Support
Short, well-founded answers to the questions we hear most often from EU organisations.
Questions & answers
It depends on the sector and size of the organisation. NIS2 covers medium-sized and large entities in the sectors listed in its two annexes, and certain entities regardless of size. Obligations arise from each national transposing law, such as Decree-Law 125/2025 in Portugal. A Compliance Assessment determines whether you are an essential or an important entity, and which obligations apply. See Cybersecurity (NIS2).
Under Directive (EU) 2019/1937, private entities with 50 or more workers and public-sector entities must have internal reporting channels, subject to the exemptions some Member States allow for small municipalities and entities. Reports must be acknowledged within seven days and followed up with feedback within three months. See Whistleblower Protection.
Regulation (EU) 2026/1744, in force since 27 July 2026, postponed the high-risk obligations to 2 December 2027 for Annex III systems and to 2 August 2028 for systems embedded in regulated products. Prohibitions, AI literacy and the rules on general-purpose AI already apply, and the transparency obligations of Article 50 apply from 2 August 2026. See Artificial Intelligence.
Yes, if you are a public authority or body, or if your core activities involve large-scale regular and systematic monitoring or large-scale processing of special categories of data (GDPR, Article 37). Other organisations may appoint one voluntarily. The role can be performed under a service contract. See Data Protection.
From 10 July 2027, Regulation (EU) 2024/1624 largely harmonises national rules through a single EU rulebook, while Directive (EU) 2024/1640 is transposed nationally for supervision and registers. The Regulation requires a member of the management body to be responsible for compliance and a compliance officer of sufficient seniority, and sets a EUR 10,000 limit on cash payments. AMLA will directly supervise selected institutions from 2028. See Anti-Money Laundering.
Yes. Directive (EU) 2026/1021 on combating corruption was published in May 2026 and must be transposed by 1 June 2028. It harmonises offences, establishes the liability of legal persons and treats effective compliance programmes as a mitigating factor. National regimes, such as Portugal's RGPC, already require compliance programmes. See Anti-Corruption.
Following Directive (EU) 2026/470, CSRD reporting applies to EU companies with more than 1,000 employees and more than EUR 450 million in turnover, and to certain non-EU groups. Smaller companies are outside the mandatory scope but will continue to receive requests from customers and banks. See Sustainability.
Under Directive (EU) 2023/970, employers with 150 or more workers must report by 7 June 2027, and employers with 100 to 149 workers by 7 June 2031. National laws may set lower thresholds. See Pay Transparency.
In many cases, yes. The fractional model provides an experienced, independent Compliance Officer on retainer and is well suited to SMEs and public bodies. Some roles must be held within the organisation, such as the AML compliance manager or, in Portugal, the person responsible for regulatory compliance under the RGPC, so the model supports those persons rather than replacing them. See Fractional Compliance Officer.
You request a proposal, we send a tailored offer, and once the order is confirmed and invoiced, access to the Office is activated for the users you indicate. See Services & Products.