EU Regulatory Intelligence,
Without the Noise

Expert analysis on NIS2, DORA, AI Act, CRA, and GDPR — written by compliance specialists for CTOs, CISOs, and DPOs.

Browse all articles

📬 The Regulatory Signal

Weekly digest — NIS2, DORA, AI Act, CRA, GDPR. One concise email, no fluff.

By subscribing you accept that NexCyber may process your email to send the Regulatory Signal newsletter (RGPD Art. 6(1)(a) consent). You'll receive a confirmation email to validate. Unsubscribe anytime in one click.

Latest articles

NIS2 Jul 9, 2026

NIS2 Article 23 Incident Reporting: 24h/72h/1-month Decision Tree for CISOs

NIS2 Article 23 imposes a three-tiered incident reporting regime that turns every cyber event into a ticking clock. Miss the 24-hour early warning and you risk a fine of up to €10 million or 2 % of gl…

DORA Jul 2, 2026

DORA Reporting Failures: What Moody's EUR 2.1M Fine Reveals About ICT Audit Gaps

The EUR 2.1 million fine imposed by ESMA on Moody’s Deutschland GmbH in July 2024 was not just a penalty—it was a regulatory warning shot. The enforcement action, the first major DORA-related sanction…

GDPR Jul 2, 2026

Connected Vehicle Location Data: CNIL's New GDPR Compliance Framework

The French data protection authority (CNIL) published its final recommendations on connected-vehicle location data in June 2026, closing a two-year consultation that began when a major EU fleet operat…

NIS2 Jul 1, 2026

Calibrating AI Code Review for NIS2: The 'Vibe Spectrum' Compliance Framework

AI-assisted development is now the default for most engineering teams. Yet for CTOs in NIS2-covered entities, every `git commit` that originates from an LLM prompt carries regulatory weight. NIS2 Arti…

NIS2 Jul 1, 2026

NIS2 Article 19 Disclosure Deadlines: When Vendor Patches Miss Your Reporting Window

A single unpatched critical vulnerability in a third-party component can trigger NIS2’s 24-hour incident notification clock—long before the vendor delivers a fix. For CISOs and CTOs in essential and i…

DORA Jul 1, 2026

DORA Meets SREP 2026: EBA's New ICT Risk Scoring in Supervisory Reviews

The European Banking Authority’s (EBA) revised Supervisory Review and Evaluation Process (SREP) Guidance for 2026 introduces a paradigm shift: ICT risk is no longer a standalone compliance exercise bu…

→ All articles