Legal Landscape
We read the law. You get to-dos.
BSIG, NISG, the AI Act, GDPR, ISO 27001 — here's how we track regulation and translate it into plain language. With every provision you can check for yourself.
Deadline Radar 2025–2028
The calendar your competitors don't have.
Regulation arrives in stages — and most people only notice once a stage is already behind them. Up next: the deadline that's coming for you first.
How we work
Why you can rely on this.
01
Every requirement carries a source
No “NIS2 just requires that” — every requirement in Compliverse points to the specific provision: Section 30(2) No. 3 BSIG, not “Article 21 of the Directive”. German and Austrian transposition, not just EU prose.
02
We track legislation before it applies
Regulations arrive in stages, national transpositions shift, authorities change reporting channels. We keep the legal status current — you see the date at the bottom of every page.
03
Plain language is deliberate, not a simplification
Legalese protects nobody. We translate every obligation into a sentence your team understands — and a step it can tick off. The source citation stays for anyone who wants to check it.
Change log
When the law moves, we document it here.
Every review, every change, every correction of our own — with a date and a source. Including the times we had to catch up. A review that found nothing is an entry too.
Monthly legal review (all sources)
Checked on 01/09/2026
Monthly review: the six sources are unchanged — and the Danish reservation is closed against the original text
What changed
- Nothing in the six sources: the AI Act continues to apply unchanged in the consolidated version of 27 July 2026 (CELEX 02024R1689-20260727); there is no corrigendum. The BSIG is unchanged since the last review (last amended by Art. 8 Abs. 1 G v. 23.07.2026, BGBl. 2026 I Nr. 226 — status of the official citation line; the full text was last read in full on 7/8 August 2026). The NISG 2026 has no amendment (RIS consolidation, statute number 20013065). The NIS 2-loven is unchanged (LOV nr 434 af 06/05/2025, gældende). The GDPR has no amending act — the data part of the Digital Omnibus package is still only a proposal. For ISO/IEC 27001:2022 there is no new amendment sheet; it stays at Amendment 1:2024.
- The reservation from the review of 24 August 2026 is resolved: retsinformation.dk was reachable this time. § 13 stk. 1 NIS 2-loven has been read in the original text — early warning within 24 hours of awareness (nr. 1), notification within 72 hours of awareness (nr. 2), final report no later than one month after submission of the notification under nr. 2 (nr. 4), and a status report first if the incident is still ongoing (nr. 5). Our statements are thus backed by the primary text for all three countries. A side note from the same wording: trust service providers face a shortened 24-hour deadline for the notification (§ 13 stk. 2) — regularly irrelevant for our target group, but recorded here.
- For the record — applicable law, but outside the six sources: in Germany, the AI Market Surveillance and Innovation Promotion Act (KI-MIG) entered into force on 29 July 2026; the Bundesnetzagentur is thereby the central market surveillance authority and complaints body for the AI Act in Germany, while BaFin remains responsible for the financial sector. And ISO 14001 has been available in its 2026 edition since 15 April 2026 (transition period 36 months). We are checking both for product and website — inclusion only after a review against the wording, not with this check.
- Still being watched, still not applicable law and therefore without any change on our side: the Commission guidelines on high-risk classification (Art. 6(5) AI Act, draft of 19 May 2026, consultation closed, not final), the EDPB draft guidelines on anonymisation and web scraping (consultation until 30 October 2026), the proposal to amend the NIS2 Directive (COM(2026) 13 of 20 January 2026, in the legislative procedure) and the revision of ISO 9001 expected for autumn 2026. The German KritisV has still not been issued; the BBK's obligation to submit it was postponed by G v. 21.07.2026 (BGBl. 2026 I Nr. 221, Art. 8) to eight months after the KritisV enters into force.
What we did about it
- The open reading of § 33 Abs. 1 NISG 2026 (self-declaration) has narrowed, but honestly is not closed: secondary sources quote the wording as “nach Eintritt der Registrierungspflicht gemäß § 29 Abs. 2” — the trigger is therefore the point at which the duty arises, not the end of the registration period, and registering early does not shorten the deadline. That supports our guided date of 30 September 2027. Direct retrieval of § 33 from the RIS was technically blocked; we keep the point open until the section itself has been read.
