NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →

LEARN

Deep-dive guides on EU compliance frameworks and regulatory requirements.

eIDAS Compliance Software: An eIDAS 2.0 Buyer's Guide
Learn

eIDAS Compliance Software: An eIDAS 2.0 Buyer's Guide

eIDAS compliance software compared: the three product categories buyers confuse, what an eIDAS 2.0 governance layer must cover, and how a crosswalk cuts duplicate work before 24 December 2027.

What Is NIS2 and Who Must Comply in 2026?
Learn

What Is NIS2 and Who Must Comply in 2026?

What is NIS2 and who must comply? The 2026 scope guide: sectors, size thresholds, essential vs important, obligations and penalties. Reviewed July 2026.

What Is HIPAA Compliance? Covered Entities and BAAs
Learn

What Is HIPAA Compliance? Covered Entities and BAAs

HIPAA compliance explained: covered entities, business associates, BAAs, the Privacy, Security and Breach Notification Rules, penalties. Reviewed July 2026.

PCI DSS: Who Must Comply and Which SAQ Applies
Learn

PCI DSS: Who Must Comply and Which SAQ Applies

PCI DSS applies to any business that stores, processes or transmits cardholder data. Learn who must comply and which SAQ fits your setup. Reviewed July 2026.

What Is SOC 2? Type 1 vs Type 2, Explained
Learn

What Is SOC 2? Type 1 vs Type 2, Explained

SOC 2 explained: what the AICPA attestation report is, the five Trust Services Criteria, Type 1 vs Type 2, and which SaaS vendors need it. Reviewed July 2026.

ISO 27001 Annex A: The 93 Controls Explained (2022)
Learn

ISO 27001 Annex A: The 93 Controls Explained (2022)

ISO 27001 Annex A controls explained: the 93 controls, four themes, the Statement of Applicability, 2022 changes, and who must comply. Reviewed July 2026.

eIDAS 2.0 Scope: Who Must Accept the EUDI Wallet?
Learn

eIDAS 2.0 Scope: Who Must Accept the EUDI Wallet?

Use this role-based decision tree to see when eIDAS 2.0 applies, when EUDI Wallet acceptance is mandatory, and which SME exemptions matter.

The eIDAS 2.0 Deadline: What Happens by 24 December 2027
Learn

The eIDAS 2.0 Deadline: What Happens by 24 December 2027

eIDAS 2.0 (Regulation (EU) 2024/1183) entered into force on 20 May 2024. By 24 December 2027, private relying parties legally or contractually required to use strong user authentication must accept the EU Digital Identity Wallet. Here is who it binds and the full timeline.

How to Become Compliant: A Step-by-Step Guide (2026)
Learn

How to Become Compliant: A Step-by-Step Guide (2026)

A practical, framework-agnostic guide to becoming compliant: work out which regulations apply to you, run a gap analysis, remediate, collect evidence once, pass the audit, and stay compliant without drowning in spreadsheets.

Who Must Comply With the Cyber Resilience Act?
Learn

Who Must Comply With the Cyber Resilience Act?

CRA scope follows the product, not the sector. See the products-with-digital-elements test, the three economic operators, Annex III and IV classification, the 11 Sep 2026 and 11 Dec 2027 deadlines, the Article 14 reporting clock, and the penalties.

The Cyber Resilience Act Deadlines: 2026 and 2027
Learn

The Cyber Resilience Act Deadlines: 2026 and 2027

The CRA entered into force on 10 December 2024. Reporting obligations begin on 11 September 2026 and the regulation applies in full on 11 December 2027. Here is the full timeline.

Solvency II Software: A Pillar 2 Buyer's Guide
Learn

Solvency II Software: A Pillar 2 Buyer's Guide

Solvency II software compared: the three tool categories, what a Pillar 2 governance platform needs, and how a crosswalk cuts duplicate work.

EU AI Act vs DORA: Comply With Both, One Programme
Learn

EU AI Act vs DORA: Comply With Both, One Programme

EU AI Act and DORA overlap in five zones. Run both from one compliance programme instead of two, and see exactly where the requirements meet.

