Official sources
Go to the source.
The calendar of obligations and deadlines for the main European cybersecurity regulations, with direct links to the primary texts. No interpretation layered on top.
Other primary sources
Legislation and authorities we refer to most often in our advisory work.
- NIS2 Directive — (EU) 2022/2555The directive on the security of network and information systems (text on EUR-Lex).Open source
- Cyber Resilience Act — (EU) 2024/2847EU regulation on products with digital elements.Open source
- DORA — (EU) 2022/2554Digital Operational Resilience Act, for the financial sector.Open source
- GDPR — (EU) 2016/679General Data Protection Regulation.Open source
- ACN — Italian National Cybersecurity AgencyItaly’s cybersecurity authority and NIS2 point of contact.Open source
- ENISAEuropean Union Agency for Cybersecurity.Open source
- Italian Data Protection Authority (Garante)Italy’s supervisory authority for personal data.Open source