- The review date has been raised to 1 September 2026, and the internal honesty list per source points to this entry. Wherever this check read only the official citation line instead of the full text, the entry says so — a “no change” is only worth as much as the statement of what it was checked against.
NISG 2026 (Austria) · NIS 2-loven (Denmark)
Checked on 24/08/2026
Re-checked for Austria and Denmark: one statement in our policy template held true only for Germany
What changed
- Nothing in the law. What changed is what we write about it — in a document our customers print out.
- The reporting deadlines are confirmed, contrary to our own suspicion: early warning within 24 hours of awareness, notification within 72 hours of awareness, final report one month after the notification — this chain applies identically in all three countries (§ 32 BSIG, § 34 Abs. 2 NISG 2026, NIS 2-loven § 13 stk. 1). We suspected our template was carrying German deadlines over into Austrian and Danish law. The suspicion was wrong; the check was right nonetheless.
- Said plainly, where this check hit a limit: for Denmark, retsinformation.dk was not reachable (HTTP 403). The wording comes from two independent secondary sources that agree — but that is not a primary source. We therefore list the Danish part as requiring confirmation and will re-check it against the original text at the next monthly review.
What we did about it
- Our information security policy stated that the law requires “appropriate, proportionate and effective risk management measures in line with the state of the art” — with the citation of the respective country underneath. For Germany that sentence holds. For Austria the word “effective” is missing from the wording (§ 32 NISG 2026 knows effectiveness only as the object of the evaluation); for Denmark both effectiveness and state of the art are missing. The sentence now names what all three laws contain: appropriate and proportionate measures. Fewer words, but verifiable in every country.
- In the same sentence we cited the whole statute (“BSIG”), although the duty sits in a specific provision. It is there now: § 30 Abs. 1 BSIG, § 32 Abs. 1 NISG 2026, NIS 2-loven § 6 stk. 1 — separate from the catalogue of measures, which is a different provision.
- The management's duty was also phrased a touch too German (“ensure and monitor”). Germany demands more (§ 38 BSIG: implement and monitor), Denmark something different (NIS 2-loven § 7: approve and supervise). We now write “be accountable for and monitor” — that covers all three without contradicting any of the three statutory texts.
- The Austrian reporting provision has been made precise: § 34 Abs. 2 NISG 2026 instead of § 34 NISG 2026. The paragraph reference had been open since the review of 11 August 2026, because the RIS was not reachable at the time; today it was.
Monthly legal review (all sources)
Checked on 24/08/2026
Monthly review: nothing changed in the law — two of our own texts did
What changed
- Nothing. All six sources were checked against the statutory wording again: the Digital Omnibus version of the AI Act is unchanged, there is no corrigendum. The BSIG was amended twice since our last review (21 and 23 July 2026) — but both amendments predate our review on 7/8 August and were already read then. The NISG 2026 and the NIS 2-loven are unchanged, and there is no new amendment to ISO 27001.
- Noted, but not yet applicable law — which is why we change nothing for it: the Commission is working on guidelines for high-risk classification (Art. 6(5) AI Act, draft of 19 May 2026, not final), and the European Data Protection Board on guidelines for anonymisation and web scraping for generative AI (draft of 8 July 2026, consultation open until 30 October 2026). Both are on the list for the next review.
- Also being watched: on 20 January 2026 the Commission proposed amending the NIS2 Directive itself. The proposal has not been adopted; the BSIG in force is unaffected.
What we did about it
- The error we already corrected once on 7 August 2026 — the final report runs one month after the report, not from awareness — turned up in three further places where it had lived on independently: in the policy template “Handling of security incidents” that we ship to customers, in the NIS2 evidence package itself, and in the completion sentence of the guided NIS2 walkthrough. All three are fixed. That the sentence “You have now met …” was among them is the uncomfortable part — it is the exact place where we ask to be trusted.
