Support

EU Regulation & National Transposition

Map of the key EU instruments framing the compliance function, their current status and how they apply in the Member States.

The regulatory map, as of October 2026

For each domain: the EU instrument, its current status and how it applies in the Member States. Follow the links for the full domain page.

  • Data Protection: Regulation (EU) 2016/679 (GDPR); fully in force; directly applicable and complemented by national laws, such as Law 58/2019 in Portugal and Organic Law 3/2018 in Spain;

  • Cybersecurity (NIS2): Directive (EU) 2022/2555; transposition was due by 17 October 2024; in Portugal, Decree-Law 125/2025, in force since 3 April 2026;

  • Digital Operational Resilience: Regulation (EU) 2022/2554 (DORA); applicable since 17 January 2025 to financial entities; oversight of critical ICT providers since November 2025;

  • Artificial Intelligence: Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744; prohibitions, AI literacy and general-purpose AI rules apply; high-risk obligations from 2 December 2027 and 2 August 2028;

  • Whistleblower Protection: Directive (EU) 2019/1937; transposed nationally, for example by Law 93/2021 in Portugal and Law 2/2023 in Spain; mandatory channels from 50 workers;

  • Anti-Money Laundering: Regulation (EU) 2024/1624 and Directive (EU) 2024/1640; single rulebook from 10 July 2027; AMLA operational since 2025; national laws apply until then;

  • Anti-Corruption: Directive (EU) 2026/1021; to be transposed by 1 June 2028; national regimes already apply, such as the RGPC in Portugal;

  • Sustainability (CSRD/CSDDD): Directives (EU) 2022/2464 and 2024/1760, amended by Directive (EU) 2026/470; CSRD amendments to be transposed by 19 March 2027; CSDDD applies from 26 July 2029;

  • Pay Transparency: Directive (EU) 2023/970; transposition was due by 7 June 2026 and is still under way in most Member States; first reports in 2027;

  • Corporate Governance: Directives (EU) 2017/828 and 2022/2381, and the audit reform; national company law and governance codes;

  • Third-Party & Supply Chain: CSDDD, NIS2, DORA, GDPR and AML due-diligence requirements; applied through each instrument;

  • Digital Services & Markets: Regulations (EU) 2022/2065 (DSA) and 2022/1925 (DMA); directly applicable; Commission and national Digital Services Coordinators.

Keep it current

This map is reviewed regularly. To receive the changes as they happen, subscribe to the Regulatory Alerts. For the legal nature of each instrument, see the EU Legal Order.

The information is indicative and does not constitute legal advice. Confirm the applicable requirements with the competent authorities and the official texts on EUR-Lex and the national official gazettes.