Andrea Margiovanni .it
Home / European software compliance 2026

European software compliance 2026

CRA, AI Act, PLD, NIS2, EAA, DORA. Six regulations that between 2026 and 2028 reshape how software is designed, sold and documented in Europe. This is the index page — with my own take, the deadlines, and every essay I've written for each one.

What follows is my personal reading of what’s changing in European software over the next 18–24 months, with pointers to the essays I’ve written on each theme. Not legal advice — the perspective of someone who designs software architectures that have to ship and stay alive.

Last revised: 25 August 2026. I update this page when a new deadline drops or I return to a point in an essay.


Thesis in one line

European compliance 2026–2028 cannot be “ticked off” at the end of a project: it must be designed into the architecture on day one, like any other non-functional constraint.

Everything below is the reasoning behind that sentence.

The six regulations, in one breath

  • CRA (Cyber Resilience Act) — security obligations for “products with digital elements”: SBOM, vulnerability management, incident reporting, declared support window. Reporting obligations kick in on 11 September 2026: early warning within 24 hours, on an ENISA platform that goes live the very same day, with no test environment, so the dress rehearsal has to happen in-house. And the maturity model ENISA published in July measures the organisation’s maturity: it does not prove a product’s conformity.
  • AI Act — staggered obligations for AI systems by risk level: general models, high-risk systems (HR, credit, justice), prohibited systems, GPAI (general purpose AI). The June 2026 Digital Omnibus moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), with dates now fixed; the rest of the calendar is confirmed.
  • PLD (new Product Liability Directive) — extends strict liability to software: the producer is liable for damage from defects regardless of fault.
  • NIS2 — cybersecurity for essential and important entities: governance, incident reporting within 24/72h, digital supply chain obligations.
  • EAA (European Accessibility Act) — mandatory accessibility for e-commerce, ebooks, online banking, ticketing, telephony and transport services from June 2025.
  • DORA (Digital Operational Resilience Act) — operational resilience for the EU financial sector: ICT risk management, resilience testing, oversight of critical third-party providers. In force since January 2025; its reach beyond finance is significant, because it sets de facto standards for operational resilience across the digital supply chain.

Six regulations written in different years by different DGs in different styles. But they converge on a common operational idea: software is no longer “an intellectual work exempt from technical responsibility” — it’s an industrial product with compliance obligations comparable to a fridge.

Italian specificity — ACN. Italy’s National Cybersecurity Agency has published a qualification matrix (QC1–QC4) for cloud services used by public administration that overlaps with NIS2, CRA and GDPR while imposing tighter operational constraints. For anyone selling to Italian public administration it’s a non-optional variable, to be read alongside the EU package — not as an alternative to it.

My essays, grouped by regulation

CRA, architecture, SBOM

16.09 2026
№ 96

A Hundredth of a Second per Target

On Monday the Spanish data protection authority published the first breach notification in which the attack was reportedly carried out by an agent. The interesting part is not that a machine broke into an application. It is that sixteen years ago a researcher worked out how much attention a mass attacker can afford to spend on each target, and the number was a hundredth of a second.

21′ reading time
4,833 words
Read →
13.09 2026
№ 95

When Does a Company Know Something?

On Friday the form went live through which European manufacturers report exploited vulnerabilities. It contains a field asking for the date and time you became aware, and a twenty-four-hour clock starts from it. It looks like admin. It is the point where the architecture through which an organisation comes to know something becomes a legal matter.

22′ reading time
4,874 words
Read →
08.09 2026
№ 94

The Cost of Changing Your Mind

For years we looked for digital sovereignty in the provider's passport, the location of the data centre, the software licence. Those are fair questions that miss the decisive one: if we want to change our decision tomorrow, can we actually do it, and at what price? Sovereignty as a real option, and a way to count it.

23′ reading time
5,220 words
Read →
04.09 2026
№ 93

Redacted

A car stopped dead in a freeway lane at three in the morning, a federal report with three blacked-out fields, two deaths twenty-five days apart, and nobody able to say why. Europe's new Product Liability Directive is criticised from every side as a compensation tool. It does one thing, and that thing matters: it makes not knowing illegitimate.

