EU Regulation

The CRA 24-Hour Reporting Deadline: What Manufacturers Must Do
Cyber Resilience Act · · 4 min read

The CRA 24-Hour Reporting Deadline: What Manufacturers Must Do

The CRA 24-hour reporting deadline explained: when the clock starts, what an early warning must contain, and how manufacturers build a process that hits the deadline every time.

CRA Article 14 Reporting Requirements for EU Manufacturers
Cyber Resilience Act · · 4 min read

CRA Article 14 Reporting Requirements for EU Manufacturers

CRA Article 14 reporting requirements explained: what manufacturers must report to ENISA, the 24-hour and 72-hour deadlines, and how to build a compliant vulnerability and incident reporting process.

Cyber Resilience Act Compliance Checklist for Manufacturers
Cyber Resilience Act · · 5 min read

Cyber Resilience Act Compliance Checklist for Manufacturers

A practical Cyber Resilience Act compliance checklist for manufacturers: Annex I requirements, conformity assessment, technical documentation, and timelines.

EUVD vs NVD vs CVE: What EU Manufacturers Need to Know
Cyber Resilience Act · · 4 min read

EUVD vs NVD vs CVE: What EU Manufacturers Need to Know

EUVD vs NVD vs CVE explained for EU manufacturers: how the three vulnerability databases differ, how they connect to CRA Article 14 reporting, and which identifiers to cite.

What Is the ENISA Single Reporting Platform? A Manufacturer Guide
Cyber Resilience Act · · 4 min read

What Is the ENISA Single Reporting Platform? A Manufacturer Guide

What is the ENISA Single Reporting Platform? How EU manufacturers submit CRA Article 14 vulnerability and incident reports, what the portal expects, and how to prepare submissions.

NIS2 Compliance Is Now an Underwriting Requirement — Every Broker's Duty of Care
NIS 2 · · 4 min read

NIS2 Compliance Is Now an Underwriting Requirement — Every Broker's Duty of Care

The NIS2 transposition deadline has passed. With fewer than 10% of critical entities fully compliant, carriers are starting to exclude non-compliant organizations from coverage. For insurance brokers, failing to verify client NIS2 status is now a professional liability risk. Here's what you need to know.

The NIS2 + AI Coverage Gap: When Your Cyber Policy Won't Cover the Incident NIS2 Requires You to Report
NIS 2 · · 9 min read

The NIS2 + AI Coverage Gap: When Your Cyber Policy Won't Cover the Incident NIS2 Requires You to Report

NIS2 mandates AI incident reporting for hundreds of thousands of EU entities. But most cyber insurance policies contain silent AI exclusions, sublimits, or ambiguity that leave insureds paying for AI incident response out of pocket — even though NIS2 required them to report the incident in the first place.

DORA ICT Risk Management Framework: Complete Practitioner Guide for Financial Institutions and Their Insurers in 2026
DORA · · 16 min read

DORA ICT Risk Management Framework: Complete Practitioner Guide for Financial Institutions and Their Insurers in 2026

Comprehensive guide to the Digital Operational Resilience Act (DORA) ICT risk management framework. Covers all 5 pillars, compliance requirements, underwriting implications, and the intersection with NIS2 for EU financial institutions.

How to Prepare for a NIS2 Audit: Documentation, Evidence, and Compliance Verification Guide (2026)
NIS 2 · · 12 min read

How to Prepare for a NIS2 Audit: Documentation, Evidence, and Compliance Verification Guide (2026)

Complete guide to NIS2 audit preparation. Covers documentation requirements by Article, evidence collection, common failures, management liability, and a 30-day pre-audit checklist for in-scope EU entities.

NIS2 Ireland Preparation Guide: National Cyber Security Bill, NCSC Ireland and CyFun Framework for 2026
NIS 2 · · 8 min read

NIS2 Ireland Preparation Guide: National Cyber Security Bill, NCSC Ireland and CyFun Framework for 2026

Complete guide to NIS2 preparation in Ireland. Covers the pending National Cyber Security Bill, NCSC Ireland authority, CyFun compliance framework adopted from Belgium, 15 Risk Management Measures, entity classification expectations, and what organizations should do now despite legislation not yet enacted.

Cyber Resilience Act vs NIS2 vs DORA: Which Regulation Applies to My Insured?
Cyber Resilience Act · · 12 min read

Cyber Resilience Act vs NIS2 vs DORA: Which Regulation Applies to My Insured?

A practical comparison of the three major EU cybersecurity regulations — CRA, NIS2, and DORA — explaining scope, timelines, requirements, and what cyber insurance underwriters need to ask clients in 2026.

DORA ICT Risk Management Framework: What Cyber Insurance Underwriters Must Know in 2026
DORA · · 23 min read

DORA ICT Risk Management Framework: What Cyber Insurance Underwriters Must Know in 2026

Complete practitioner guide to the DORA ICT risk management framework for cyber insurance underwriting. Covers the 5 pillars, how they affect coverage decisions, underwriting questions for financial sector clients, and compliance deadlines.

NIS2 Compliance Cost: What European Companies Actually Spend in 2026
NIS 2 · · 9 min read

NIS2 Compliance Cost: What European Companies Actually Spend in 2026

Real NIS2 compliance costs broken down by company size and sector. Essential entities spend €150K-€2M+, important entities €30K-€500K. Includes cost framework, hidden expenses, ROI calculation, and free tools to estimate your budget.

NIS2 Compliance for IT Managers: The Action Plan That Actually Works in 2026
NIS 2 · · 9 min read

NIS2 Compliance for IT Managers: The Action Plan That Actually Works in 2026

Step-by-step NIS2 compliance action plan for IT managers and CISOs. Practical implementation guide covering risk management, incident reporting, security governance, supply chain security, and business continuity — with free tools and templates.

NIS2 Underwriting Questions: What Every Cyber Insurance Broker Should Ask
NIS 2 · · 16 min read

NIS2 Underwriting Questions: What Every Cyber Insurance Broker Should Ask

Practical Line 1, Line 2, and Line 3 underwriting questions for NIS2-exposed clients. Essential vs important entities. Coverage gaps brokers should flag.

NIS2 Compliance Requirements: 10 Mandatory Security Controls Before the 2026 Deadline
NIS2 Compliance Requirements · · 13 min read

NIS2 Compliance Requirements: 10 Mandatory Security Controls Before the 2026 Deadline

Master NIS2 compliance with our guide to the 10 mandatory security requirements. Learn what to implement, when deadlines hit, and how to avoid penalties up to €10 million or 2% of global turnover.

The NIS2 Audit Crunch: What Underwriters Need to Know Before June 30, 2026
NIS 2 · · 10 min read

The NIS2 Audit Crunch: What Underwriters Need to Know Before June 30, 2026

With the June 30, 2026 NIS2 compliance audit deadline approaching, cyber underwriters face a narrow window to reassess risk profiles across their entire European portfolio. Here is what the audit requirement means for how you evaluate, price, and write cyber coverage.