Guides
The AI Act timeline after the Digital Omnibus
Which AI Act deadlines moved (high-risk to 2 December 2027 and 2 August 2028), which did not, and what that means for your plans.
Read the guide ›AI Act chatbot disclosure
What Article 50 asks when customers talk to a chatbot or see AI-generated content, and how to word the notice.
Read the guide ›NIS2 Implementing Regulation 2024/2690 checklist
The technical and methodological requirements for cloud, data-centre, managed-service and other digital providers, as a checklist.
Read the checklist ›Answering NIS2 supplier questionnaires
What NIS2-regulated customers ask their suppliers about security, and how to answer once and reuse it.
Read the guide ›DORA for SaaS vendors
What banks and insurers will ask of you as an ICT third-party service provider under DORA, from contract clauses to the register of information.
Read the guide ›Cyber Resilience Act reporting
The CRA duty to report actively exploited vulnerabilities and severe incidents in products with digital elements: who, what, when and to whom.
Read the guide ›Framework overviews
What each framework asks for and how the Dazr Compliance portal covers it.
ISO 27001
The information security management system standard customers ask for in procurement.
See how Dazr helps ›NIS2
The EU cybersecurity directive for essential and important entities.
See how Dazr helps ›GDPR
Records of processing, breach notification and DPIAs.
See how Dazr helps ›DORA
Digital operational resilience for EU financial entities.
See how Dazr helps ›EU AI Act
Risk-based rules for AI systems on the EU market.
See how Dazr helps ›NEN 7510
Dutch information security standard for healthcare.
See how Dazr helps ›Netherlands and Italy, in English
Country-specific guides to the Dutch Cyberbeveiligingswet, BIO2 and NEN 7510, and to the Italian NIS2 decree, the ACN and the Garante.
Registering for the Dutch Cyberbeveiligingswet
How to register with the NCSC on MijnNCSC: eHerkenning EH2+, the five steps, the deadlines and a checklist of what to collect first.
Read the guide ›Dutch incident reporting: Cbw and GDPR
When to report a significant incident to your CSIRT via MijnNCSC, when a breach to the Autoriteit Persoonsgegevens, and when both. With a decision aid.
Read the guide ›Dutch Cbb next to ISO 27001, NEN 7510 and BIO2
A filterable crosswalk of the Dutch duty of care against the three frameworks, with the evidence you need and where the gaps are.
Open the crosswalk ›BIO versus BIO2
What changed in the Dutch government security baseline, how BIO2 became law via the Cbw and what it means for municipalities and provinces.
Read the guide ›BIO2 and ENSIA for Dutch municipalities
The annual ENSIA accountability cycle, the role of the RDI and how to collect evidence all year instead of in December.
Read the guide ›NEN 7510:2024 transition
What changed in the Dutch healthcare standard, the 20 February 2027 certification deadline, a gap list and the Cbw for healthcare.
Read the guide ›NEN 7510 for Dutch GP practices
What a small practice really has to do, what it costs, whether to hire an adviser, and a 12-month plan.
Read the guide ›Italy's ACN basic measures
All 43 measures and 116 requirements of the Italian NIS2 basic specifications as a checklist, with deadlines, ISO 27001 mapping and CSV export.
Open the checklist ›Italy: relevant NIS suppliers and CPV codes
Who goes on the supplier list for the ACN, which data to report and how to pick CPV codes. With a CPV search and CSV export.
Read the guide ›Italy: data breach to the Garante and the ACN
The Italian GDPR and NIS2 double track: when to notify the Garante, when also CSIRT Italia, and a decision tool with deadlines.
Read the guide ›Country pages
Cyberbeveiligingswet, NEN 7510, BIO2 en AVG
Dutch pages on the Cbw (registration, reporting, scope), NEN 7510:2024, BIO2 for gemeenten and the AVG breach deadline.
Naar de Nederlandse pagina ›NIS2, D.Lgs. 138/2024, ACN e Garante
Italian pages on the NIS2 decree, the ACN basic measures, relevant suppliers and data-breach notification to the Garante and ACN.
Vai alla pagina italiana ›Free tools
Deadline calculators and scope checks that go with the guides. All tools ›
Breach deadline calculator
Enter when you became aware of an incident and get the GDPR 72-hour and NIS2 24-hour, 72-hour and one-month deadlines, with a calendar file to download.
Calculate deadlines ›NIS2 significant-incident checker
Check an incident against the significance criteria of Article 23 NIS2 and Implementing Regulation (EU) 2024/2690 before you decide whether to report.
Check an incident ›NIS2 scope checker
Answer a few questions on sector, size and services to see whether NIS2 is likely to make you an essential entity, an important entity or neither.
Check your scope ›