We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.
Powered by
Customise Consent Preferences
We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.
The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ...
Always Active
Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
Cookie
__cf_bm
Duration
1 hour
Description
This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
Cookie
_cfuvid
Duration
session
Description
Cloudflare sets this cookie to track users across sessions to optimize user experience by maintaining session consistency and providing personalized services
Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
No cookies to display.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
Cookie
session-id
Duration
1 hour
Description
Amazon Pay uses this cookie to maintain a "session" that spans multiple days and beyond reboots. The session information includes the identity of the user, recently visited links and the duration of inactivity.
Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.
No cookies to display.
Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.
Seven EU regulations are simultaneously active and enforceable in April 2026, each requiring operational responses from German SMEs. Germany's NIS2 implementation law took effect in December 2025 with no transition period, covering an estimated 29,500 organizations1. The AI Act's AI literacy obligation has been live since February 2025, and from December 2026, manufacturers of software and AI products face liability under the revised Product Liability Directive223. An integrated governance framework can reduce compliance effort by up to 60%, because six of the seven regulations share the same core requirements12.
EU AI regulation for mid-sized companies 2026: status, deadlines, and penalties at a glance
Regulation
Status April 2026
Next Deadline
Max Penalty
EU AI Act
Prohibitions + AI Literacy + GPAI in force
Aug 2026: Transparency obligations, Nov 2026: Watermarking (Omnibus)
€35M / 7% revenue
NIS2 (Germany)
Fully in force since 06.12.2025
Registration deadline passed (Mar 2026)
€10M / 2% revenue
DORA
Fully in force since 17.01.2025
31.12.2026: BAIT/VAIT superseded
Up to 2% revenue (daily 1%)
CRA
In force since 10.12.2024
Sep 2026: 24h vulnerability reporting
€15M / 2.5% revenue
Product Liability (new)
Directive in force since 08.12.2024, Bundestag 1st reading 04.03.2026
Digital Omnibus status (8 April 2026): Council (13 March) and Parliament (26 March, 569 to 45 votes) have adopted their negotiating positions3. Both call for the high-risk deadline to shift to December 2027. Trilogue has been running since 26 March. Target agreement: 28 April 2026. Current deadlines remain legally binding until formal adoption.
Which regulations apply to your company?
Every CEO needs to know which of these regulations apply to their specific company. Three factors determine this: employee count, sector, and product portfolio.
Every company deploying AI systems must ensure AI literacy of its staff since February 2025 (Art. 4 AI Act)2. Prohibited practices apply regardless of company size. Any AI application processing personal data triggers GDPR obligations. The EDPB clarified in its Opinion 28/2024 that legitimate interest can serve as a legal basis for AI training but requires a three-part balancing test4.
Companies in NIS2 sectors (energy, transport, healthcare, digital infrastructure, manufacturing, food, chemicals, and 12 others) with more than 50 employees or €10 million revenue fall under Germany's NIS2 implementation law1. The BSI registration portal has been live since January 2026; the deadline passed in March 2026. Managing directors bear personal liability under §38 BSIG with no option for contractual limitation6.
Manufacturers of products with digital elements (machinery, IoT devices, industrial software) are subject to the Cyber Resilience Act. From September 2026, actively exploited vulnerabilities must be reported within 24 hours7. Full conformity with CE marking applies from December 2027. For connected products, the Data Act adds an "Access by Design" obligation from September 20268. In the UK, the Product Security and Telecommunications Infrastructure Act has been in force since April 2024 with similar objectives, making CRA compliance a competitive advantage beyond EU borders.
The revised Product Liability Directive adds another layer: software and AI systems are now classified as "products" for liability purposes, with a transposition deadline of 9 December 202623. The German Bundestag held its first reading of the implementing legislation on 4 March 202623. Non-compliance with CRA or AI Act requirements can trigger a rebuttable presumption of product defectiveness in civil proceedings. Manufacturers who retain control over their product after placing it on the market (through updates, digital services, or connected components) can be held liable for defects that arise afterward23.
