Short answer: company profile first, legal review second
The four rulebooks belong on one management radar because they rely on many of the same foundations: reliable inventories, named owners, documented decisions, supplier and product transparency, and recurring review. Whether and how a particular provision applies then requires qualified assessment.
EU Digital Regulation for Mid-Market Companies: AI Act, NIS2, CRA and the Data Act
A visual management radar for European mid-market teams: what the AI Act, NIS2, the Cyber Resilience Act and the Data Act broadly cover, which companies should look more closely and the first management question for each lane.
EU Digital Regulation Management Radar
This table supports internal prioritisation. It does not determine whether your organisation is legally in scope.
| Look closer if … | Regulation lane | First management question | Useful internal evidence |
|---|---|---|---|
| You use, procure, develop or provide AI systems. | AI Act / AI governance | Do we know where AI is used, who owns it and how risk, competence and approvals are handled? | AI inventory, roles, policy, risk assessments, training and approval evidence. |
| Sector, size, services, customer requirements or supply-chain position warrant a NIS2 assessment. | NIS2 | Has potential applicability been assessed and are management, risk, reporting and supplier responsibilities clear? | Company and service profile, risks and measures, suppliers, incident and reporting paths. |
| You manufacture, import, distribute or offer products with digital elements under your own name. | Cyber Resilience Act | Are product role, software components, vulnerability handling, updates and release evidence assigned? | Product portfolio, software components, vulnerability process, update policy, technical documentation and approvals. |
| Connected products, related services, industrial data or cloud switching matter to your business. | Data Act | Do we understand data sources, roles, access routes, contracts and technical handoffs? | Data map, product and service roles, contracts, interfaces, safeguards and handoff processes. |

Accessible description and data
A management radar places the company at the centre. Four recurring topic symbols identify the review lanes: an AI node network for the AI Act, a leadership shield for NIS2, a product-lifecycle mark for the CRA and a data store with a flow arrow for the Data Act. Owner, inventory, review and evidence connect all four regulation lanes. The radar is a management-orientation model, not a legal scope or compliance determination.
A 30/90/180-day management agenda
These windows are a Momentum planning aid, not statutory deadlines.
| Window | Management outcome | Expected evidence |
|---|---|---|
| 30 days | Sponsor, working group, company profile and existing inventories are identified. | Responsibility map, data sources, open specialist reviews and initial risk questions. |
| 90 days | Relevant specialist reviews are commissioned and material gaps prioritised by risk and dependency. | Review notes, gap list, action plan, owners and dependencies. |
| 180 days | Priority controls, evidence and review routines are embedded into operating processes. | Approvals, policies, process records, training, tests and recurring management review. |

Accessible description and data
A rising bridge connects three orientation horizons. By 30 days, management focuses on the company profile, inventories and owners. By 90 days, it reviews relevance, prioritises gaps and engages specialists. By 180 days, it manages actions, secures evidence and embeds reviews. These are management-orientation horizons, not legal deadlines.
| Horizon | Management actions |
|---|---|
| 30 days | Clarify profile; start inventories; name owners |
| 90 days | Review relevance; prioritise gaps; engage specialists |
| 180 days | Manage actions; secure evidence; embed reviews |
EU Digital Regulation Radar Checklist
Use the questions to prepare ownership, available evidence and the need for qualified legal or technical review.
Official starting sources
These primary sources are maintained by the European Commission or BSI. For specific application, deadline and obligation questions, always check the current law and competent authority guidance. External sources open in a new tab.
European Commission
AI Act
Current implementation and application timeline from the European Commission.
Open at the European CommissionFederal Office for Information Security (BSI)
NIS2 in Germany
Current BSI information on registration and reporting under the German implementation act.
Open at BSIEuropean Commission
Cyber Resilience Act
Current European Commission information, including reporting obligations.
Open at the European CommissionEuropean Commission
Data Act
European Commission guidance on connected products, data access and cloud switching.
Open at the European CommissionMethod, currency and limitations
Momentum Advisory developed this radar as a management aid based on company characteristics, inventories, ownership questions and typical evidence packages. The official starting sources and material claims were last checked on 22 July 2026. The radar supports orientation and prioritisation; it does not determine legal applicability or compliance with individual obligations. Claims will be reviewed again whenever material legislation or authority guidance changes.
Common management questions
Do we need to address all four rulebooks at the same time?
Not at the same depth. Start with the company profile, products, services, AI use and data flows. This produces a prioritised list of specialist reviews. Shared foundations such as inventories, ownership and evidence can be developed in parallel.
Can the checklist determine whether our company is in scope?
No. It structures information and management questions. Legal applicability depends on the organisation, its roles, products, services and national context and requires qualified assessment.
Who should own the work internally?
Ownership should be anchored at management level and distributed operationally across legal, information security, product, IT, procurement, data protection and affected business functions. The exact model depends on the business.
What information should we gather first?
Start with the company and service profile, AI inventory, information assets, product and software overview, suppliers, data flows, contracts, policies, incident processes and existing review or approval evidence.
How often should management revisit the radar?
Use a recurring review while implementation and authority guidance continue to evolve. Material changes to products, AI use, services, supply chains or data models should trigger an additional assessment.

Heinrich Ruhwasser
Heinrich Ruhwasser is a seasoned entrepreneur and advisor with more than twenty years of experience in digital transformation, corporate strategy, and succession planning. As an expert in business growth, he has successfully guided a wide range of companies through complex transformation initiatives. His core area of expertise is increasing enterprise value, where he applies his deep knowledge to long-term planning and seamless business succession. Heinrich’s combination of visionary thinking and hands-on experience makes him a trusted advisor to executives and business owners.
How would you rate this article?
Did this article help, or is something missing? Your feedback goes straight into improving our articles.
We review every response and use it to improve both content and reading flow.
Related reading
E-Invoice Conversion: PDF, XRechnung, ZUGFeRD and structured data
Why safe e-invoice conversion starts with structured source data and why PDF-to-XRechnung is often risky.
E-Invoicing Formats in Europe: EN 16931, UBL, CII, Peppol, XRechnung, ZUGFeRD and KSeF
A practical overview of relevant European e-invoice formats, standards and national systems without thin country pages.
E-Invoicing in Germany: obligations, formats and workflow
What companies need to know about German e-invoicing: 2025 obligation, XRechnung, ZUGFeRD, receiving, validation, archiving and practical next steps.