AI ACT
The AI Act does not start all at once. For an industrial manufacturer the real fault line is not a date but where the AI sits: in your processes (Annex III high-risk, 2 August 2026) or in your product (Art. 6(1), Annex I, 2 August 2027). The operational timeline, with references to the articles.
Updated 26 August 2026·6 min read
CRANIS2
Three European cybersecurity acts, three different levels: the CRA regulates products, NIS2 organisations, DORA the financial sector. What each text says about object, legal form, dates of application and addressees, and how they fit together. A guide from the official sources, with references to the articles.
Updated 19 August 2026·7 min read
NIS2
The NIS2 directive and its Italian transposition (Legislative Decree 138/2024) in a reference guide: what changes compared with NIS1, who the essential and important entities are, the compliance calendar set by ACN, and the requirements on governance, risk management and incident notification. From the official sources, with references to the articles.
Updated 19 August 2026·9 min read
AIAI ACTISO 42001
IEEE, ISO/IEC 42001, EN 18286 and the SC 42 family of standards are not on the same plane. Confuse them and you certify the wrong thing. The three-level map, and how each standard hooks into the AI Act articles.
Updated 12 August 2026·9 min read
CRA
The Cyber Resilience Act doesn't start all at once. There are three dates that matter, 11 September 2026, 11 December 2027, and the end of the RED's cyber requirements, and for each a minimum state you must be able to demonstrate. The operational timeline, with references to the articles.
Updated 12 August 2026·6 min read
CRA
The Cyber Resilience Act is not a box to tick before CE marking: it's an obligation that follows the product for its whole life. What a product with digital elements is, the three obligations that didn't exist before, and how to turn their requirements into development decisions. With precise article references.
Updated 12 August 2026·7 min read
CRA
The CRA↔ISO 9001 map: which quality-system mechanisms you extend to the Cyber Resilience Act almost frictionlessly, which three processes you have to build from scratch, and where the 9001 helps more than it seems. With references to the CRA articles and the ISO 9001 clauses.
Updated 12 August 2026·6 min read
CRA
From 11 September 2026, actively exploited vulnerabilities and severe incidents are reported on a single ENISA platform. What the SRP is, who registers, what goes into each notification, who receives it and within how many hours. A guide from the official sources, with references to the CRA articles and to ENISA guidance.
Updated 12 August 2026·8 min read
No guides with this tag yet.