Short answer: company profile first, legal review second

Video overview

EU Digital Regulation for Mid-Market Companies: AI Act, NIS2, CRA and the Data Act

A visual management radar for European mid-market teams: what the AI Act, NIS2, the Cyber Resilience Act and the Data Act broadly cover, which companies should look more closely and the first management question for each lane.

EU Digital Regulation Management Radar

This table supports internal prioritisation. It does not determine whether your organisation is legally in scope.

You use, procure, develop or provide AI systems. AI Act / AI governance Do we know where AI is used, who owns it and how risk, competence and approvals are handled? AI inventory, roles, policy, risk assessments, training and approval evidence.
Sector, size, services, customer requirements or supply-chain position warrant a NIS2 assessment. NIS2 Has potential applicability been assessed and are management, risk, reporting and supplier responsibilities clear? Company and service profile, risks and measures, suppliers, incident and reporting paths.
You manufacture, import, distribute or offer products with digital elements under your own name. Cyber Resilience Act Are product role, software components, vulnerability handling, updates and release evidence assigned? Product portfolio, software components, vulnerability process, update policy, technical documentation and approvals.
Connected products, related services, industrial data or cloud switching matter to your business. Data Act Do we understand data sources, roles, access routes, contracts and technical handoffs? Data map, product and service roles, contracts, interfaces, safeguards and handoff processes.
Management radar for EU digital regulation with four review lanes for the AI Act, NIS2, CRA and Data Act and the company at the centre.
Management radar for EU digital regulation with four review lanes for the AI Act, NIS2, CRA and Data Act and the company at the centre.

The radar connects four regulation lanes through shared management disciplines; legal applicability still requires specialist review.

The radar connects four regulation lanes through shared management disciplines; legal applicability still requires specialist review.
Accessible description and data

A management radar places the company at the centre. Four recurring topic symbols identify the review lanes: an AI node network for the AI Act, a leadership shield for NIS2, a product-lifecycle mark for the CRA and a data store with a flow arrow for the Data Act. Owner, inventory, review and evidence connect all four regulation lanes. The radar is a management-orientation model, not a legal scope or compliance determination.

A shared management operating model

Each regulation needs its own qualified assessment. Preparation can still use one common operating model.

Clarify the company profile

Capture relevant entities, locations, sectors, products, services, customer roles and supply-chain relationships.

Connect the inventories

Maintain reliable views of AI systems, information assets, products, software components, suppliers and data flows.

Assign ownership

Name a management sponsor and operational owners for assessment, actions and evidence in every regulation lane.

Run qualified applicability reviews

Assess legal, technical and contractual questions with the right specialists, documenting assumptions and open points.

Prioritise and monitor gaps

Order measures by risk, dependencies and effort; assign owners and dates; and review progress on a recurring cadence.

A 30/90/180-day management agenda

These windows are a Momentum planning aid, not statutory deadlines.

30 days Sponsor, working group, company profile and existing inventories are identified. Responsibility map, data sources, open specialist reviews and initial risk questions.
90 days Relevant specialist reviews are commissioned and material gaps prioritised by risk and dependency. Review notes, gap list, action plan, owners and dependencies.
180 days Priority controls, evidence and review routines are embedded into operating processes. Approvals, policies, process records, training, tests and recurring management review.
30/90/180-day management agenda from regulatory radar to implementation, covering profile, inventories, owners, review, actions and evidence.
30/90/180-day management agenda from regulatory radar to implementation, covering profile, inventories, owners, review, actions and evidence.

The 30/90/180-day agenda moves from profile and inventories through relevance review and prioritisation to actions, evidence and recurring reviews; the horizons are not legal deadlines.

The 30/90/180-day agenda moves from profile and inventories through relevance review and prioritisation to actions, evidence and recurring reviews; the horizons are not legal deadlines.
Accessible description and data

A rising bridge connects three orientation horizons. By 30 days, management focuses on the company profile, inventories and owners. By 90 days, it reviews relevance, prioritises gaps and engages specialists. By 180 days, it manages actions, secures evidence and embeds reviews. These are management-orientation horizons, not legal deadlines.

30/90/180-day management agenda
HorizonManagement actions
30 daysClarify profile; start inventories; name owners
90 daysReview relevance; prioritise gaps; engage specialists
180 daysManage actions; secure evidence; embed reviews

EU Digital Regulation Radar Checklist

Official starting sources

These primary sources are maintained by the European Commission or BSI. For specific application, deadline and obligation questions, always check the current law and competent authority guidance. External sources open in a new tab.

Primary source

Federal Office for Information Security (BSI)

NIS2 in Germany

Current BSI information on registration and reporting under the German implementation act.

Open at BSI

Method, currency and limitations

Common management questions

Do we need to address all four rulebooks at the same time?
Can the checklist determine whether our company is in scope?
Who should own the work internally?
What information should we gather first?
How often should management revisit the radar?
Portrait of a mature man with gray hair wearing a dark blue suit and light blue shirt, with a neutral background and slightly blurred plants in the background.

Heinrich Ruhwasser

Your feedback

How would you rate this article?

Did this article help, or is something missing? Your feedback goes straight into improving our articles.

Related reading