1---2name: eu-compliance-directives3description: Curated index of official EU and national (member state) compliance sources, including directives, transposition laws, and regulatory guidance. ACTIVATE when answering questions about EU regulations or national implementations (NIS2, GDPR, DORA, AI Act, Cyberbeveiligingswet, etc.) — especially differences between EU directives and local laws, applicability, enforcement, timelines, or legal obligations. Also activate for conceptual or comparative questions ("what changed", "how does NL differ from the EU directive"). Always verify current legal status and ground answers in authoritative sources instead of relying on general knowledge.4---56# EU Compliance Directives & National Transpositions78> Don't hardcode compliance facts that change. Look them up. EU directives become national law differently in each member state — always check both levels.910## Key concept: directives vs regulations1112| Type | What it means | Example |13|---|---|---|14| **Regulation** | Directly applicable in all member states. No transposition needed. | GDPR, DORA, AI Act |15| **Directive** | Must be transposed into national law. Each country may implement differently. | NIS2 → Cyberbeveiligingswet (NL), NIS2UmsuCG (DE), etc. |1617When a user asks about a directive, always consider both the EU-level text AND the national transposition. They can differ on scope, penalties, and sector definitions.1819## Source index2021### EU-level sources2223#### ECSO NIS2 Transposition Tracker2425- **URL**: https://ecs-org.eu/activities/nis2-transposition-tracker/26- **Maintainer**: European Cyber Security Organisation27- **Reliability**: HIGH28- **Use for**: Per-country transposition status, timeline, national legislation links29- **Limitations**: May lag behind official notifications by days3031#### EC Digital Strategy3233- **URL**: https://digital-strategy.ec.europa.eu/en/policies/nis-transposition34- **Maintainer**: European Commission35- **Reliability**: HIGH36- **Use for**: Official notification status per member state37- **Limitations**: Less detail than ECSO tracker3839#### EUR-Lex4041- **URL**: https://eur-lex.europa.eu42- **Maintainer**: Publications Office of the EU43- **Reliability**: HIGH (authoritative)44- **Key URLs**:45 - NIS2: https://eur-lex.europa.eu/eli/dir/2022/255546 - GDPR: https://eur-lex.europa.eu/eli/reg/2016/67947 - DORA: https://eur-lex.europa.eu/eli/reg/2022/255448 - AI Act: https://eur-lex.europa.eu/eli/reg/2024/168949- **Use for**: Full legislative text, recitals, annexes, transposition notices5051#### ENISA Technical Guidance5253- **URL**: https://www.enisa.europa.eu/publications54- **Maintainer**: EU Agency for Cybersecurity55- **Reliability**: HIGH56- **Use for**: Practical implementation guidance for NIS2 Art. 21, risk management, incident reporting57- **Limitations**: Guidance, not binding5859#### ENISA NIS2 Technical Implementation Guidance (June 2025, v1.0)6061- **URL**: https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance62- **PDF**: https://www.enisa.europa.eu/sites/default/files/2025-06/ENISA_Technical_implementation_guidance_on_cybersecurity_risk_management_measures_version_1.0.pdf63- **Reliability**: HIGH64- **Use for**: Per-requirement guidance and auditor-accepted evidence examples for all 13 NIS2 Art. 21(2) domains65- **Scope**: Legally binds ICT-type entities only (DNS, TLDs, cloud, data centres, CDN, MSPs/MSSPs, online platforms, trust services). Useful reference for all NIS2 entities6667#### EU ICT Supply Chain Security Toolbox (NIS Cooperation Group, Jan 2026)6869- **URL**: https://digital-strategy.ec.europa.eu/en/library/toolbox-improve-ict-supply-chain-security70- **Maintainer**: NIS Cooperation Group (Member States + Commission + ENISA)71- **Reliability**: HIGH72- **Use for**: 11 ICT supply chain risk scenarios + 7 recommendations (R01-R07) supporting NIS2 Art. 21(2)(d)7374#### EDPB Guidelines (GDPR)7576- **URL**: https://edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en77- **Maintainer**: European Data Protection Board78- **Reliability**: HIGH79- **Use for**: GDPR interpretation, cross-border enforcement, binding decisions80- **Supervisory authorities**: https://edpb.europa.eu/about-edpb/about-edpb/members_en8182#### EU