European Regulatory & Legislative Compliance Matrix
Comprehensive mapping of the 11 core EU directives, regulations, and standards governing telecommunications operators, cloud infrastructure providers, and digital service platforms.
Directive (EU) 2022/2555 — Network & Information Systems
Official Journal of the European Union L 333/80
Mandates cybersecurity risk management, 24h CSIRT incident reporting, supply chain risk controls, and executive liability for essential telecom entities.
Regulation (EU) 2022/2554 — Digital Operational Resilience Act
Official Journal of the European Union L 333/1
Harmonizes ICT risk management, threat-led penetration testing (TLPT), and critical third-party provider (CTPP) oversight for financial services and linked telcos.
Regulation (EU) 2024/2847 — Cyber Resilience Act (CRA)
Regulation (EU) 2024/2847
Introduces mandatory cybersecurity requirements, vulnerability handling rules, CE marking, and Software Bill of Materials (SBOM) for software & connected hardware.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Official Journal of the European Union L 2024/1689
Risk-based governance framework for AI systems. Telecom AI for network traffic management, biometric processing, and predictive maintenance are categorized by risk tier.
Regulation (EU) 2022/2065 — Digital Services Act (DSA)
Official Journal of the European Union L 277/1
Regulates online intermediaries, cloud platforms, and telcos acting as conduit/caching providers regarding illegal content, notice-and-action, and systemic risk.
Regulation (EU) 2022/1925 — Digital Markets Act (DMA)
Official Journal of the European Union L 265/1
Ensures contestable and fair digital markets. Governs gatekeeper core platform services, messaging interoperability, and non-discriminatory API access.
Regulation (EU) 2016/679 — General Data Protection Regulation
Official Journal of the European Union L 119/1
Protects personal data, subscriber location data, ePrivacy metadata, and mandates Data Protection Impact Assessments (DPIA) & 72h breach notifications.
Zero-Trust Open Telco API Gateway Security
GSMA Open Gateway & CAMARA Project Guidelines
Enforces OAuth 2.0, OpenID Connect (OIDC), Mutual TLS (mTLS), and fine-grained role-based access control (RBAC) across open telecom exposure APIs.
ENISA EU Cybersecurity Certification Frameworks
Cybersecurity Act — Regulation (EU) 2019/881
EUCC (Common Criteria), EUCS (Cloud Services), and EU5G cybersecurity certification schemes for high-assurance telecom and cloud infrastructure.
European Telecommunications Standards Institute Specifications
ETSI TS 103 701 / GS NFV / EN 303 645
Technical standard specifications covering Cyber Security Technical Advisory, NFV virtualization security, and consumer IoT cybersecurity baselines.
Cross-Border EU Member State Legal Transposition Tracker
EU Member State Transposition Acts (BSI, ANSSI, NCSC-NL)
Monitors member state national transposition laws (e.g., German BSIG/NIS2UmsuCG, French LPM, Dutch Wbni) ensuring multi-jurisdictional compliance.