NIS2 DirectiveIN FORCE / TRANSPOSITION

Directive (EU) 2022/2555 — Network & Information Systems

Mandates cybersecurity risk management, 24h CSIRT incident reporting, supply chain risk controls, and executive liability for essential telecom entities.

✓ 24h CSIRT Early Warning ✓ Art 21.2(d) CVD Policy ✓ Art 21.2(f) Effectiveness Audits ✓ Supply Chain HRB Matrix
DORA RegulationAPPLICABLE JAN 2025

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

Harmonizes ICT risk management, threat-led penetration testing (TLPT), and critical third-party provider (CTPP) oversight for financial services and linked telcos.

✓ ICT Risk Framework ✓ TLPT Red Teaming ✓ Third-Party ICT Risk ✓ Major Incident Reporting
Cyber Resilience ActADOPTED 2024

Regulation (EU) 2024/2847 — Cyber Resilience Act (CRA)

Introduces mandatory cybersecurity requirements, vulnerability handling rules, CE marking, and Software Bill of Materials (SBOM) for software & connected hardware.

✓ CE Security Marking ✓ Software Bill of Materials (SBOM) ✓ Vulnerability Reporting (ENISA) ✓ Security by Design
EU AI ActENTRY INTO FORCE 2024

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Risk-based governance framework for AI systems. Telecom AI for network traffic management, biometric processing, and predictive maintenance are categorized by risk tier.

✓ High-Risk AI Governance ✓ Risk Management System ✓ Algorithmic Transparency ✓ Human Oversight & Audit
Digital Services ActFULLY APPLICABLE 2024

Regulation (EU) 2022/2065 — Digital Services Act (DSA)

Regulates online intermediaries, cloud platforms, and telcos acting as conduit/caching providers regarding illegal content, notice-and-action, and systemic risk.

✓ Notice & Action Mechanism ✓ Trusted Flagger Network ✓ Transparency Reporting ✓ Content Moderation Audit
Digital Markets ActAPPLICABLE 2023

Regulation (EU) 2022/1925 — Digital Markets Act (DMA)

Ensures contestable and fair digital markets. Governs gatekeeper core platform services, messaging interoperability, and non-discriminatory API access.

✓ Messaging Interoperability ✓ API Access Openness ✓ Non-Preferential Access ✓ Data Portability
GDPR PrivacyIN FORCE

Regulation (EU) 2016/679 — General Data Protection Regulation

Protects personal data, subscriber location data, ePrivacy metadata, and mandates Data Protection Impact Assessments (DPIA) & 72h breach notifications.

✓ Location Data Privacy ✓ 72h Data Breach Alert ✓ Subscriber Consent (ePrivacy) ✓ DPIA Assessment
API Access SecurityMANDATORY DESIGN

Zero-Trust Open Telco API Gateway Security

Enforces OAuth 2.0, OpenID Connect (OIDC), Mutual TLS (mTLS), and fine-grained role-based access control (RBAC) across open telecom exposure APIs.

✓ OAuth 2.0 / OIDC ✓ mTLS Gateway Auth ✓ Rate Limiting & Throttling ✓ API Threat Detection
ENISA SchemesACTIVE FRAMEWORKS

ENISA EU Cybersecurity Certification Frameworks

EUCC (Common Criteria), EUCS (Cloud Services), and EU5G cybersecurity certification schemes for high-assurance telecom and cloud infrastructure.

✓ EUCS Cloud Assurance ✓ EU5G Core Certification ✓ EUCC Hardware Trust ✓ ENISA Incident Guidelines
ETSI StandardsINDUSTRY STANDARDS

European Telecommunications Standards Institute Specifications

Technical standard specifications covering Cyber Security Technical Advisory, NFV virtualization security, and consumer IoT cybersecurity baselines.

✓ ETSI TS 103 701 Cyber ✓ ETSI GS NFV Security ✓ ETSI EN 303 645 IoT ✓ 3GPP Core Compliance
EU Law HarmonizationACTIVE TRACKING

Cross-Border EU Member State Legal Transposition Tracker

Monitors member state national transposition laws (e.g., German BSIG/NIS2UmsuCG, French LPM, Dutch Wbni) ensuring multi-jurisdictional compliance.

✓ 27 Member State Tracker ✓ National CSIRT Links ✓ Cross-Border Roaming Impact ✓ Harmonized Penalties