25′ reading time
5,598 words
Read →
28.08 2026
№ 90

Authority Arrives Before Intelligence

We describe agents in a technical vocabulary, tool calling, memory, sandboxes. But an agent is not interesting because it does things on its own: it is interesting because someone granted it the right to do things that have consequences. And rights, unlike intelligence, are not acquired. They are delegated. With everything that word carries.

19′ reading time
4,239 words
Read →
23.08 2026
№ 87

The Lock-In Won't Be in the Data Anymore

The Data Act made data portable, and open standards are making agents interchangeable. But between the documents and the decisions a third object is forming, the state the system has accumulated while working for you, and no rule today says who owns it. The next lock-in won't hold your data hostage: it will let you take everything, except what the system learned to do with it.

17′ reading time
3,617 words
Read →
19.08 2026
№ 84

The Price of Leaving

On August 18 Apple repriced its European ecosystem, and the commission owed by anyone who sends a customer to pay outside the App Store became a single number. The Digital Markets Act has taken power away from nobody. It has started arguing about what it may cost not to depend on that power. That is a different thing, and it is politics.

19′ reading time
4,181 words
Read →
13.08 2026
№ 82

No Dress Rehearsal

On September 11 the Cyber Resilience Act's reporting obligations kick in: 24 hours for the early warning, on a platform that goes operational the very day the duty binds. No API, no test environment, an address that isn't public yet. Onboarding is a compliance requirement nobody wrote down, and whoever registers on September 12 has already lost.

8′ reading time
1,736 words
Read →
27.07 2026
№ 81

The Floor Below

Around the third month of using an agent, someone says the model has got worse. Almost always it isn't the model: it's the scaffolding, which came apart without throwing an exception. What degrades quietly is exactly what nobody is required to check, and in Europe, from September, that friction costs a non-conformity.

9′ reading time
1,816 words
Read →
17.07 2026
№ 79

A Score Is Not Proof of Conformity

An Advanced rating measures an organisation’s maturity. It does not show that a specific product conforms to the CRA. The distinction is not self-assessment versus outside scrutiny. It is diagnosis versus a declaration that carries responsibility.

10′ reading time
2,118 words
Read →
24.06 2026
№ 75

Sovereignty Doesn't Live in the Data Center

On the Cloud and AI Development Act, on the ten thousand repositories dressed up as honest projects, and on the distance between being inspectable and actually being inspected.

13′ reading time
2,976 words
Read →
07.05 2026
№ 65

The Compliance Hourglass

A map of the Italian compliance market drawn from the inside: specialist advisory at the top, platforms at the bottom, the middle layer crushed between them. And the one specifically Italian piece—ACN—that bends the rules.

7′ reading time
1,768 words
Read →
21.04 2026
№ 58

DPIA as a Genre, Not a Form

The EDPB's DPIA template, released in April, isn't a longer form. It codifies a form. On the shift from module to genre, and what changes for anyone who writes compliance as continuous writing practice.

26′ reading time
6.514 words
Read →
18.04 2026
№ 56

Mrs. Donoghue's Last Bottle

Why the «product» on which modern liability law is built no longer exists in contemporary software — and what we might put in its place.

30′ reading time
7.401 words
Read →
28.03 2026
№ 50

Incompetence as a Structural Condition of the Present

Nobody knows what they’re doing—not as a cliché, but as a structural fact: our technical systems are now too complex for any single person to understand.

12′ reading time
2.707 words
Read →
16.03 2026
№ 41

Things I've Stopped Doing Over the Last Fifteen Years of Work

Notes on the things it took me at least 15 years to unlearn—habits about code, stacks, business, compliance, hiring, language, and leadership.

9′ reading time
1.897 words
Read →
11.03 2026
№ 39

The Smallness Paradox: Long Live European Regulation

Between the AI Act, CRA and NIS2, Europe is rewriting the rules: it’s not who runs fastest that wins, but who builds serious, secure, accessible software.

11′ reading time
2.311 words
Read →
08.03 2026
№ 37

Hands and the Machine: Trust in Software

Software runs the world yet stays invisible. Between ai, open source and European rules, trust is built with care, choices, and responsibility.

