Key takeaways
- The five biggest compliance risks are regulatory blind spots, evidence gaps, supply chain exposure, framework silos, and missing AI governance.
- NIS2 has applied since 18 October 2024, but your obligations come from national law. Germany's BSIG has applied since 6 December 2025 with no transition period, and its registration deadlines expired on 6 March 2026 and 31 July 2026.
- The Digital Omnibus, Regulation (EU) 2026/1744, moved the EU AI Act's Annex III high-risk obligations to 2 December 2027. The transparency obligations took effect on 2 August 2026 as originally scheduled.
- Cyber Resilience Act reporting under Art. 14 starts on 11 September 2026, 15 months before the regulation applies in full on 11 December 2027.
- Most audit findings come from missing evidence for controls that already exist, not from missing controls.
Compliance risks are no longer mainly a question of fines. They are a question of whether you can prove your position on a given day. Nobody in a procurement review, a certification audit, or a supervisory inspection asks whether controls exist. They ask what the state of play was on the day of an incident. That is where most programs come apart, and it happens in the same five places every time.
2026 did not replace those five risks. It sharpened them. NIS2 is now national law in most member states, the Cyber Resilience Act brings reporting duties into your product supply chain, and under the EU AI Act one set of obligations was postponed while another was not. The table below orders the five; the sections that follow work through each one.
Risk 1: Regulatory blind spots
The most expensive compliance risk is an obligation nobody in the building noticed. It rarely comes from negligence. It comes from pace: in 2026 several European deadlines moved at once, and they moved in different directions.
Directive (EU) 2022/2555 has applied since 18 October 2024, but it names no obligations you can comply with directly. Your duties come from whichever national law implements it where you are established. Germany is the clearest example. The NIS2 implementation act folded the directive into the BSIG, which has applied since 6 December 2025 with no transition period. Registration under section 33 BSIG was legally due within three months, so by 6 March 2026, and the BSI allowed a grace period to 31 July 2026. Both dates have passed. A company that is still unregistered is not running late, it is in breach. How the directive and national law fit together is covered in our guide to the NIS2 Directive.
Elsewhere the picture is uneven. On 8 July 2026 the Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to transpose NIS2. If you are established in more than one member state, your obligations differ per country, and so does the authority you report to.
A common misconception: many teams read in July 2026 that the EU AI Act's high-risk rules had been delayed and concluded that nothing happened on 2 August 2026. That is wrong. The Digital Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the obligations for stand-alone Annex III high-risk systems from 2 August 2026 to 2 December 2027, and those for Annex I systems embedded in regulated products to 2 August 2028. The Art. 50 transparency obligations became applicable on 2 August 2026 as planned, along with the labeling duties for AI-generated content. Two new prohibited practices apply from 2 December 2026.
On data protection the reverse holds. The second Digital Omnibus, which would amend the GDPR, has been on the table since 19 November 2025 and is still in first reading. It is not law. Anyone deferring work today on the argument that the GDPR is being relaxed is following a draft instead of the GDPR.
How to reduce the risk: name an owner for monitoring each jurisdiction you operate in, and log every new obligation with the date it was spotted, the assessment, and the assignment. What a supervisory authority wants to see later is not the obligation itself, it is your decision about it.
Risk 2: Evidence gaps, not missing controls
Most audit findings arise not because a control is missing but because its effectiveness cannot be proven. The practice is sound and the documentation is not: an expired policy version, a restore test nobody recorded, an exception approved verbally.
The law targets exactly that gap. Art. 21(2) NIS2 lists ten risk-management measures, and point (f) requires policies and procedures to assess whether those measures are actually working. That is a separate obligation from the measure itself. Running access control is not enough. You have to be able to show that you tested whether it works, when you tested it, and what the test returned.
ISO 27001 works the same way. The 2022 revision contains 93 controls in Annex A across four themes: 37 organizational, 8 people, 14 physical, and 34 technological. Most organizations select 60 to 80 of them. An auditor does not check whether a control is documented, but whether it operated throughout the audit period. Which controls those are in detail is covered in our overview of the ISO 27001 controls.
A worked example: a 45-person SaaS company has run its ISMS for 14 months. Policies are in place, MFA is enforced everywhere, backups run nightly. The certification audit produces three findings: the last documented restore test is 11 months old, two people who left in spring have no offboarding evidence, and MFA is recorded as a policy but was never evidenced out of the identity system. None of the three concerns a missing control. All three concern missing evidence.
How to reduce the risk: collect evidence continuously from the systems you already run instead of gathering it before an audit. History is the feature that matters. Evidence that shows only today's state does not answer the question of what the state was eight months ago.
Risk 3: Supply chain and vendor risk
Your liability does not stop at your own firewall. Art. 21(2)(d) NIS2 requires measures covering supply chain security, explicitly including the security of the relationships between you and your direct suppliers or service providers. That is an ongoing assessment, not a questionnaire completed at contract signature.
In 2026 a second layer arrives. Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents under Art. 14: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days of a corrective measure being available. Full application follows on 11 December 2027. For you as a buyer, that means your software and hardware vendors acquire reporting duties of their own from September 2026, and what they report concerns products running in your environment. Which product classes are affected is set out in our piece on the Cyber Resilience Act's impact on product development.
A common misconception: a signed data processing agreement is often treated as security evidence. It is not. A DPA under Art. 28 GDPR sets out obligations and instruction rights; it does not demonstrate that the processor meets them. What a data protection officer actually looks for is set out in our guide to the data processing agreement review.