- The same template hardcoded “to the BSI”, regardless of which country the customer is in. For Germany the correct recipient is the joint reporting office of the BSI and the BBK (Section 32(1) BSIG); for Austria and Denmark it is a different body. The template now inserts the reporting office of the relevant country, as it already did for the citations. The same clarification is now on the NIS2 module page.
- Said plainly, because of what it says about us: both errors sat in files that restate the law in their own words instead of drawing it from our central source. That source exists precisely to prevent this — and it still failed twice here, because those texts were older than our own correction.
Digital Omnibus Regulation (EU) 2026/1744
Checked on 08/08/2026
Follow-up honoured: the three open points are checked against the statutory text
What changed
- On 7 August we recorded publicly that three details of the Digital Omnibus version had not yet been checked against the wording, because EUR-Lex was running in degraded mode. That follow-up is now honoured: all three have been checked against the consolidated version of the AI Act (as at 27/07/2026) — and all three confirm what we had said.
- First: the transition period for machine-readable marking of legacy systems, running to 02/12/2026, is in Art. 111(4) AI Act — the paragraph reference we had withdrawn as a precaution is correct and comes back. More important than the number is the scope: the period relieves providers only, and only for machine-readable marking. Operators who have to disclose deepfakes or AI-generated text (Art. 50(4) AI Act) get no transition period; that duty has applied in full since 02/08/2026.
- Second: the fine range for breaches of the transparency duties is in Art. 99(4)(g) AI Act and is unchanged. New, and relevant for smaller companies: the Omnibus extended the rule that SMEs and start-ups face the lower of the two figures (Art. 99(6)) to small mid-cap companies (Art. 99(6a)). That is a relief we could not name before, because it was known only from secondary sources.
- Third: Art. 113 AI Act governs the application dates. Confirmed are 02/12/2027 for high-risk under Annex III and 02/08/2028 for Annex I. Also in the wording: two new prohibitions in Art. 5 AI Act become applicable on 02/12/2026 — until then they are upcoming, not applicable, law.
- One point we had not mentioned anywhere and have now added: for high-risk systems intended for use by public authorities, Art. 111(2), second sentence, AI Act sets its own deadline — 02/08/2030.
What we did about it
- Closed every internal “open” marker on the Omnibus version, and restored paragraph-level precision to the citations we had withdrawn as a precaution.
- Moved the fine figures on the Legal Landscape page and in the knowledge articles to the specific provision — instead of a blanket “Art. 99 AI Act”, the relevant paragraph now appears. We added the relief for SMEs, start-ups and small mid-caps at the same time, because the headline figures give a false picture without it.
- Stated the scope of the transition period explicitly, because the market routinely presents it as broader than it is.
- Said plainly what the check did NOT change: on all three points we were right. We still marked them open for as long as we had not read them in the statutory text ourselves — and that difference is exactly what we mean by “audit-ready”.
BSI Act of 2 December 2025 (Federal Law Gazette 2025 I No. 301)
Checked on 07/08/2026
Reporting deadlines clarified: the one-month clock starts later than most people think
What changed
- Checking Section 32 BSIG against the wording reveals a detail that is misreported almost everywhere: the final report is due “no later than one month after submission of the report on the security incident pursuant to number 2” — that is, one month after the 72-hour report, not one month from awareness. Only the early warning (24 hours) and the report (72 hours) run from the point of becoming aware.
- Two further clarifications from the same section: the recipient is the joint reporting office of the BSI and the BBK, not “the BSI”. And if the incident is still ongoing when the deadline falls, a progress report takes the place of the final report for the time being (Section 32(2) BSIG).
- Also confirmed against the wording: registration must be submitted no later than three months after an entity first, or once again, qualifies as in scope (Section 33(1) BSIG).
What we did about it
- Corrected our reporting assistant: the one-month clock for the final report now only starts at the moment the 72-hour report is marked as submitted — until then the platform states openly what the deadline depends on.
- Updated every affected text (measure catalogue, training content, incident capture) and named the reporting office correctly.