11′ reading time
2.390 words
Read →
08.03 2026
№ 36

Compliance Is Your Problem

Between 2026 and 2027, software becomes a product with legal liability. If the client only wants go-live, the risk stays with everyone.

7′ reading time
1.560 words
Read →
24.02 2026
№ 29

Don't Add AI to Your Products. Rethink Them from Scratch.

Adding a chatbot isn't enough. If half the interactions are going to flow through AI agents, you have to rethink software, APIs, trust, and compliance.

8′ reading time
1,580 words
Read →
18.02 2026
№ 21

Software Is a Product. Now What?

From 9 December 2026, the new EU Product Liability Directive treats software as a product. What changes for roadmaps, contracts, releases, and open source.

10′ reading time
2,150 words
Read →

AI Act, governance, deployer

21.08 2026
№ 86

The Button Is Still Yours

In July 2026 an agent tried to get malicious code approved on a real open source project. When the maintainer pushed back, it built itself some allies. It failed, and how it failed matters more than the incident: human oversight holds only while the machine stays out of the conversation in which the human decides.

23′ reading time
4,971 words
Read →
20.08 2026
№ 85

Where Judgment Is Formed

On 19 August OpenAI announced a system that promises to spot abuse without retaining conversations and without anyone reading them. The direction is right, and it makes visible a problem that database privacy cannot yet name: we can build machines that keep nothing and know a great deal.

25′ reading time
5,544 words
Read →
15.08 2026
№ 83

The Right to Understand Is Not the Right to Multiply

On August 14 a Chinese lab shipped a model with offensive capabilities it had not planned for, and it shipped them on a schedule rather than with a switch. This is the moment the word "open" stops being enough.

20′ reading time
4,260 words
Read →
24.07 2026
№ 80

The Level You Can't Delegate

ATMs didn't kill the bank teller, and the spreadsheet created more accountants than it destroyed bookkeepers. The fastest typist in the office disappeared anyway. Agents are repeating that move on entire processes, and the one function no workflow can expel is already written into European regulations.

9′ reading time
1,893 words
Read →
09.07 2026
№ 78

Seventeen Months Are Not a Grace Period

The Digital Omnibus pushed the AI Act's high-risk obligations to 2027, and healthcare software breathed a sigh of relief. But the pressure never came from that deadline: it comes from three clocks, enforcement, engineering and the market, and none of them was touched.

9′ reading time
1,953 words
Read →
04.07 2026
№ 77

Compliance Doesn't Fail for Lack of Rules, It Fails for Lack of Inventory

Five European regulations, written by different hands for different sectors, are converging on the same demand: prove you know what you have in the house. Whoever can't answer isn't non-compliant, they're ungovernable. And the inventory that's needed isn't compiled: it's generated.

7′ reading time
1,416 words
Read →
30.06 2026
№ 76

The Name of the Future

On artificial intelligence as a political fact before a technical one, on the translation that never quite lands, and on what a country loses when it imports the words along with the machines.

11′ reading time
2,433 words
Read →
17.06 2026
№ 74

The Digital Omnibus Is Not an Amnesty

Brussels moved a few AI Act deadlines and confirmed everything else. For a small or mid-sized IT company that had just started getting serious about compliance, this is the moment to accelerate, not to slow down.

14′ reading time
2,915 words
Read →
16.06 2026
№ 73

Before It Becomes Irreparable

On June 9 the Commission ordered Meta to reopen WhatsApp to rival AI assistants within five days. It is the rarest interim measure in European competition law, and it is a meditation on time disguised as an administrative order.

10′ reading time
2,210 words
Read →
27.05 2026
№ 69

The Human Is a Stance

I am an atheist, I come from philosophy, I work in European compliance. Leo XIV's first encyclical on artificial intelligence is not something I signed, it is something I argued with. And I found in it a vocabulary that Brussels still lacks.

10′ reading time
2,096 words
Read →
13.05 2026
№ 67

Twelve Jobs in Search of a Market

The first national European standard on AI professional profiles was published on 30 April. It is worth taking seriously, and it is worth mistrusting in the right way.

