EU Compliance Regulations Comparison for 2026
Last updated: 29 June 2026
Eight EU regulations now set the compliance workload for most mid-sized European companies, and they share no deadline, no penalty cap and no single enforcer between them. This EU compliance regulations comparison puts GDPR, NIS2, the AI Act, DORA, CSRD, CBAM, the Cyber Resilience Act and EUDR side by side, so a risk or compliance lead can see in one pass which ones bite, when, and how hard. Fines run from GDPR’s €20M floor to the AI Act’s €35M ceiling. Three of the eight changed scope or deadlines across 2025 and 2026, which is the part most existing comparisons quietly get wrong.
2026 is where the calendar got messy. DORA and CBAM both crossed from preparation into live enforcement, the Omnibus packages moved scope and deadlines on part of the rulebook, and the AI Act stays a moving target with fresh timelines for its high-risk systems. Several frameworks reach enforcement milestones inside the same eighteen months, which is why one side-by-side view is worth more this year than it was last.
The EU Compliance Regulations Comparison Shows Eight Different Deadlines
No two of the eight regulations carry the same deadline, penalty cap or enforcer. They split into two families. Five are digital or cyber rules (GDPR, NIS2, the AI Act, DORA and the Cyber Resilience Act). Three are sustainability and supply-chain rules (CSRD, CBAM and EUDR). That split is the first thing the comparison makes obvious, and it is the reason “are we compliant” is never a single question for a company that touches more than one of them.
| Regulation | Who is in scope | Headline 2026 status | Maximum penalty | Enforcer |
|---|---|---|---|---|
| GDPR | Anyone processing EU residents’ personal data, no size threshold | In force since 2018 | €20M or 4% of global turnover | National data protection authorities |
| NIS2 | 18 sectors, medium and large entities (50+ staff or €10M+) | Transposition was due 17 Oct 2024, still incomplete | €10M or 2% (essential); €7M or 1.4% (important) | National authorities and CSIRTs |
| AI Act | Providers and deployers of AI systems, extraterritorial | High-risk rules apply 2 Aug 2026; deferral to 2 Dec 2027 agreed, not yet law | €35M or 7% of global turnover | EU AI Office and national authorities |
| DORA | 20 types of financial entity and their ICT providers | Applies since 17 Jan 2025 | 2% of global turnover; €5M for critical ICT providers | National authorities and the ESAs |
| CSRD | EU firms with 1,000+ staff and €450M+ turnover (post-Omnibus) | New scope applies from FY2027, first reports 2028 | Set per member state (Germany up to €10M or 5%) | National authorities and auditors |
| CBAM | Importers of steel, aluminium, cement, fertilisers, electricity, hydrogen above 50t/yr | Definitive period from 1 Jan 2026 | €100 per excess tonne of CO2 | National authorities and customs |
| CRA | Makers and sellers of products with digital elements | Reporting from 11 Sep 2026; full application 11 Dec 2027 | €15M or 2.5% of global turnover (Article 64) | Market surveillance authorities and ENISA |
| EUDR | Operators and traders in cattle, cocoa, coffee, palm, rubber, soy, wood | Applies 30 Dec 2026 (large and medium operators) | At least 4% of EU-wide turnover | National authorities and customs |
The table is the fast version. Our interactive EU regulation comparison tool lets you filter the same data by sector and company size, so you only see the rules that actually reach you. The rest of this comparison takes the four dimensions that decide real workload, fines, deadlines, scope changes and overlaps, one at a time.
AI Act Fines Reach €35M, GDPR €20M, NIS2 €10M for Essential Entities
The AI Act carries the heaviest fine of the eight, up to €35M or 7% of global annual turnover for prohibited practices, ahead of GDPR’s €20M or 4% and NIS2’s €10M or 2% for essential entities. The numbers are not interchangeable, because they attach to different failures and run off different bases, and reading the headline figure alone will mislead you about your real exposure.
GDPR runs on a two-tier model under Article 83. Procedural breaches cap at €10M or 2%, substantive ones at €20M or 4%, whichever is higher. The AI Act’s €35M ceiling applies only to the banned practices in Article 5; ordinary high-risk non-compliance caps lower, at €15M or 3% under Article 99. NIS2 separates essential entities (€10M or 2%) from important ones (€7M or 1.4%) and bolts on personal accountability for management bodies under Article 20, which is the part that tends to focus a board. DORA does not lead with a euro figure for financial entities at all. It caps at 2% of total annual worldwide turnover and reserves a fixed €5M specifically for critical ICT third-party providers. CBAM and EUDR break the pattern entirely. CBAM charges €100 for every excess tonne of CO2 you fail to cover with certificates, and EUDR sets a floor rather than a ceiling, at least 4% of EU-wide turnover plus product confiscation and procurement bans. In our assessment EUDR’s “at least” wording is the one most companies underweight, because it is the only penalty in the set with no stated maximum.
If your exposure sits with the AI Act, our AI Act fines calculator turns those percentage caps into a euro figure for your turnover and risk tier.
The 2025 and 2026 Omnibus Packages Cut CSRD Scope by Roughly 80 Percent
Three of the eight regulations changed across 2025 and 2026, and the largest change shrank CSRD. The Omnibus I Directive lifted the reporting threshold to more than 1,000 employees and more than €450M net turnover, a change the Commission estimated lifts about 80% of companies out of CSRD’s scope. The Council gave its final sign-off on 24 February 2026, and the amending directive was published as Directive (EU) 2026/470, with new-scope obligations now starting from financial years beginning 1 January 2027 and first reports due in 2028. If your company was preparing its first CSRD report and sits under 1,000 staff, the most useful thing you can do this quarter is confirm you are now out, before you spend another euro on it.
