EU regulation

The rules Trusq covers

Five EU frameworks in depth, each with its obligations, deadlines and primary source. Every conclusion links back to the official text on EUR-Lex — no source, no claim. The deadline calendar reaches wider: it also tracks dated obligations under CBAM, customs and ICS2, eFTI and maritime reporting.

EU AI Act

The European regulation for artificial intelligence. Obligations differ per risk category; below are the categories with what they mean and when they apply, each traceable to the legal text.

Regulation (EU) 2024/1689

NIS2 Directive / Cybersecurity Act

The NIS2 Directive (Directive (EU) 2022/2555), implemented in the Netherlands as the Cybersecurity Act, obliges organisations in designated sectors to maintain a duty of care, an incident reporting duty and management…

Directive (EU) 2022/2555

DORA (financial sector)

DORA (Regulation (EU) 2022/2554) requires financial entities and their critical ICT service providers to manage ICT risk, report incidents and oversee third-party providers; applicable since 17 January 2025.

Regulation (EU) 2022/2554

Data Act (EU Data Regulation)

The Data Act (Regulation (EU) 2023/2854) governs access to and sharing of data from connected products and related services, and has applied since 12 September 2025.

Regulation (EU) 2023/2854

Cyber Resilience Act

EU-wide cybersecurity requirements for products with digital elements (Regulation (EU) 2024/2847), fully applicable from 11 December 2027.

Regulation (EU) 2024/2847

The AI Act in full

Beyond the summary above, the enacting terms of Regulation (EU) 2024/1689 as adopted are published here article by article: all 113 articles, the annexes (including Annex III) and the recitals — each on a stable URL you can cite, each linked to EUR-Lex. It is not a consolidated text: provisions changed by a later regulation carry a notice naming the amending act. Dated obligations are on the AI Act deadline register.

NIS2 in the Netherlands Nederlands

The Dutch Cybersecurity Act (Cyberbeveiligingswet) applies from 15 August 2026 with no transition period, widening scope to roughly 8,000 organisations. Because it is Dutch law with Dutch supervisors and Dutch primary sources, that page is written in Dutch: Cyberbeveiligingswet — wat moet er op 15 augustus 2026 geregeld zijn?

Check one of your own systems

The transparency duties in Article 50 have applied since 2 August 2026. The free Article 50 check takes about two minutes, asks no contact details before showing the full result, and quotes the official text for every answer.
← Back to Trusq

Independent expertise

Need a specialist for this work?

Describe the framework, location and assignment parameters. Trusq staff reviews the request and performs selection manually; profiles are not public and no automated ranking is used.

Request an expert