eu-compliance-directives

Curated index of official EU and national (member state) compliance sources, including directives, transposition laws, and regulatory guidance. ACTIVATE when answering questions about EU regulations or national implementations (NIS2, GDPR, DORA, AI Act, Cyberbeveiligingswet, etc.) — especially differences between EU directives and local laws, applicability, enforcement, timelines, or legal obligations. Also activate for conceptual or comparative questions ("what changed", "how does NL differ from the EU directive"). Always verify current legal status and ground answers in authoritative sources instead of relying on general knowledge.

EU Compliance Directives & National Transpositions

Don't hardcode compliance facts that change. Look them up. EU directives become national law differently in each member state — always check both levels.

Key concept: directives vs regulations

TypeWhat it meansExample
RegulationDirectly applicable in all member states. No transposition needed.GDPR, DORA, AI Act
DirectiveMust be transposed into national law. Each country may implement differently.NIS2 → Cyberbeveiligingswet (NL), NIS2UmsuCG (DE), etc.

When a user asks about a directive, always consider both the EU-level text AND the national transposition. They can differ on scope, penalties, and sector definitions.

Source index

EU-level sources

ECSO NIS2 Transposition Tracker

EC Digital Strategy

EUR-Lex

ENISA Technical Guidance

  • URL: https://www.enisa.europa.eu/publications
  • Maintainer: EU Agency for Cybersecurity
  • Reliability: HIGH
  • Use for: Practical implementation guidance for NIS2 Art. 21, risk management, incident reporting
  • Limitations: Guidance, not binding

ENISA NIS2 Technical Implementation Guidance (June 2025, v1.0)

EU ICT Supply Chain Security Toolbox (NIS Cooperation Group, Jan 2026)

EDPB Guidelines (GDPR)

EU AI Office

  • URL: https://digital-strategy.ec.europa.eu/en/policies/ai-office
  • Maintainer: European Commission
  • Reliability: HIGH
  • Use for: AI Act implementation timeline, codes of practice, high-risk classification
  • Phased entry: Feb 2025 (prohibited) → Aug 2025 (GPAI) → Aug 2026 (high-risk Annex III) → Aug 2027 (Annex I)

ESA Guidance (DORA)

  • Maintainer: EBA, EIOPA, ESMA (jointly)
  • Use for: DORA regulatory technical standards (RTS), implementing technical standards (ITS)
  • In force: January 2025

National sources

Netherlands

SourceURLUse for
Cyberbeveiligingswet (Cbw)wetten.overheid.nlNIS2 transposition — Dutch national law
NCSC-NLncsc.nlGuidance, self-assessment, incident reporting
Autoriteit Persoonsgegevensautoriteitpersoonsgegevens.nlGDPR supervision, breach reporting

Germany

SourceURLUse for
NIS2UmsuCGbsi.bund.deNIS2 transposition — German national law
BSI IT-Grundschutzbsi.bund.deBaseline protection catalogue, KRITIS
OpenKRITISopenkritis.deCommunity resource for KRITIS implementation

Belgium

SourceURLUse for
CCB CyFunccb.belgium.beBelgian Cybersecurity Framework, NIS2 mapping
Centre for Cybersecurity Belgiumccb.belgium.beNational authority, guidance

Bird & Bird NIS2 Tracker (multi-country)

EU_compliance_MCP — pre-indexed regulation database

  • Install: npx @ansvar/eu-regulations-mcp or add as MCP server
  • Source: https://github.com/Ansvar-Systems/EU_compliance_MCP
  • Reliability: HIGH (sourced from EUR-Lex)
  • Coverage: 49 EU regulations, 2,500+ articles, 1,200+ definitions, full-text search
  • Use for: Instant article/recital retrieval, cross-regulation comparison, control mappings
  • When available: Prefer over web lookups for article text — faster and offline-capable

Agent lookup workflow

For EU-level questions (regulations, general obligations)

  1. EUR-Lex — authoritative legislative text
  2. ENISA / EDPB / ESA — practical guidance per regulation
  3. EU_compliance_MCP — if available, use for instant article lookup and cross-regulation comparison
  4. Always include a freshness warning — compliance status changes

For national implementation questions (transposition, local differences)

  1. ECSO tracker — which countries have transposed, links to national laws
  2. National source — check the specific country's authority (NCSC-NL, BSI, CCB, etc.)
  3. Cross-reference EUR-Lex — compare directive text with national implementation
  4. Flag differences — explicitly tell the user where national law adds to or differs from the EU directive

For comparative questions ("how does X differ from Y")

  1. Identify both sources (EU directive + national law, or two national laws)
  2. Use EUR-Lex for the EU baseline
  3. Use national sources for local specifics
  4. Present a clear comparison: what's the same, what differs, what's stricter

Agent instructions

  1. Never state transposition status or legal facts from memory — always direct the user to check the source.
  2. Use the lookup workflow above to guide which source to check first.
  3. Include the source URL and a freshness warning in every response.
  4. If a user needs country-specific detail, check the ECSO tracker and the relevant national authority.
  5. For practical "how to comply" questions, point to ENISA guidance (NIS2), EDPB guidelines (GDPR), or ESA standards (DORA).
  6. For legal text, point to EUR-Lex.
  7. When comparing EU directive vs national law, always flag where the national implementation is stricter or broader than the directive minimum.
  8. If the user's org profile includes a jurisdiction, prioritise sources for that country.