- Built the new industry pages directly on the checked wording — including the sector lists from Annexes 1 and 2 and the size criteria in Section 28 BSIG.
BSI Act of 2 December 2025 (Federal Law Gazette 2025 I No. 301)
Checked on 07/08/2026
Wording check on Sections 30 and 38 BSIG: two of our own formulations made precise
What changed
- Checking against the statutory text confirms the ten minimum measures in Section 30(2) BSIG — but sharpens terms that many people, ourselves included, had taken from the EU directive rather than the German act. The BSIG does not speak of “cyber hygiene” but of “basic training and awareness measures” (No. 7), of “cryptographic procedures” rather than “cryptography and encryption” (No. 8), and of the “management of ICT systems, products and processes” rather than “asset management” (No. 9).
- Section 38 BSIG requires management bodies to “implement the risk management measures and monitor their implementation” — merely “approving” them, as the EU directive puts it, does not appear in the German act; the duty is stricter. Liability runs to the entity itself, primarily under company law (Section 38(2)).
- Note on the citations: German provisions are given as “Section 30(2) No. 1 BSIG”. The German original reads “§ 30 Abs. 2 Nr. 1 BSIG” — same provision, English convention.
What we did about it
- Moved our own texts (requirement catalogue, plain-language translator, knowledge articles, training content) to the promulgated wording — including correcting a quoted extract that contained “approve”.
- Built the new policy template library (eleven templates, one per statutory duty) directly on the checked wording — each template carries its citation.
Digital Omnibus Regulation (EU) 2026/1744
Checked on 07/08/2026
Primary-source check against the Official Journal: Art. 4 now verbatim
What changed
- Nothing in substance — the check against the official wording (OJ L of 24 July 2026, EUR-Lex) confirms what we said: Art. 4 requires measures to support AI literacy, and nobody has to guarantee any particular level of competence (Art. 4(1), second sentence, as amended). The high-risk deadlines 02/12/2027 (Annex III) and 02/08/2028 (Annex I) appear as such in the Official Journal; the regulation has been in force since 27/07/2026.
- A clarification from the wording: alongside your own staff, Art. 4 expressly covers people dealing with the operation and use of AI systems on your behalf (freelancers, service providers) — and what must be taken into account is their technical knowledge, experience, education and training, the context of use, and the groups of people affected.
What we did about it
- Replaced our summary of Art. 4 on the home page with the verbatim quotation of the amended version (source: EUR-Lex, German Official Journal version).
- Said plainly: EUR-Lex was running in degraded mode during the check and part of the Official Journal text could not be retrieved. Three details (the fine provision Art. 99(4), Art. 111(4), Art. 113) will be checked against the wording as soon as EUR-Lex is fully available again — until then we mark them internally as open.
Digital Omnibus Regulation (EU) 2026/1744
Checked on 07/08/2026
The Digital Omnibus amends the AI Act — we have followed suit
What changed
- Art. 4 (AI literacy) was recast with effect from 27/07/2026: instead of “ensuring” a level of competence, companies must take measures that support the development of AI literacy. The duty remains — documented measures are still required.
- The high-risk obligations were postponed: Annex III to 02/12/2027, Annex I (embedded systems) to 02/08/2028. The grandfathering for legacy systems is tied to the same dates.
- Unchanged: the transparency duties under Art. 50 have applied since 02/08/2026. Only the machine-readable marking of legacy systems has a transition period, running to 02/12/2026.
What we did about it
- Moved the home-page ticker, the deadline radar and every Legal Landscape detail page to the Omnibus version — including correcting outdated statements of our own.
- Updated the knowledge article on Art. 4 and marked it as revised.
- Moved every deadline and version into a single checked source, so future changes arrive everywhere at once.
The German original is the source for every date and citation — see it here. Questions about a specific entry? Ask us directly.
And what applies to you?
Four questions, thirty seconds.
The scope check gives you an honest first estimate.
Question 1 / 4
Do you use AI in daily work — ChatGPT, Copilot, or your own AI applications?
EU AI Act · competence measures under Art. 4
Ready to see it running?
Real screens from the running platform, no scheduling required.