Financial sector firms and their IT suppliers fall under DORA, which has been fully applicable since January 2025. DORA is lex specialis to NIS2 and imposes stricter incident reporting: four hours after classification as severe10. The BaFin is conducting systematic audits throughout 2026. SMEs are affected if they serve as critical ICT third-party providers to financial institutions.
Even companies below the formal thresholds face indirect pressure. NIS2-regulated customers increasingly require contractual cybersecurity assurances from their suppliers11.
Where do the requirements overlap?
Five requirement areas appear across virtually every regulation. Building them once in an integrated framework saves an estimated 60% of compliance effort compared to siloed projects12.
Requirement matrix: where AI Act, NIS2, DORA, GDPR, and CRA overlap for mid-sized companies
Requirement
AI Act
NIS2
DORA
GDPR
CRA
Risk Management
AI risk classification
Cyber risk analysis
ICT risk framework
DPIA
Product security assessment
Incident Reporting
Serious incidents
24h / 72h / 1 month
4h / 72h / 1 month
72h (96h proposed)
24h to ENISA
Supply Chain
AI supplier assessment
Art. 21: Supply chain security
Art. 28: ICT third-party
Processor management
Component security
Governance
Human oversight
Personal director liability
Personal director liability
DPO
Declaration of conformity
Documentation
Technical documentation
Risk analyses
Information register
Processing records
SBOM + CE
AI Act
Risk Management
AI risk classification
Incident Reporting
Serious incidents
Supply Chain
AI supplier assessment
Governance
Human oversight
Documentation
Technical documentation
NIS2
Risk Management
Cyber risk analysis
Incident Reporting
24h / 72h / 1 month
Supply Chain
Art. 21: Supply chain security
Governance
Personal director liability
Documentation
Risk analyses
DORA
Risk Management
ICT risk framework
Incident Reporting
4h / 72h / 1 month
Supply Chain
Art. 28: ICT third-party
Governance
Personal director liability
Documentation
Information register
GDPR
Risk Management
DPIA
Incident Reporting
72h (96h proposed)
Supply Chain
Processor management
Governance
DPO
Documentation
Processing records
CRA
Risk Management
Product security assessment
Incident Reporting
24h to ENISA
Supply Chain
Component security
Governance
Declaration of conformity
Documentation
SBOM + CE
A single risk register with regulation-specific categories serves all frameworks. One incident response process with differentiated reporting timelines replaces five parallel notification chains. A vendor assessment framework with regulation-specific add-on modules eliminates redundant supplier audits.
The Digital Omnibus proposes a unified EU reporting portal that automatically routes notifications to the relevant authorities3. Until that portal is operational, companies must build their own multi-regime notification logic. The revised Product Liability Directive adds further motivation: non-compliance with CRA or AI Act requirements can serve as evidence of product defectiveness in civil proceedings23.
Which certification delivers the most leverage?
ISO 27001:2022 covers 60 to 85% of NIS2 requirements and approximately 85% of DORA requirements13. The remaining gaps are primarily sector-specific reporting timelines and technical penetration testing mandates. For a 100-person SME, certification typically costs between €50,000 and €100,000 (estimate) and takes six to twelve months.
For AI governance specifically, ISO 42001:2023 supports EU AI Act compliance for high-risk systems, though it does not guarantee conformity since legal requirements exceed any voluntary standard14. The forthcoming harmonised standards from CEN-CENELEC JTC 21 are expected to reference ISO 42001 concepts.
Revised in October 2025, ISO 27701 is now a standalone management system, removing the previous ISO 27001 prerequisite16. It maps GDPR requirements directly and includes new annexes on AI-related data processing.
For the automotive supply chain, TISAX assessments cover NIS2 Art. 20 and Art. 21 requirements completely when all affected locations are within scope17. Cloud service providers benefit from the BSI C5 attestation with 121 controls18. In contrast, US-based frameworks like SOC 2 Type II provide reasonable overlap with ISO 27001 but do not map directly to NIS2 or AI Act requirements. For EU compliance, ISO-based certification is the more efficient path.