CBAM entered its definitive, paying phase on 1 January 2026 under Regulation (EU) 2025/2083, with a single de minimis threshold of 50 tonnes per year that lifts most small importers out while keeping almost all embedded emissions in scope. EUDR slipped again. A second delay under Regulation (EU) 2025/2650 pushed application to 30 December 2026 for large and medium operators and 30 June 2027 for the smallest. The deforestation rules have now been postponed twice, so the teams who scrambled to hit the original 2024 date have spent eighteen months ready for a deadline that keeps walking away from them.
The AI Act sits in a different state, and this is the one to read carefully. A Digital Omnibus deal agreed in May 2026, which the European Parliament approved on 16 June 2026 by 423 votes to 57, would push high-risk Annex III obligations from 2 August 2026 to 2 December 2027. As of 29 June 2026 it is not yet law. Council formal adoption and Official Journal publication are still outstanding, and until the text is published, 2 August 2026 remains the operative date, with the Article 50 transparency duties and the AI literacy obligation not deferred at all. The EU is, in effect, racing to adopt before 2 August 2026 a law whose main purpose is to move 2 August 2026, and if it misses, the original date stands. You can track every confirmed date across all eight regulations in our EU compliance deadline tracker.
For the other half of the picture, which regulations have actually issued fines and which have not, see the EU regulatory enforcement tracker.The Omnibus did cut direct regulatory burden for a lot of companies, CSRD most of all. It also created new uncertainty, because the AI Act’s key dates are still moving and a company cannot easily tell whether to accelerate its preparation or wait. None of that means less work. At a company of around 200 people the priorities just reshuffle. If CSRD drops away, GDPR, NIS2, the AI Act and, where relevant, DORA or CBAM are still there, which is the argument for building one unified compliance programme rather than a separate project per regulation.
NIS2 and DORA Overlap, and DORA Wins for Financial Firms
Where NIS2 and DORA both apply, DORA takes precedence. DORA is lex specialis to NIS2 for financial entities, so a bank or insurer follows DORA’s rules on ICT risk management and incident reporting and falls back to NIS2 only for the gaps DORA does not cover. This is set out in NIS2 Article 4 and confirmed in DORA’s recitals, which means financial firms are not subject to both regimes for the same obligation. The trap is assuming the carve-out is total. It covers ICT risk management and ICT incident reporting, not every NIS2 duty, so a financial entity is not simply exempt from NIS2 across the board.
The overlap bites because the reporting clocks disagree. DORA wants an initial notification within four hours of classifying an incident as major, NIS2 sets a 24-hour early warning, and GDPR allows 72 hours for a personal data breach. A single incident at a financial firm can start several of these clocks at once, and add a compromised AI system and the AI Act’s reporting duty joins the queue. Not one of them agrees on what counts or when the count begins.
This is also where member-state variation shows up most, which matters if you operate in more than one country. NIS2 is a directive, so each country writes it into its own law, and by mid-2026 most had, with France, Ireland, the Netherlands and Spain among those still finishing in their legislative procedures. Counts differ depending on whether you measure adopted primary law or full notification to the Commission, which is why two trackers rarely agree on the exact number. The Commission added another moving part on 20 January 2026, proposing targeted NIS2 amendments it says will ease compliance for 28,700 companies. To check whether NIS2 reaches your organisation, our NIS2 applicability checker runs the sector and size tests, and our DORA compliance assessment does the same for the financial scope.
Knowing Which Regulations Apply to You Comes Before Any Deadline
The most useful first move does not depend on any single deadline. Map which of the eight regulations actually reach your organisation, by sector and by size, before you plan around dates. Most of the 2026 pressure comes from rules a company did not realise applied to it, not from a date it saw coming and missed.
Start with the cyber and data cluster, because it is the broadest. GDPR catches almost anyone handling personal data. NIS2 reaches medium and large entities across 18 sectors, with the 50-employee or €10M turnover floor as the trigger, and you also need to know whether your national NIS2 law is yet in force where you operate. DORA captures financial entities and, importantly, their ICT suppliers, so a software vendor to a bank can be pulled in without ever calling itself a financial firm. For AI, build the inventory and classify every system against Annex III. That work does not get easier with time, and the 2 December 2027 deferral, if it becomes law, is time to prepare, not time to wait. Article 50 transparency and AI literacy still apply from 2 August 2026 regardless. Then test the sustainability and supply-chain cluster against the post-Omnibus thresholds, because the company that was in CSRD scope for FY2024 may now be out, the importer that ignored CBAM may now be over the 50-tonne line, and EUDR’s large and medium operators face 30 December 2026. Once the map is built, the dates take care of themselves, and the EU compliance deadline tracker holds the confirmed ones in one place.
For a company of around 200 people the first step is almost trivial. Do a proper scope mapping first. Work out which regulations actually apply to you by sector, size, customers and supply chain, and only then build the timeline and the projects. In our assessment that buys more than waiting for new standards to land or chasing a single deadline. Most mistakes come from a company misjudging which obligations apply to it at all, not from missing one specific date.
Use our free EU regulation comparison tool to filter all eight by your sector and headcount in one pass. And if your sharpest question is the AI Act, take our free AI Act Readiness Assessment to see which obligations reach you and when.
One monthly email. EU regulatory intelligence for compliance and risk teams, from the people who read the 47 pages so you don’t have to. Subscribe at regdossier.eu.
RegDossier
Making EU compliance almost enjoyable. Almost.
EU regulatory updates in your inbox every two weeks. Free.
Get the next briefing