6′ reading time
1,312 words
Read →
05.05 2026
№ 64

The Spectre We Are

A long reckoning with European digital regulation seen from the outside—by those who hate it—and a counter-reading from inside, by those who translate those rules into technical objects every working day.

22′ reading time
4,950 words
Read →
01.05 2026
№ 63

The Contract's Deception

On why the software supply contract, as we have known it, has stopped being the central instrument of the relationship between vendor and client — and how much it costs to keep pretending it still is.

19′ reading time
4.180 words
Read →
01.05 2026
№ 62

The Rise of the Compliance Engineer

On the figure now emerging from the gap between software engineering and European regulation, and on why almost no one is noticing in time.

16′ reading time
3.520 words
Read →
01.05 2026
№ 61

The Specification Debt

On why the document that certifies the system ages worse than the code that implements it, and why the next generation of civil software-liability cases will be fought over the specification.

19′ reading time
4.420 words
Read →
27.04 2026
№ 59

The Shape of Constraint

Treating regulatory compliance as the adversary of the technical project means you haven't understood what the technical project is. An essay on the category error weakening Europe's software industry — and on how the European framework, read as a system rather than as a list, configures a structural competitive advantage for those who learn to inhabit it.

16′ reading time
3.842 words
Read →
07.04 2026
№ 54

Behavior Is the New Credential. And That's a Problem.

Cybersecurity is undergoing a transition that deserves more attention than it gets: online authentication is shifting from what you know to how you behave.

10′ reading time
2.226 words
Read →
06.04 2026
№ 53

Microsoft Wrote the Perfect Confession—and You'll Pay the Bill

It’s tempting to dismiss it as a legal team slip-up. It isn’t. Terms of Use aren’t written by accident—and every word is meant for court.

19′ reading time
4.112 words
Read →
30.03 2026
№ 51

The advisory blind spot: what an IT vendor knows that an analyst doesn't

A few weeks ago I received an advisory report on IT services in our segment. It was solid, but it missed what only delivery-side vendors learn.

6′ reading time
1.365 words
Read →
25.03 2026
№ 47

Progress Is Not a Direction: Anatomy of a Dangerous Misconception

When people shout that the state is "holding back progress," are they really talking about progress: or something else entirely?

29′ reading time
6.442 words
Read →
17.03 2026
№ 42

EU compliance 2026: it's architecture, not just legal

Over the next 18 months CRA, AI Act, PLD, NIS2 and EAA will reshape European software. Compliance isn’t a checkbox: it’s designed into architecture.

11′ reading time
2.331 words
Read →

Governance and the craft of software in a world of constraints

27.04 2026
№ 59

The Shape of Constraint

Treating regulatory compliance as the adversary of the technical project means you haven't understood what the technical project is. An essay on the category error weakening Europe's software industry — and on how the European framework, read as a system rather than as a list, configures a structural competitive advantage for those who learn to inhabit it.

16′ reading time
3.842 words
Read →
30.03 2026
№ 51

The advisory blind spot: what an IT vendor knows that an analyst doesn't

A few weeks ago I received an advisory report on IT services in our segment. It was solid, but it missed what only delivery-side vendors learn.

6′ reading time
1.365 words
Read →
17.03 2026
№ 42

EU compliance 2026: it's architecture, not just legal

Over the next 18 months CRA, AI Act, PLD, NIS2 and EAA will reshape European software. Compliance isn’t a checkbox: it’s designed into architecture.

11′ reading time
2.331 words
Read →
16.03 2026
№ 41

Things I've Stopped Doing Over the Last Fifteen Years of Work

Notes on the things it took me at least 15 years to unlearn—habits about code, stacks, business, compliance, hiring, language, and leadership.

9′ reading time
1.897 words
Read →

How I’d use this page

If you’re a CTO or Head of Engineering: my operational suggestion is to treat these deadlines as release engineering — explicit ownership, roadmap milestones, a RACI. Not legal with a code review.

If you’re a product manager: start with the EAA if you have a consumer-facing product, with the CRA if you sell B2B. Those two have the most tangible product implications.

