Insights
EU regulation
The European regulatory surface a software product actually sits on — GDPR, the European Accessibility Act, the Cyber Resilience Act and NIS2 — read for what they require of an engineering team, with the dates and the primary sources.
Where we stand
European software regulation arrives as a sequence of dates rather than as a single event, and the useful question is never "are we compliant" but "which of these actually binds this company, and by when". Scope depends on sector, size and where the entity is established, and a great deal of published advice skips all three.
Most of what these regulations ask of an engineering team is unglamorous and familiar: know what is in your product, know where personal data goes, be able to say what changed and when, and have a route to report an incident inside a fixed window. Teams already doing those things well are closer to compliant than they expect.
The places it gets genuinely hard are the seams. A production restore into a staging environment is processing personal data. A dependency you did not write is part of the product you place on the market. An integration partner’s breach is your incident to report. None of those are edge cases and all of them cross a boundary somebody assumed was somebody else’s.
We write about this because the gap between the text and the engineering consequence is where teams get caught, and because we cannot give legal advice — only an accurate account of what the requirement asks a delivery team to do.
Articles on EU regulation
- NIS2 when your customers are in scope and you are notThe directive binds essential and important entities. Its supply-chain article reaches everyone who sells to them, and it arrives as contract clauses rather than as law.
- DORA’s testing programme: what a financial entity has to prove, and how oftenDORA asks for a documented testing programme over the systems behind critical functions, and a much heavier threat-led test for entities singled out for it. The two are not the same product.
- Testing with production-like data without breaking GDPRRestoring the production database into staging is processing personal data. What that obliges you to do, why anonymised and pseudonymised are not interchangeable words, and what belongs in the test plan.
- The European Accessibility Act and your website: what it actually requiresThe Act has applied since June 2025. What it covers, which technical standard sets the bar today, and the accessibility failures no automated checker will ever find for you.
- The Cyber Resilience Act’s first deadline: what changes on 11 September 2026From 11 September 2026, manufacturers must report an actively exploited vulnerability within 24 hours. Who that binds, what the clock actually demands, and what to have in place before it starts.
Contact
Have a project in mind?
Tell us what you are building — or what keeps breaking. You will get a considered reply from an engineer, not an autoresponder.