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027
Learn

EU AI Act High-Risk Deadline: Why 2 August 2026 Moved to 2027

The 2 August 2026 EU AI Act high-risk deadline was postponed by the Digital Omnibus (adopted 29 June 2026) to 2 December 2027 for standalone systems and 2 August 2028 for product-embedded ones. Here is what actually binds in August 2026 and what high-risk providers must still build.

EU AI Act Conformity Assessment for High-Risk AI in Financial Services
Learn

EU AI Act Conformity Assessment for High-Risk AI in Financial Services

How the Article 43 conformity assessment works for high-risk financial AI - credit scoring and insurance pricing - and why the Digital Omnibus moved the deadline from August 2026 to 2 December 2027.

DORA vs NIS2: Key Differences and Who's Covered
Learn

DORA vs NIS2: Key Differences and Who's Covered

DORA vs NIS2: two EU cyber regulations with confusingly close names and very different obligations. See which one applies to your organisation, and why.

DORA TLPT: Threat-Led Penetration Testing in 2026
Learn

DORA TLPT: Threat-Led Penetration Testing in 2026

Threat-led penetration testing under DORA Articles 26 and 27: who competent authorities designate, the TIBER-EU based phases in RTS 2025/1190, and how to plan the engagement.

Key Risk Indicators (KRIs): 14 to Track in 2026
Learn

Key Risk Indicators (KRIs): 14 to Track in 2026

Key Risk Indicators explained for CISOs and CROs, with thresholds, formulas and a 14-KRI starter pack mapped to ISO 27001, NIS2, DORA and NIST CSF.

DORA Key Risk Indicators: Article-by-Article Guide
Learn

DORA Key Risk Indicators: Article-by-Article Guide

Fourteen DORA key risk indicators, each mapped to the article of Regulation (EU) 2022/2554 it helps evidence, with every article number checked against the text.

ISO 42001 vs EU AI Act: Do You Need Both?
Learn

ISO 42001 vs EU AI Act: Do You Need Both?

One is voluntary certification, one is binding law. See exactly where they overlap so you build AI governance once, not twice, and what each requires.

VARA CISO Appointment and Staff Competency Rules
Learn

VARA CISO Appointment and Staff Competency Rules

The CISO rule sits in VARA's Technology and Information Rulebook, not the Company Rulebook. What Part I Sections I and J actually require, and what they do not.

VARA Cybersecurity Policy: The 19 Mandatory Criteria
Learn

VARA Cybersecurity Policy: The 19 Mandatory Criteria

VARA's Technology and Information Rulebook lists 19 minimum cybersecurity policy criteria, (a) to (s), not 18. Here is each one in the rulebook's own words, with the two that generic ISO 27001 templates always miss.

VARA Penetration Testing and Smart Contract Audits
Learn

VARA Penetration Testing and Smart Contract Audits

Rule I.E.1 has two triggers, not one: at least annually AND before any new system, application or product ships. What VARA binds, and what is only Guidance.

VARA Compliance Guide for Dubai VASPs 2026
Learn

VARA Compliance Guide for Dubai VASPs 2026

What a Dubai VASP licence actually requires: the four compulsory rulebooks, the 19 cybersecurity policy criteria, the 72 hour and 24 hour clocks, and the capital floors, with the rule reference for each.

VARA Key and Wallet Management: What the Rules Say
Learn

VARA Key and Wallet Management: What the Rules Say

VARA key and wallet duties come in three tiers: four binding Rules in Part I Section D, Schedule 1 Guidance, and custody-only rules. What each one requires.

VARA Incident Reporting: The 72-Hour Clock
Learn

VARA Incident Reporting: The 72-Hour Clock

VARA's 72-hour notification runs from detection, under Rule I.K.1 of the Technology and Information Rulebook. Here is what triggers it, what the report must contain, and the 24-hour personal data clock that runs alongside it.