AI Office8384- **URL**: https://digital-strategy.ec.europa.eu/en/policies/ai-office85- **Maintainer**: European Commission86- **Reliability**: HIGH87- **Use for**: AI Act implementation timeline, codes of practice, high-risk classification88- **Phased entry**: Feb 2025 (prohibited) → Aug 2025 (GPAI) → Aug 2026 (high-risk Annex III) → Aug 2027 (Annex I)8990#### ESA Guidance (DORA)9192- **Maintainer**: EBA, EIOPA, ESMA (jointly)93- **Use for**: DORA regulatory technical standards (RTS), implementing technical standards (ITS)94- **In force**: January 20259596### National sources9798#### Netherlands99100| Source | URL | Use for |101|---|---|---|102| **Cyberbeveiligingswet (Cbw)** | wetten.overheid.nl | NIS2 transposition — Dutch national law |103| **NCSC-NL** | ncsc.nl | Guidance, self-assessment, incident reporting |104| **Autoriteit Persoonsgegevens** | autoriteitpersoonsgegevens.nl | GDPR supervision, breach reporting |105106#### Germany107108| Source | URL | Use for |109|---|---|---|110| **NIS2UmsuCG** | bsi.bund.de | NIS2 transposition — German national law |111| **BSI IT-Grundschutz** | bsi.bund.de | Baseline protection catalogue, KRITIS |112| **OpenKRITIS** | openkritis.de | Community resource for KRITIS implementation |113114#### Belgium115116| Source | URL | Use for |117|---|---|---|118| **CCB CyFun** | ccb.belgium.be | Belgian Cybersecurity Framework, NIS2 mapping |119| **Centre for Cybersecurity Belgium** | ccb.belgium.be | National authority, guidance |120121#### Bird & Bird NIS2 Tracker (multi-country)122123- **URL**: https://www.twobirds.com/en/insights/2023/global/nis2-tracker124- **Reliability**: MEDIUM (commercial, law firm)125- **Use for**: Quick visual overview of transposition status across all EU countries126127### EU_compliance_MCP — pre-indexed regulation database128129- **Install**: `npx @ansvar/eu-regulations-mcp` or add as MCP server130- **Source**: https://github.com/Ansvar-Systems/EU_compliance_MCP131- **Reliability**: HIGH (sourced from EUR-Lex)132- **Coverage**: 49 EU regulations, 2,500+ articles, 1,200+ definitions, full-text search133- **Use for**: Instant article/recital retrieval, cross-regulation comparison, control mappings134- **When available**: Prefer over web lookups for article text — faster and offline-capable135136## Agent lookup workflow137138### For EU-level questions (regulations, general obligations)1391401. **EUR-Lex** — authoritative legislative text1412. **ENISA / EDPB / ESA** — practical guidance per regulation1423. **EU_compliance_MCP** — if available, use for instant article lookup and cross-regulation comparison1434. **Always include a freshness warning** — compliance status changes144145### For national implementation questions (transposition, local differences)1461471. **ECSO tracker** — which countries have transposed, links to national laws1482. **National source** — check the specific country's authority (NCSC-NL, BSI, CCB, etc.)1493. **Cross-reference EUR-Lex** — compare directive text with national implementation1504. **Flag differences** — explicitly tell the user where national law adds to or differs from the EU directive151152### For comparative questions ("how does X differ from Y")1531541. Identify both sources (EU directive + national law, or two national laws)1552. Use EUR-Lex for the EU baseline1563. Use national sources for local specifics1574. Present a clear comparison: what's the same, what differs, what's stricter158159## Agent instructions1601611. Never state transposition status or legal facts from memory — always direct the user to check the source.1622. Use the lookup workflow above to guide which source to check first.1633. Include the source URL and a freshness warning in every response.1644. If a user needs country-specific detail, check the ECSO tracker and the relevant national authority.1655. For practical "how to comply" questions, point to ENISA guidance (NIS2), EDPB guidelines (GDPR), or ESA standards (DORA).1666. For legal text, point to EUR-Lex.1677. When comparing EU directive vs national law, always flag where the national implementation is stricter or broader than the directive minimum.1688. If the user's org profile includes a jurisdiction, prioritise sources for that country.