If you’re a European software SME: it’s not catastrophic, but decisions are needed now on three fronts — logging/audit, SBOM, incident procedure. I cover this directly in several of the essays linked above.

If you’re an advisory consultant: the window for readiness assessments is now, not once the first enforcement case hits the news.

Primary sources (required reading)

Work with me

My engagement here isn’t to tell you ‘here’s the rule’. It’s to help you translate six European regulations into a set of architectural choices, a roadmap, and internal ownership. Legal counsel remains necessary, but it isn’t the right place to start.

Who it's for

  • CTOs and Heads of Engineering at EU software vendors and SaaS businesses

  • Product managers who need to understand what changes in their product before planning the next four quarters

  • Tech SME founders realising the CRA deadline is too close to keep ignoring

  • Compliance officers who want requirements translated into a backlog, not a policy PDF

How I work

Readiness assessment (2–4 weeks)

I take your product, pipeline and supply chain and compare them to the applicable CRA, AI Act, PLD, NIS2, EAA and DORA requirements. Output: a gap map with priorities, estimated effort, and design-in suggestions.

Compliance roadmap design (3–6 weeks)

From assessment to roadmap. Who does what, with what measurable milestones, synchronised with the EU deadlines. A document a board can approve and a team can execute.

RFP and vendor second opinion (1–2 weeks)

I read a vendor contract or purchase proposal and tell you whether the chain of responsibility holds up under the new PLD and CRA. Useful before you sign.

Engagement FAQ

Are you a lawyer?

No. I’m a systems architect who works with legal teams. My output is operational: flow diagrams, RACIs, backlogs. Legal opinion comes from your lawyer.

Do you work on single regulations (e.g. only the AI Act)?

Yes, but reluctantly. The six regulations interact in subtle ways (e.g. CRA and PLD, or AI Act and NIS2, or NIS2 and DORA). Looking at one in isolation often hides costs that surface on the second.

How long does a typical engagement last?

Two to six weeks for an assessment or review, two to three months for a full compliance plan.

Do you do delivery or certification audits?

No to both. Independent advisory works precisely because it has no incentive to sell you delivery work. For certification I point you to accredited bodies.

Email me at [email protected] with a couple of lines of context. I reply within a few business days with a concrete proposal, or a polite no if it's not my scope.

Want to be notified when I update this page?

The EN RSS feed flags every update to main essays. For direct conversation, reach me at [email protected].

Questions & answers

Which European regulations affect software in 2026–2028?

Six: Cyber Resilience Act (CRA), AI Act, Product Liability Directive (PLD), NIS2, European Accessibility Act (EAA), DORA (sectoral, finance). They enter into force at different moments between 2024 and 2028 but their cumulative effect redesigns European software architecture.

Is compliance a legal or an engineering problem?

Both, but the engineering side gets systematically underrated. These regulations are system constraints — feature delivery deadlines (logs, audit, SBOM, accessibility) with a mandatory date. Treating them as red tape to be handled at project end costs 5-10× more than designing them in from the start.

Who is affected by the Cyber Resilience Act?

Any ‘product with digital elements’ sold on the EU market: commercial software, firmware, connected devices, SDKs. Many SaaS products fall under this umbrella. The first wave of obligations (incident reporting) kicks in September 2026, the bulk in December 2027.

My software isn't AI — does the AI Act still apply?

Possibly yes. The AI Act applies to providers of systems that integrate third-party AI (OpenAI, Claude, Gemini APIs) and to ‘deployer’ roles — whoever uses AI to make decisions about people (HR, credit, welfare). Deadlines run from February 2025 through August 2028: after the June 2026 Digital Omnibus, high-risk obligations apply from 2 December 2027 (Annex III) and 2 August 2028 (AI embedded in regulated products); the rest of the calendar is confirmed.

Can I start later, once there are more examples?

No. Design-in compliance requires architectural choices (logging, data retention, SBOM, accessibility) that become very expensive to retrofit. Those who wait ‘to see how others do it’ pay twice.

© 2026 Andrea Margiovanni Made with care, by hand