VARA Data Protection: UAE PDPL Rules for VASPs
Learn

VARA Data Protection: UAE PDPL Rules for VASPs

VARA's Technology and Information Rulebook binds every VASP to the UAE PDPL, a mandatory DPO, and a notify-VARA step within 24 hours of reporting an incident. Here is what the rulebook actually requires.

DORA Supervisory Assessments: 2026 Guide
Learn

DORA Supervisory Assessments: 2026 Guide

DORA has applied since 17 January 2025 and is supervised by national competent authorities and the ESAs. How DORA supervision is structured, what a supervisor can request, and the evidence to have ready.

DORA ICT Risk Management Framework: Article-by-Article Guide
Learn

DORA ICT Risk Management Framework: Article-by-Article Guide

What DORA Chapter II and RTS (EU) 2024/1774 actually require an ICT risk management framework to contain, chapter by chapter, with every article citation checked against the official text.

DORA ICT Third-Party Risk: Build a Compliant Vendor Register
Learn

DORA ICT Third-Party Risk: Build a Compliant Vendor Register

DORA Chapter V, Section I, in full: the register of information, the nine contract clauses every ICT contract needs plus six more for critical functions, the subcontracting RTS, and the exit tests.

DORA Major Incident Classification: 7 Criteria
Learn

DORA Major Incident Classification: 7 Criteria

A payment system fails on a Friday afternoon. Whether you owe your regulator a report in 4 hours turns on a precise test in Delegated Regulation (EU) 2024/1772: the criticality gateway plus either a malicious intrusion or two materiality thresholds. Here is the exact logic, every number, and the 4h/72h/1-month clock.

DORA Operational Resilience Testing: Article 24
Learn

DORA Operational Resilience Testing: Article 24

What DORA Article 24 actually requires of a resilience testing programme, where the board approval obligation really comes from, and which widely quoted numbers are not in the regulation at all.

DORA 'Significant': The Critical ICT Provider Test
Learn

DORA 'Significant': The Critical ICT Provider Test

Will the ESAs designate your firm a critical ICT third-party provider? See the thresholds behind DORA's 'significant' test and where it bites.

EU AI Act for Healthcare: Which AI Must Comply
Learn

EU AI Act for Healthcare: Which AI Must Comply

Most medical and diagnostic AI is high-risk under the EU AI Act - as a regulated medical device (Annex I) or a standalone Annex III use case. The Digital Omnibus moved the deadlines to 2 August 2028 and 2 December 2027. Here is which systems fall where, and what each route demands.

EU AI Act: Who's in Scope and the 2025-28 Deadlines
Learn

EU AI Act: Who's in Scope and the 2025-28 Deadlines

Not sure the EU AI Act applies to you? Map your systems to the risk tiers and the phased 2025-2028 deadlines - including the Digital Omnibus postponement of high-risk to 2 December 2027 - to see if you are in scope.

Does the EU AI Act Apply Outside the EU?
Learn

Does the EU AI Act Apply Outside the EU?

Selling AI into the EU from outside it usually puts you in scope. See which non-EU companies the Act catches, the 'output used in the EU' trigger, the authorised representative rule, and the deadlines after the 2026 Digital Omnibus moved high-risk to December 2027.

Why Your DORA Register of Information Gets Rejected
Learn

Why Your DORA Register of Information Gets Rejected

The ESAs publish which register of information errors actually reject a submission and which do not. The seven rejecting rule codes, what causes them, and how to clear the cascade.

DORA Register of Information: 15 Official Templates Explained
Learn

DORA Register of Information: 15 Official Templates Explained

The DORA Register of Information is built from 15 official templates set by Commission Implementing Regulation (EU) 2024/2956. This guide explains each template, how they connect, and how to file one clean submission.

DORA Gap Assessment: Score Your Readiness
Learn

DORA Gap Assessment: Score Your Readiness

Score your DORA readiness across seven domains, each anchored to the article it comes from, then weight the gaps so you know what to fix first.