Aller au contenu principal
Back to blog
Compliance 4 min 30 March 2026

Weekly Regulatory Recap #13 — NIS2, GDPR, CRA: The 5 Key Regulatory Updates

NIS2 GDPR ANSSI ENISA Cyber Resilience Act
Share LinkedIn X / Twitter

Week 13 (March 24–30, 2026) — an exceptionally busy week on the cybersecurity regulatory front.


👉 The 5 regulatory updates you cannot miss — along with their impact level for your organisation.

📋 The 5 Regulatory Updates

1NIS2ANSSI
🟠 High

Strengthened NIS2 Support

ANSSI publishes new practical guides to help essential and important entities comply with the NIS2 directive.

  • New sector-specific guides available on the ANSSI website
  • Focus on security obligations for essential entities
  • Transposition deadline: October 2026 — preparation must start now
Deadline: October 2026
2GDPREDPB
🔴 Critical

CEF 2026: Coordinated Action on Transparency

The European Data Protection Board launches a coordinated action targeting information obligations (Articles 12 to 14 of the GDPR).

  • Controls on the quality and accessibility of legal notices
  • Verification of privacy policy compliance
  • Risk of coordinated sanctions between national authorities
Risk of immediate sanctions
3Cyber Threat FRANSSI
🟠 High

Cyber Threat Landscape 2025: +35% in Attacks

ANSSI publishes its annual report on the state of cyber threats in France.

  • +35% incidents handled compared to 2024
  • Ransomware remains the main threat for businesses
  • Increasing targeting of local authorities and healthcare institutions
Urgent awareness required
4Cyber Resilience ActEuropean Commission
🟡 Moderate

CRA: Market Surveillance Structure Being Set Up

The EU structures the governance of the Cyber Resilience Act with the appointment of the Market Surveillance Group Chair.

  • Progressive establishment of the surveillance structure
  • Future obligations for manufacturers of connected products
  • Full application scheduled for 2027
Full application planned for 2027
5CVE / VulnerabilitiesENISA
🟡 Moderate

ENISA: Moving Towards CVE Root Authority Role

The European cybersecurity agency is evolving towards a CVE Root Authority role, strengthening European coordination.

  • Enhanced coordination for vulnerability management in Europe
  • Standardisation of responsible disclosure processes
  • Reduced dependency on the US CVE system (MITRE)
Standardisation in progress

📈 Trend of the Week

Regulatory Acceleration in Europe (NIS2 / GDPR / CRA)

European authorities are changing pace. In a single week:

« Compliance is no longer optional. It is a strategic priority. »
  • ANSSI publishes sector-specific practical guides to accelerate NIS2
  • EDPB coordinates GDPR checks between member states
  • European Commission structures CRA governance
  • ENISA strengthens its independence in CVE management

🎯 Watch Next Week

  • 📝ANSSI call for comments — reference architectures
  • 🎤InCyber Forum 2026 — ANSSI presence and institutional stakeholders
  • SME consultation deadline — Cyber Resilience Act

🧠 What This Means for Your Organisation

The regulatory calendar is accelerating on three fronts simultaneously:

✔ NIS2 → October 2026: essential entities must act now

✔ GDPR / CEF → coordinated checks are already under way

✔ CRA → 2027: start planning today for connected products

Every week of preparation counts.

Is your organisation ready for the NIS2 October 2026 deadlines? Where does your compliance roadmap stand?

Share LinkedIn X / Twitter

Need personalised guidance?

NagaShield Security helps you implement these measures concretely, tailored to your organisation and budget.

Request a free diagnostic
📋

Besoin d'aide sur ce sujet ?

Accompagnement Conformité ISO 27001 / NIS2