchasing, and compliance checks. Companies must register with authorities, hold CBAM accounts, and undergo annual reviews.
  3. Cost risks
    Depending on the emissions intensity of imports, CBAM can have a significant financial impact on margins.
  4. Strategic sourcing
    Companies may need to reassess supply chains, potentially shifting from non-EU suppliers to EU-based ones to reduce exposure.

Opportunities Through CBAM

Despite the challenges, CBAM can also create value:

  • Fair competition: EU producers will no longer be disadvantaged against non-EU suppliers with weaker carbon rules.
  • Innovation driver: Non-EU producers exporting to the EU will have incentives to decarbonize production.
  • Reputation benefits: Companies that build transparent, low-carbon supply chains early will stand out as leaders.

Conclusion

CBAM is a milestone in EU climate policy. From 2026, it will become both a compliance and a cost issue for many companies. Businesses that start now—by gathering emissions data, engaging suppliers, and adjusting procurement strategies—will have a clear advantage.

CBAM should not only be seen as a regulatory burden but also as an opportunity: companies that embrace transparency and sustainability will strengthen both compliance and competitiveness.


CBAM FAQ

What does CBAM mean for importers?
From 2026, importers must declare the carbon emissions embedded in imported goods and purchase CBAM certificates accordingly.

Which countries are covered?
All countries exporting to the EU, except those with equivalent carbon pricing systems (e.g., Norway, Switzerland).

What data must be reported?
Direct emissions from production, production volumes, process details, and in some cases indirect emissions (e.g., electricity use).

How high will the costs be?
Costs depend on the EU ETS carbon price. If no verified data is provided, default emission factors will apply, often at higher levels.

Are there penalties for non-compliance?
Yes. Incorrect reporting or failure to surrender certificates can lead to significant fines and import restrictions.

How can companies prepare?

  • Engage suppliers early and require emissions data.
  • Build internal processes and IT systems for reporting and certificate management.
  • Adapt procurement and pricing strategies to reflect CBAM costs.

26 August 2025 | 3 min

MiCA: The New EU Crypto Regulation and Its Impact on GRC

The regulation of crypto-assets in the European Union has reached a historic milestone with the introduction of the Markets in Crypto-Assets Regulation (MiCA). Fully applicable since the end of 2024, MiCA establishes, for the first time, a unified legal framework for the crypto market across all EU member states. Its goal is to foster market stability, protect investors, and create a level playing field for all providers. For companies, this represents a fundamental shift in governance, risk, and compliance management.

  • MiCA has been fully applicable since December 30, 2024
  • First-ever unified EU-wide regulatory framework for crypto-assets and service providers
  • Mandatory licensing for crypto-asset service providers (CASPs)
  • Strict rules for stablecoins, market integrity, and consumer protection
  • Relevant for more than 10,000 businesses across Europe

Why MiCA Was Introduced

Before MiCA, Europe’s crypto market was shaped by fragmented national regulations. Each country had its own approach, leading to uncertainty for businesses and investors alike. Repeated market disruptions, fraud cases, and collapses of crypto exchanges further highlighted the need for a clear, harmonized legal framework.

The EU introduced MiCA to strengthen trust in the market and to position Europe as a competitive hub for crypto-asset innovation and investment.

Key Elements of MiCA

Licensing Requirements

All providers of crypto-asset services (CASPs) now require authorization. Licenses are granted by national supervisory authorities but are valid across the entire EU.

Stablecoin Regulation

Stablecoin issuers must hold sufficient reserves and comply with strict transparency obligations, minimizing the risks of instability and misuse.

Investor and Consumer Protection

Companies must publish detailed whitepapers outlining risks and functionalities of their products. Stronger requirements also apply to the safeguarding of client assets.

Market Integrity

MiCA introduces explicit rules against insider trading, market manipulation, and unfair practices to reinforce confidence in the market.

Implications for Governance, Risk, and Compliance

MiCA is more than a financial regulation—it reshapes companies’ governance and compliance frameworks.

  • Governance: Clear responsibilities and oversight structures are essential to ensure MiCA-compliant business processes.
  • Risk management: Companies must address new risks such as volatility, cyberattacks, and operational risks tied to crypto-assets.
  • Compliance: Extensive documentation, continuous monitoring, and close interaction with regulators are now mandatory.

For GRC teams, MiCA expands responsibilities and requires tighter integration with IT security and financial supervision.

Opportunities and Challenges

While MiCA imposes significant implementation costs, it also creates opportunities. With a clear framework in place, legitimate providers can differentiate themselves from unregulated competitors, building stronger trust among investors and customers. International providers entering the EU must also comply with the same standards, giving regulated entities a competitive advantage.

Conclusion

With MiCA, the EU is setting a global benchmark for crypto-asset regulation. For companies, it is not just a legal obligation but an opportunity to modernize governance, risk, and compliance structures while strengthening trust in their services. Businesses that act early and embrace MiCA will gain regulatory certainty and long-term market opportunities.


FAQ

What is MiCA?
MiCA stands for Markets in Crypto-Assets Regulation, the EU’s first comprehensive crypto regulatory framework.

When did MiCA take effect?
MiCA has been fully applicable since December 30, 2024.

Who is affected?
All providers of crypto-asset services within the EU, as well as international providers offering services in Europe.

What does MiCA mean for stablecoins?
Stablecoin issuers must meet strict requirements on transparency, reserves, and risk management.

What are the penalties for non-compliance?
Violations can result in license revocation, heavy fines, and bans from operating in the EU market.

Why is MiCA a major GRC topic?
Because it deeply affects governance structures, risk management processes, and compliance systems, forcing companies to professionalize their controls.