EU Regulatory Center
Beyond the six core instruments
National transpositions, sector-specific guidance and widely used standards all shape real-world compliance — tracked with the same source-and-review discipline.
What this page covers
The six instruments in the EU Regulatory Center are EU-level law. In practice, compliance also depends on national transposition details, regulator guidance, and voluntary standards many customers are asked to align with — most commonly ISO/IEC 27001 for information security management and ENISA guidance for sector-specific implementation.
National transpositions
NIS2 and CER are EU directives, meaning each Member State transposes them into national law on its own timeline and with some local variation. Applicability in a specific country should always be confirmed against that country’s transposing legislation, not the EU directive text alone.