/

Regulations

By regulation

Regulations & frameworks.

New EU regulation is the most common reason organisations come to us. Here’s where the pressure is right now.

NIS2

The EU's updated cybersecurity directive expanded scope across 18 sectors, strict incident reporting, supply-chain security, and personal accountability for management.

EU AI Act

The world's first comprehensive AI regulation — a risk-based framework with obligations that scale from transparency to strict conformity, for organisations that build or use AI.

Cyber Resilience Act (CRA)

EU security requirements for products with digital elements — secure-by-design, vulnerability handling, and lifecycle obligations for anyone making or selling connected hardware and software.

DORA

The EU's digital operational resilience regulation for the financial sector — covering ICT risk management, incident reporting, resilience testing, and third-party oversight.

Not sure where you stand?

Start with a free scoping check to see what applies to you. From there, a focused assessment — like a NIS2 Gap Analysis or AI Readiness Scan — gives you the full picture, and can lead straight into a managed partnership.

Not sure where you stand?

Start with a free scoping check to see what applies to you. From there, a focused assessment — like a NIS2 Gap Analysis or AI Readiness Scan — gives you the full picture, and can lead straight into a managed partnership.

Looking for expertise in a specific area?

© 2026 CTRL Disrupt Consulting B.V. · KvK 87198983 · All rights reserved.

© 2026 CTRL Disrupt Consulting B.V. · KvK 87198983 · All rights reserved.

© 2026 CTRL Disrupt Consulting B.V. · KvK 87198983 · All rights reserved.