Regulatory watch
What changed, and which controls it touches
Tracked obligations across security, financial services, privacy and sustainability, mapped to the controls they affect.
Recent updates
Regulatory updates from our team
- EU · Financial services
DORA oversight expectations for critical ICT providers
Register of information detail, exit planning and threat-led penetration testing obligations.
- EU · Cross-sector
NIS2 national transpositions and reporting deadlines
Incident notification windows and management accountability provisions to reflect in policy.
- EU · Sustainability
CSRD phase-in and ESRS data point sequencing
Which disclosures apply in which reporting year, and where assurance readiness usually slips.
- Global · Payments
PCI DSS 4.0 future-dated requirements now in force
Targeted risk analyses, authentication changes and evidence expectations for assessors.
- Global · AI
ISO 42001 and emerging AI governance obligations
Building an AI management system that satisfies both customers and forthcoming statute.
More resources
Other collections
Turn the reading into a working programme.
Book a demo and we will show how these practices run inside TrustsComply.