Operations | Monitoring | ITSM | DevOps | Cloud

What Is DORA Compliance? The Digital Operational Resilience Act Explained

The Digital Operational Resilience Act has applied to EU financial firms since 17 January 2025. The first year was mostly paperwork. In year two, supervisors want proof, and most of that proof sits with IT operations. DORA joins the other rules on your cybersecurity compliance list, with much tighter clocks. A major incident needs its first report within 4 hours of classification. In this blog, you will: By the end, you will know what DORA compliance asks of your IT team and where to begin.

EU AI Act 2026: delay, new deadlines & article 73 reporting

On July 27, 2026, the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force and rewrote the EU AI Act's timeline. The high-risk obligations that were due to apply on August 2, 2026, including Article 73 serious-incident reporting, now apply from December 2, 2027 for standalone high-risk systems (Annex III) and August 2, 2028 for AI embedded in regulated products (Annex I). Not everything moved.

The Cloud Repatriation Bill: What UK Businesses Didn't Budget for and How to Control Cost

Half of organisations spent more on public cloud than they had planned for last year. According to IDC research, reported by ITPro, 59% expect the same to happen again this year. That gap between what businesses expect to spend and what they actually spend is usually what starts the repatriation conversation. It is also where the next miscalculation begins.

Digital ID Arrives at the Till: What the Alcohol Rule Change Means for Checkout Integrations

For years, proof of age at an alcohol till in England and Wales meant something you could hold in your hand: a passport, a photocard driving licence, a PASS card. That's no longer the whole list. Since mid-September 2026, licensed premises can accept certified digital proof of age from a customer's phone.

You probably already have most of what CRA requires

CRA compliance is similar to other frameworks, like ISO 27001, SOC 2, GDPR, or PCI DSS, in that the same approach applies: define your scope, figure out your product classification, then work through the list of controls. This video covers why that's less daunting than it sounds: CRA compliance isn't a one-time milestone. If you're selling into Europe, you need to continuously meet it.

December 2026 Is the Wallet Deadline. The Harder Question Is What Companies Do With What Comes Out of It

Every EU member state has to offer at least one European Digital Identity Wallet. Regulation (EU) 2024/1183 sets the obligation, and the implementing regulations apply from 24 December 2026. Most coverage has focused on the citizen side: one app, national ID inside, log in anywhere in Europe. The business side has had less attention, and it's the side that involves work.

The Cyber Resilience Act isn't just for hardware

There's a common assumption that the EU Cyber Resilience Act is a hardware and IoT manufacturer concern. Actually, it affects any SaaS company selling into the EU too, and that's a gap in awareness worth closing. This video covers what the CRA is actually there to do and what it means for your own software supply chain: Securing your customers' supply chain starts with being able to account for your own.

Building Quality and Compliance Systems That Hold Up to an FDA Inspection

For any company operating in an FDA-regulated industry, the inspection is the moment of truth. It is when the quality and compliance systems a company has built, or failed to build, are examined by investigators trained to find exactly the gaps a company hopes it does not have. A successful inspection reflects systems that were designed to withstand scrutiny; a difficult one, with findings and follow-up, reflects systems that were not. The difference is rarely luck. It comes down to whether a company has built genuine, robust quality and compliance systems well before an inspector ever arrives.

NYDFS Part 500 Asset Inventory Requirements: How Technology Can Support Section 500.13

Financial-services organizations may already have multiple tools telling them what exists across their environment. The problem is that those tools do not always agree. An endpoint platform may recognize a device that a vulnerability scanner does not. A network system may identify an active device that is missing from another asset record. The same device may even appear under multiple names across different platforms. That creates a simple but important question: Which view can you trust?

The EU Is Starting to Put Labels on the Synthetic Internet

It's getting harder and harder to distinguish between content produced by people and content produced by machines on the internet. AI can now create convincing articles, images, audio and video that may not be immediately recognized as being AI-generated. Europe has decided that this uncertainty cannot be left to users to deal with on their own. The EU AI Act introduces new transparency obligations, which are beginning to establish a more structured framework for identifying synthetic content.