Skip to content
Momentum Advisory Momentum Advisory Management consultancy
Menu

Management video

EU digital regulation for mid-market companies

The video connects the AI Act, NIS2, Cyber Resilience Act and Data Act in one management radar. It shows which company characteristics warrant a closer look, what information to prepare and where qualified specialist review begins.

Read transcript

Which four EU digital rules belong on your management radar? Start with four review lanes. The AI Act addresses roles and risks around AI systems: look closer if you develop, provide, procure or deploy AI. NIS2 covers cybersecurity risk management in specified sectors: check sector, size, entity role and Germany's current BSI Act. The Cyber Resilience Act covers cybersecurity of products with digital elements: review your role around digital hardware or software. The Data Act structures access to and use of data from connected products and related services: map users, data holders and recipients. These are review lanes, not automatic scope decisions, and they are not the complete EU digital rulebook. First, the AI Act. Make AI visible before classifying it. List systems and use cases, who provides or deploys them, and which decisions they influence. Turn that inventory into an AI policy, accountable owners and risk-oriented review. Add role-appropriate competence evidence. The inventory governs the work; it does not decide the legal classification. Second, NIS2. Keep one memory anchor: leadership, cyber risk, supply chain, incidents and evidence. Management should verify the entity's sector and characteristics under Germany's current BSI Act, then connect responsibilities, measures and reporting routes. Concrete scope and obligations need specialist review. Third, the Cyber Resilience Act. Treat product security as a lifecycle: product role and scope, components and SBOM, vulnerability handling, security updates and release evidence. This is the review lane for hardware and software with digital elements made available in the EU. Conformity and technical implementation remain specialist work. Fourth, the Data Act. Map connected products and related services to the data they generate, then map user, data holder and recipient. Add technical access and contract flows. Keep personal data, trade secrets and existing rights as separate safeguards. Start with the map, not a blanket assumption that data must be handed over. My recommendation: take the four-lane radar into your next management meeting. Mark only the lanes with concrete company signals; assign one owner and one specialist review to each. Use the Momentum Advisory radar checklist as your structured starting point. It supports prioritisation, not legal compliance.

Key moments

  1. 00:00

    Four rulebooks: overview and company signals

  2. 00:49

    AI Act and AI governance

  3. 01:11

    NIS2 and cyber governance

  4. 01:33

    Cyber Resilience Act and product security

  5. 01:55

    Data Act and data roles

  6. 02:17

    Recommendation for the next management meeting

AI-generated presenter; editorial and subject-matter responsibility: Momentum Advisory.

Editorial: Momentum Advisory

Content version: 2.1-question-led-cumulative-support · Reviewed: 22/07/2026

Subject-matter review: Momentum Advisory publication review against official sources; concrete applicability requires qualified specialist assessment · 22/07/2026

Choose your next step

Orientation, not a legal assessment

Have questions?

Talk to us about your situation.

In a short conversation we clarify goals, constraints and the most practical next step for your team.

Professional advisor character in a business meeting