Guide

NIS2, Cyber Resilience Act and EU AI Act: an overview for companies

NIS2, the Cyber Resilience Act and the EU AI Act explained: who is affected, which 2026 deadlines apply and how one ISMS covers shared requirements.

Summary

NIS2 sets cybersecurity obligations for organizations in critical and important sectors (in Germany in force since December 2025). The Cyber Resilience Act sets security requirements for products with digital elements (reporting since September 2026, most obligations from December 2027). The EU AI Act regulates AI by risk (high-risk obligations deferred to 2027/2028). An ISMS provides the common foundation: risk management, controls, incident handling and evidence.

European cybersecurity and AI regulation has grown quickly. Three regulations matter most for many companies. This overview explains them in plain language. It is not legal advice — whether a regulation applies to you should be confirmed by legal counsel.

NIS2 — cybersecurity for important and essential entities

What it is: an EU directive that obliges organizations in many sectors (energy, transport, health, digital infrastructure, manufacturing of certain products, digital providers and more) to manage cybersecurity risks.

In Germany: implemented by the NIS2 Implementation Act, in force since December 2025. Affected companies must register with the BSI.

Core obligations:

  • risk management measures (policies, incident handling, business continuity, supply chain security, secure development, access control, cryptography, training and more),
  • reporting of significant incidents (24 h / 72 h / one month),
  • accountability and training of management bodies.

Cyber Resilience Act — security of products with digital elements

What it is: an EU regulation setting cybersecurity requirements for hardware and software products placed on the EU market, across their lifecycle.

Timeline:

  • since 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe incidents,
  • from December 2027: most other requirements apply (security by design, vulnerability handling, documentation, conformity assessment).

Typical topics: secure development, software bills of materials (SBOM), vulnerability handling, security updates, technical documentation.

EU AI Act — rules for artificial intelligence

What it is: an EU regulation that regulates AI by risk. Prohibited practices and AI literacy obligations already apply; transparency obligations apply from August 2026; high-risk obligations were deferred by the 2026 Digital Omnibus to December 2027 and August 2028.

Relevant for: providers and deployers of AI systems — which includes many companies simply using AI tools.

What they have in common

All three require organizations to:

  • understand their risks,
  • implement appropriate technical and organizational measures,
  • handle and report incidents,
  • assign responsibilities and involve management,
  • document and evidence what they do.

That is exactly what an ISMS does. Instead of three separate compliance projects, one management system can carry the shared elements — and specific obligations are added where needed.

A sensible order

  1. Clarify applicability — which regulations apply, in which role? (with legal counsel)
  2. Use or build the ISMS as the common foundation.
  3. Close specific gaps — registration, reporting processes, product security, AI inventory.
  4. Evidence and maintain — so compliance stays current.

Talk to us

Want to tackle this in your organization? We help — together with your team.

contact@feldmanncyber.com · +49 (0)151 6275 6121