How to reduce the risk: keep a vendor register with a criticality tier, an assessment result, and the next review date, and link questionnaire answers back to the measures they are meant to support. A folder of PDFs moves the work, it does not do it.
Risk 4: Framework silos
When each framework is managed separately you pay three times over: duplicated work, controls implemented inconsistently, and no single view of your compliance status. The security gain is zero, because two separately maintained access control policies are not safer than one.
The overlap is substantial. An ISMS certified to ISO 27001 covers a large part of the ten measures in Art. 21(2) NIS2. What it does not cover are the NIS2-specific duties: registration under Art. 27, the reporting deadlines in Art. 23, and the management body evidence required by Art. 20. GDPR and SOC 2 behave similarly. The technical measures required by Art. 32 GDPR and the Trust Services Criteria both draw on controls you already operate for certification.
A common misconception: an additional framework does not automatically mean an additional project. It means a mapping exercise. How ISO 27001, GDPR, and SOC 2 map onto a shared control set is set out in our article on ISO 27001, GDPR, and SOC 2.
How to reduce the risk: maintain one control set and map it to the requirements, rather than running a separate system per framework. Evidence for one tested access control should satisfy the corresponding NIS2 measure, the ISO control, and the SOC 2 criterion at the same time.
Risk 5: AI governance
The fastest-growing compliance risk sits in tools nobody approved. Shadow AI does not arrive through bad intent. A team trials an assistant, connects it to a shared mailbox, and three months later a system is processing personal data while appearing in no inventory anywhere.
The Digital Omnibus postponement changes none of that. What moved were the obligations for Annex III high-risk systems, to 2 December 2027, and for Annex I embedded systems, to 2 August 2028. What did not move are the Art. 5 prohibitions and the Art. 4 AI literacy duty, both applicable since 2 February 2025, the GPAI obligations since 2 August 2025, and the transparency obligations since 2 August 2026. Which systems fall into the high-risk class in the first place is covered in our article on high-risk AI systems under the EU AI Act.
The GDPR applies independently of all of this. Where an AI system processes personal data at high risk, a data protection impact assessment under Art. 35 GDPR is due before deployment, not after the pilot. No postponement touches that obligation.
How to reduce the risk: build the inventory first, classify second. The extra 16 months to December 2027 are time for classification and technical documentation. They are not time to carry on not knowing which AI systems are running in your organization. A company with no inventory today has no basis on which to use the extension at all.
What the five risks have in common
The causes differ, the remedies overlap heavily. First, continuous evidence collection rather than a point-in-time snapshot, because every one of the five gaps becomes visible the moment somebody asks about a past state. Second, clear ownership, because an obligation without an owner is not an obligation, it is a note. Third, a shared control set, because the frameworks overlap far more in substance than the project plans used to implement them.
How Kertos addresses the five risks
Kertos maps GDPR, ISO 27001, NIS2, SOC 2, TISAX, and the EU AI Act onto one shared control set. A measure you implement and test once evidences the corresponding requirement in every framework where it appears. More than 100 integrations pull evidence from the systems your teams already use and attach it to the requirement it supports, which cuts manual compliance effort by around 80 percent.
What the platform does not replace is professional judgment. Whether your measures are appropriate for your risk profile is an assessment, not a calculation. Kertos therefore pairs the platform with certified information security and data protection experts who make that assessment with you and can hold external CISO and data protection officer mandates. Data is stored in Germany.
What that looks like for NIS2 specifically is set out on our NIS2 page.
Frequently asked questions
What are the biggest compliance risks for businesses?
The five most common are regulatory blind spots, meaning obligations spotted too late, evidence gaps, where controls exist but cannot be proven, supply chain risk from service providers and product vendors, framework silos with duplicated work, and missing AI governance. All five surface in an audit or a supervisory review rather than in day-to-day operations.
Why do companies fail audits when the controls are in place?
Because effectiveness cannot be proven. Most findings concern missing, expired, or inconsistent evidence rather than missing controls. Art. 21(2)(f) NIS2 goes further and makes assessing the effectiveness of your measures a separate obligation alongside the measures themselves.
Am I liable for my vendors' compliance failures?
Increasingly, yes. Art. 21(2)(d) NIS2 explicitly requires measures covering the security of the relationships between you and your direct suppliers and service providers. A data processing agreement under Art. 28 GDPR sets out the obligations but does not evidence compliance with them. For that you need an ongoing assessment with review dates.
Were the EU AI Act obligations delayed?
Only in part. Regulation (EU) 2026/1744 was published on 24 July 2026 and moved the Annex III high-risk obligations to 2 December 2027 and the Annex I obligations to 2 August 2028. The prohibitions and the AI literacy duty have applied since 2 February 2025, the GPAI obligations since 2 August 2025, and the transparency obligations since 2 August 2026.
How high are the fines for NIS2 breaches?
Art. 34 NIS2 sets a maximum of at least 10 million euros or 2 percent of total worldwide annual turnover for essential entities, whichever is higher, and 7 million euros or 1.4 percent for important entities. These are floors for national maxima rather than EU-wide caps, so your actual exposure is whatever your member state legislated. In Germany, section 65 BSIG mirrors those levels and adds up to 500,000 euros for failing to register.
If you want to know where your evidence stands today and which of the five gaps is still open, we will work through it with you: request a demo.





