Curated index of official EU and national (member state) compliance sources, including directives, transposition laws, and regulatory guidance. ACTIVATE when answering questions about EU regulations or national implementations (NIS2, GDPR, DORA, AI Act, Cyberbeveiligingswet, etc.) — especially differences between EU directives and local laws, applicability, enforcement, timelines, or legal obligations. Also activate for conceptual or comparative questions ("what changed", "how does NL differ from the EU directive"). Always verify current legal status and ground answers in authoritative sources instead of relying on general knowledge.
EU Compliance Directives & National Transpositions
Don't hardcode compliance facts that change. Look them up. EU directives become national law differently in each member state — always check both levels.
Key concept: directives vs regulations
| Type | What it means | Example |
|---|
| Regulation | Directly applicable in all member states. No transposition needed. | GDPR, DORA, AI Act |
| Directive | Must be transposed into national law. Each country may implement differently. | NIS2 → Cyberbeveiligingswet (NL), NIS2UmsuCG (DE), etc. |
When a user asks about a directive, always consider both the EU-level text AND the national transposition. They can differ on scope, penalties, and sector definitions.
Source index
EU-level sources
ECSO NIS2 Transposition Tracker
EC Digital Strategy
EUR-Lex
- URL: https://eur-lex.europa.eu
- Maintainer: Publications Office of the EU
- Reliability: HIGH (authoritative)
- Key URLs:
- Use for: Full legislative text, recitals, annexes, transposition notices
ENISA Technical Guidance
- URL: https://www.enisa.europa.eu/publications
- Maintainer: EU Agency for Cybersecurity
- Reliability: HIGH
- Use for: Practical implementation guidance for NIS2 Art. 21, risk management, incident reporting
- Limitations: Guidance, not binding
ENISA NIS2 Technical Implementation Guidance (June 2025, v1.0)
EU ICT Supply Chain Security Toolbox (NIS Cooperation Group, Jan 2026)
EDPB Guidelines (GDPR)
EU AI Office
- URL: https://digital-strategy.ec.europa.eu/en/policies/ai-office
- Maintainer: European Commission
- Reliability: HIGH
- Use for: AI Act implementation timeline, codes of practice, high-risk classification
- Phased entry: Feb 2025 (prohibited) → Aug 2025 (GPAI) → Aug 2026 (high-risk Annex III) → Aug 2027 (Annex I)
ESA Guidance (DORA)
- Maintainer: EBA, EIOPA, ESMA (jointly)
- Use for: DORA regulatory technical standards (RTS), implementing technical standards (ITS)
- In force: January 2025
National sources
Netherlands
| Source | URL | Use for |
|---|
| Cyberbeveiligingswet (Cbw) | wetten.overheid.nl | NIS2 transposition — Dutch national law |
| NCSC-NL | ncsc.nl | Guidance, self-assessment, incident reporting |
| Autoriteit Persoonsgegevens | autoriteitpersoonsgegevens.nl | GDPR supervision, breach reporting |
Germany
| Source | URL | Use for |
|---|
| NIS2UmsuCG | bsi.bund.de | NIS2 transposition — German national law |
| BSI IT-Grundschutz | bsi.bund.de | Baseline protection catalogue, KRITIS |
| OpenKRITIS | openkritis.de | Community resource for KRITIS implementation |
Belgium
| Source | URL | Use for |
|---|
| CCB CyFun | ccb.belgium.be | Belgian Cybersecurity Framework, NIS2 mapping |
| Centre for Cybersecurity Belgium | ccb.belgium.be | National authority, guidance |
Bird & Bird NIS2 Tracker (multi-country)
EU_compliance_MCP — pre-indexed regulation database
- Install:
npx @ansvar/eu-regulations-mcp or add as MCP server
- Source: https://github.com/Ansvar-Systems/EU_compliance_MCP
- Reliability: HIGH (sourced from EUR-Lex)
- Coverage: 49 EU regulations, 2,500+ articles, 1,200+ definitions, full-text search
- Use for: Instant article/recital retrieval, cross-regulation comparison, control mappings
- When available: Prefer over web lookups for article text — faster and offline-capable
Agent lookup workflow
For EU-level questions (regulations, general obligations)
- EUR-Lex — authoritative legislative text
- ENISA / EDPB / ESA — practical guidance per regulation
- EU_compliance_MCP — if available, use for instant article lookup and cross-regulation comparison
- Always include a freshness warning — compliance status changes
For national implementation questions (transposition, local differences)
- ECSO tracker — which countries have transposed, links to national laws
- National source — check the specific country's authority (NCSC-NL, BSI, CCB, etc.)
- Cross-reference EUR-Lex — compare directive text with national implementation
- Flag differences — explicitly tell the user where national law adds to or differs from the EU directive
For comparative questions ("how does X differ from Y")
- Identify both sources (EU directive + national law, or two national laws)
- Use EUR-Lex for the EU baseline
- Use national sources for local specifics
- Present a clear comparison: what's the same, what differs, what's stricter
Agent instructions
- Never state transposition status or legal facts from memory — always direct the user to check the source.
- Use the lookup workflow above to guide which source to check first.
- Include the source URL and a freshness warning in every response.
- If a user needs country-specific detail, check the ECSO tracker and the relevant national authority.
- For practical "how to comply" questions, point to ENISA guidance (NIS2), EDPB guidelines (GDPR), or ESA standards (DORA).
- For legal text, point to EUR-Lex.
- When comparing EU directive vs national law, always flag where the national implementation is stricter or broader than the directive minimum.
- If the user's org profile includes a jurisdiction, prioritise sources for that country.