Weekly Regulatory Recap #13 — NIS2, GDPR, CRA: The 5 Key Regulatory Updates
Week 13 (March 24–30, 2026) — an exceptionally busy week on the cybersecurity regulatory front.
👉 The 5 regulatory updates you cannot miss — along with their impact level for your organisation.
📋 The 5 Regulatory Updates
Strengthened NIS2 Support
ANSSI publishes new practical guides to help essential and important entities comply with the NIS2 directive.
- ›New sector-specific guides available on the ANSSI website
- ›Focus on security obligations for essential entities
- ›Transposition deadline: October 2026 — preparation must start now
CEF 2026: Coordinated Action on Transparency
The European Data Protection Board launches a coordinated action targeting information obligations (Articles 12 to 14 of the GDPR).
- ›Controls on the quality and accessibility of legal notices
- ›Verification of privacy policy compliance
- ›Risk of coordinated sanctions between national authorities
Cyber Threat Landscape 2025: +35% in Attacks
ANSSI publishes its annual report on the state of cyber threats in France.
- ›+35% incidents handled compared to 2024
- ›Ransomware remains the main threat for businesses
- ›Increasing targeting of local authorities and healthcare institutions
CRA: Market Surveillance Structure Being Set Up
The EU structures the governance of the Cyber Resilience Act with the appointment of the Market Surveillance Group Chair.
- ›Progressive establishment of the surveillance structure
- ›Future obligations for manufacturers of connected products
- ›Full application scheduled for 2027
ENISA: Moving Towards CVE Root Authority Role
The European cybersecurity agency is evolving towards a CVE Root Authority role, strengthening European coordination.
- ›Enhanced coordination for vulnerability management in Europe
- ›Standardisation of responsible disclosure processes
- ›Reduced dependency on the US CVE system (MITRE)
📈 Trend of the Week
Regulatory Acceleration in Europe (NIS2 / GDPR / CRA)
European authorities are changing pace. In a single week:
« Compliance is no longer optional. It is a strategic priority. »
- →ANSSI publishes sector-specific practical guides to accelerate NIS2
- →EDPB coordinates GDPR checks between member states
- →European Commission structures CRA governance
- →ENISA strengthens its independence in CVE management
🎯 Watch Next Week
- 📝ANSSI call for comments — reference architectures
- 🎤InCyber Forum 2026 — ANSSI presence and institutional stakeholders
- ⏰SME consultation deadline — Cyber Resilience Act
🧠 What This Means for Your Organisation
The regulatory calendar is accelerating on three fronts simultaneously:
✔ NIS2 → October 2026: essential entities must act now
✔ GDPR / CEF → coordinated checks are already under way
✔ CRA → 2027: start planning today for connected products
Every week of preparation counts.
Is your organisation ready for the NIS2 October 2026 deadlines? Where does your compliance roadmap stand?
Need personalised guidance?
NagaShield Security helps you implement these measures concretely, tailored to your organisation and budget.
Request a free diagnosticBesoin d'aide sur ce sujet ?
Accompagnement Conformité ISO 27001 / NIS2