Navigating regulatory compliance is an evolving challenge for businesses operating within the EU and those engaged in EU markets. With the rapid growth of digital ecosystems, the European Union has introduced critical regulations aimed at enhancing cybersecurity, operational resilience and data protection. Here’s an overview of some of these EU regulations, their key obligations, and how Sedicii supports organisations in achieving compliance while driving innovation.
Regulations discussed in this article:
What is the Electronic Identification, Authentication, and Trust Service Regulation 2 (eIDAS2)?
Effective Date: Expected by 2025; Digital Identity Wallets mandatory by November 2026
Focus: Enhancing eIDAS with a European Digital Identity Wallet.
Who It Affects:
- Sectors: Finance, healthcare, e-commerce, and public services.
- Geographies: EU member states.
- Customers: Citizens and businesses requiring secure, portable digital identities.
Key Obligations:
- Issue certified digital wallets to citizens and businesses.
- Integrate wallets across public and private services.
How Sedicii Can Help: Sedicii’s privacy-preserving technologies protect sensitive data stored in digital wallets and facilitate interoperability between systems.
What is the Digital Operational Resilience Act (DORA)?
Effective Date: January 17, 2025
Focus: Ensuring financial institutions can withstand, respond to, and recover from operational disruptions, including cyberattacks.
Who It Affects:
- Sectors: Financial services, including banks, insurers, and ICT service providers.
- Geographies: EU member states.
- Customers: Financial institutions and their service providers.
Key Obligations:
- Implement robust ICT risk management frameworks.
- Conduct regular testing of ICT systems for resilience.
- Report significant incidents promptly.
- Manage third-party risks effectively.
How Sedicii Can Help: Sedicii’s tools streamline compliance with DORA by providing secure, privacy-preserving data-sharing mechanisms that reduce exposure and enable seamless incident reporting. We also provide a robust platform for identity management that ensures data is stored in compliant, fault-tolerant manner. Our solutions strengthen ICT risk management while ensuring compliance with EU regulations.
What is the EU Cyber Resilience Act (CRA)?
Effective Date: December 2024; Main obligations apply from December 11, 2027
Focus: Enhancing the security of digital products and services.
Who It Affects:
- Sectors: Technology manufacturers, software developers, and IoT providers.
- Geographies: EU member states.
- Customers: End-users of digital products.
Key Obligations:
- Perform mandatory risk assessments for digital products.
- Provide regular updates and patches.
- Ensure transparency with clear security labeling.
How Sedicii Can Help:
Sedicii enables compliance with CRA by offering scalable security solutions, real-time incident monitoring, and privacy-first approaches for IoT ecosystems.
What is the Network and Information Security Directive 2 (NIS2)?
Effective Date: October 18, 2024
Focus: Strengthening cybersecurity across critical infrastructure sectors to combat the rising threat of cyberattacks.
Who It Affects:
- Sectors: Energy, transport, healthcare, financial services, and digital infrastructure.
- Geographies: EU member states and cross-border entities.
- Customers: Operators of essential services and critical infrastructure.
Key Obligations:
- Enforce robust cybersecurity measures and risk assessments.
- Report significant incidents within 24 hours.
- Designate security officers for compliance oversight.
How Sedicii Can Help:
Sedicii enhances NIS2 compliance through fraud detection, real-time incident reporting tools, and identity verification solutions that ensure robust security in high-risk sectors.
What is the Digital Services Act (DSA)?
Effective Date: November 16, 2022
Focus: Ensuring transparency and accountability for online platforms, fostering safer digital spaces.
Who It Affects:
- Sectors: Online platforms, marketplaces, and search engines.
- Geographies: All EU member states and platforms accessible to EU users.
- Customers: Both platform providers and their end users.
Key Obligations:
- Remove illegal content promptly upon notification.
- Ensure transparency in advertising, including clear labeling and disclosures.
- Implement measures to combat disinformation and prevent harm.
- Conduct risk assessments for very large online platforms (VLOPs).
How Sedicii Can Help:
Sedicii’s secure data-sharing solutions enable platforms to validate and authenticate user-generated content and advertiser identities without compromising user privacy. By leveraging Zero Knowledge Proof (ZKP) technology, platforms can ensure compliance with transparency and content moderation requirements while safeguarding sensitive data.
What is the Digital Markets Act (DMA)?
Effective Date: November 1, 2022
Focus: Ensuring fair competition in digital markets by regulating “gatekeeper” platforms.
Who It Affects:
- Sectors: Large digital platforms offering core platform services, such as online search, social networks, and app stores.
- Geographies: EU member states and platforms serving EU users.
- Customers: Gatekeepers, competing businesses, and end users.
Key Obligations:
- Prohibit self-preferencing of gatekeepers’ own services.
- Ensure data portability and interoperability between services.
- Enable business users to access data generated by their activities on gatekeeper platforms.
- Restrict combining personal data from multiple services without user consent.
How Sedicii Can Help:
Sedicii provides privacy-enhancing technologies, such as Secure Multiparty Computation (MPC), to enable secure data portability and interoperability. These solutions help gatekeepers share data responsibly while meeting DMA requirements and protecting user privacy.
What is first the Electronic Identification, Authentication, and Trust Service Regulation (eIDAS)?
Effective Date: July 1, 2016
Focus: Establishing a framework for secure electronic transactions and identities across the EU.
Who It Affects:
- Sectors: Public administrations, businesses, and financial institutions.
- Geographies: EU member states.
- Customers: Citizens and organisations using electronic identification services.
Key Obligations:
- Mutual recognition of electronic ID’s among member states.
- Implementation of standards for electronic signatures and trust services.
How Sedicii Can Help:
Sedicii’s advanced identity verification solutions align with eIDAS standards, ensuring secure electronic transactions and seamless cross-border interactions.
Why Choose Sedicii?
Sedicii leverages innovative technologies like Zero Knowledge Proofs (ZKP), Secure Multiparty Computation (MPC), and Messageless Computation (MLC) to deliver solutions that address compliance while prioritising privacy and security. By using authoritative data sources and advanced technologies, Sedicii empowers organisations to navigate complex EU regulations confidently and efficiently. Let us help you redefine compliance for the digital age.
This article is part of Sedicii’s ongoing thought leadership in support of Project PHACKS, an initiative focused on building collaborative communities to address complex cybersecurity and data privacy challenges. PHACKS is funded by the European Union and brings together organisations to explore new approaches to secure data collaboration utilising privacy enhancing technologies. Through this work, Sedicii contributes its expertise in advanced cryptography, secure data collaboration and digital identity to promote safer, more transparent digital ecosystems across Europe. The views expressed herein reflect the author’s perspective and do not necessarily represent those of the European Union. Learn more about Project PHACKS.