Certification priority for mid-sized companies: ISO standards by coverage and timeline
Priority
Certification
Coverage
Timeline
1
ISO 27001:2022
NIS2 (60 to 85%), DORA (85%), AI Act (security), CRA (org)
Start now, 6 to 12 months
2
ISO 42001
AI Act (high-risk), AI governance
From Q3 2026
3
ISO 27701:2025
GDPR, AI Act (privacy)
From Q1 2027
4
Sector-specific (TISAX/C5/B3S)
Sector obligations + NIS2
As needed
Certification
1
ISO 27001:2022
2
ISO 42001
3
ISO 27701:2025
4
Sector-specific (TISAX/C5/B3S)
Coverage
1
NIS2 (60 to 85%), DORA (85%), AI Act (security), CRA (org)
2
AI Act (high-risk), AI governance
3
GDPR, AI Act (privacy)
4
Sector obligations + NIS2
Timeline
1
Start now, 6 to 12 months
2
From Q3 2026
3
From Q1 2027
4
As needed
Will the Omnibus package shift the deadlines?
Two Omnibus packages affect SMEs. The Sustainability Omnibus has been adopted: Directive (EU) 2026/470 entered into force on 16 March 2026, raising CSRD reporting thresholds to 1,000 employees and €450 million revenue19. For the typical Mittelstand company, sustainability reporting obligations are effectively gone.
The Digital Omnibus has been in trilogue since 26 March 2026. Council and Parliament broadly agree on core points: the high-risk deadline shifts to December 2027 (Annex III) and August 2028 (Annex I)3. Both institutions have rolled back several of the Commission's simplification proposals. Parliament wants to keep the AI literacy obligation mandatory, with a lowered standard3. A new prohibition on AI systems generating non-consensual sexual deepfakes has been added by both co-legislators. For watermarking of AI-generated content (Art. 50), Parliament is pushing for 2 November 2026 as the deadline3. The DIHK position paper calls for unified definitions across all digital legislation and tiered certification options21. Agreement is targeted for 28 April 2026. Until the Omnibus is formally adopted, all existing deadlines remain legally binding. Plan for August 2026, hope for December 2027.
What must CEOs do this week?
Block 90 minutes on Monday and open the BSI's applicability check at bsi.bund.de. The 15 questions determine whether NIS2 applies to your company. Write the result on a single page: affected sector yes/no, thresholds met yes/no, BSI registration completed yes/no. If you missed the March 2026 registration deadline, complete it in the same session. The BSI portal has been online since January 20261. In the same sitting, assess whether the CRA or Data Act applies to your products.
Commission an ISO 27001 readiness assessment from an accredited provider, even if NIS2 does not formally apply to you. The assessment benchmarks your current posture against the standard and produces a gap analysis with a prioritised action list. Typical timeline to certification: six to twelve months. Investment for lower Mittelstand: from €50,000 (estimate). The readiness assessment itself costs between €3,000 and €8,000 (estimate) and takes two to four weeks.
Map every AI system in use across your company, from the customer service chatbot to AI-assisted applicant screening. Classify each according to the AI Act risk tiers: prohibited, high-risk, limited risk, minimal risk. Most office AI tools (Copilot, ChatGPT in a browser) fall under minimal risk. It gets critical with AI in HR processes, credit decisions, or biometric identification. Verify that your staff meets the Art. 4 AI literacy requirement2. Bitkom provides free self-assessment guides22. If you operate high-risk systems, begin documentation now. The architectural foundation for an audit-ready AI system is laid out in AI compliance architecture: three decisions. Waiting for the Omnibus to be formally adopted is a bet, not a strategy.
Our Take
Almost every managing director tells us the same thing: "We're handling NIS2 with the IT manager and sorting out the AI Act separately." It sounds reasonable. It is the most expensive approach. With one client of around 200 employees, we built a single risk register with five regulation-specific modules. The compliance workload roughly halved (estimate based on two comparable engagements).
Something that stuck with me since: across three other engagements, ISO 27001 certification ended up costing less than the legal fees that a penalty negotiation would have required.
Three deadlines converge in September 2026: CRA vulnerability reporting, Data Act Access by Design, AI Act transparency obligations. In December, the Product Liability Directive adds another. Companies without a functioning multi-regime incident response process by summer 2026 will spend the autumn in crisis mode.
To check which regulations apply specifically to your company and where you stand today, see the AI regulation check for SMEs.