Ever-expanding regulatory requirements (without matching resources)¶

Europe’s regulatory machinery has developed a remarkable talent for producing rules at a pace that would make a rabbit colony blush, while steadfastly refusing to provide the carrots required to implement any of it. NIS2, DORA, the AI Act and the Cyber Resilience Act all arrive with noble intentions, serious faces, and a level of resourcing that could generously be described as fictional. An organisation can stumble from one deadline to the next while quietly constructing a towering pile of security debt that threatens to wobble, topple, and flatten anyone foolish enough to look directly at it.
The compliance treadmill¶
The cycle has grown familiar. Brussels publishes another directive. Member states interpret it in seventeen slightly incompatible ways. Regulators issue guidance that reads like it was written by a committee voting on synonyms. Industry studies the horizon in the hope someone else will go first. Deadlines approach. Something is bought. Something is installed. Boxes are ticked. Everyone returns to normal life until the next regulation lumbers into view and the procession begins again.
By the time one regulation is grudgingly implemented, two more are on the horizon, and the system rarely gets a moment to breathe. Staff burn out, and organisations lose good people, because working in permanent crisis mode is no one’s lifelong ambition. All of these rules require staff, budget, expertise, and time. None of them provide staff, budget, expertise, or time.
Paper compliance, the art of looking secure¶
A good deal of compliance work consists of manufacturing the appearance of competence, a bureaucratic stage-play in which everyone pretends that documents reflect reality rather than aspiration. Policies are beautifully formatted, legally reviewed, approved by senior management, and read by approximately three people. Risk registers list every imaginable calamity with carefully assigned scores and action plans nobody pursues outside the two weeks before an audit; accepted usually means ignored, and mitigated often means a thin layer of procedural varnish. Vendor questionnaires fare worse: two hundred questions, answered “yes” throughout with the enthusiasm of a child completing a treasure hunt, no evidence required and none offered.
The disconnect can grow vast. Policy says an organisation has a fully tested incident response programme with round-the-clock coverage. Reality is an engineer glancing at email alerts between other tasks. Auditors confirm compliance. Breaches later confirm that the policy lives in a parallel universe.
Panic procurement and the duct tape philosophy¶
When deadlines reach critical mass and no actual controls exist, an organisation may reach for the nearest healing potion: Buy Something Fast. Eighteen months before the deadline there is talk of forming a working group. Twelve months before, a sense that something probably ought to happen. Six months before, everyone acknowledges the urgency and behaves as if there is none. Three months before, panic. One month before, the vendor who answers emails becomes the chosen one, a tool is installed with default settings, and compliance is declared. Alerts appear, nobody knows what to do with them, fatigue sets in, and the tool becomes a silent monument to past panic. Screenshots are still taken for audits.
Quick fixes follow the same logic. If a regulation demands encryption at rest, a proper solution involves a storage review, data classification, key management, and months of actual work. A quick fix is enabling device encryption on laptops and declaring victory. The laptops are indeed encrypted. Everything else remains unprotected. And nothing lasts longer than a temporary workaround: the shortcut intended for three weeks runs for three years, familiar enough to be trusted and trusted enough to be permanent, meeting the minimum on paper while the stack turns brittle, opaque, and unmaintainable.
The accumulating debt¶
Regulations assume organisations have dedicated teams, strong governance, well maintained systems, and budgets that stretch like elastic. The organisations actually implementing them often have a handful of people juggling responsibilities and technology stacks that creak like haunted floorboards. The distance between regulatory fiction and operational reality is the gap where compliance theatre thrives, and every shortcut taken in that gap compounds silently until the temporary patch becomes a load-bearing wall no one dares touch.
The obvious remedies, funded mandates, grace periods that reflect complexity, regulators who distinguish good faith effort from impersonation of effort, are rarely adopted, because regulators write rules, legislators approve them, and everyone quietly assumes implementation is someone else’s problem. Survivors prioritise brutally, document their limitations, push back on impossible timelines, and invest in fundamentals rather than fashionable tools. Most likely, a bill is coming. It has always been coming. And we keep adding interest.
The clerk’s brief¶
From the clerks, for the Patrician’s eyes
Compiled July 2026. Entries run newest first. Observations that have stopped being news but not stopped being true are absorbed into the procession at the end. His Lordship is reminded, respectfully, that every deadline below was set by people who will not be implementing it.
July 2026: The Cyber Resilience Act’s clock is set for September¶
From 11 September 2026, manufacturers of products with digital elements are required to report actively exploited vulnerabilities: an early warning within 24 hours of becoming aware, and a full notification within 72. ENISA’s Single Reporting Platform, through which all of this is meant to flow, is officially scheduled to be operational by that same date; as of late June 2026 it was not yet live, though training materials and dry runs had appeared. The clerks observe that the obligation and the infrastructure for meeting it are currently timetabled to arrive on the same day, an arrangement whose elegance they admire and whose prudence they decline to assess.
February 2026: The data protection authorities draw a line¶
On 10 February 2026 the EDPB and EDPS adopted a joint opinion on the Digital Omnibus, welcoming the parts that reduce reporting burden, notably a higher risk threshold and a longer deadline for notifying personal data breaches, and strongly urging the co-legislators to reject the proposed narrowing of the definition of personal data as going clearly beyond the court’s jurisprudence. Simplification, in other words, is acceptable until it becomes deregulation wearing simplification’s coat. The clerks expect the argument to run through 2026, and privately expect to enjoy it.
January 2026: NIS2 receives its first rewrite¶
On 20 January 2026 the Commission proposed targeted amendments to NIS2, to simplify compliance, align the directive with the Cybersecurity Act, and connect it to the single entry point for incident reporting proposed in the Digital Omnibus. The directive is barely a year into enforcement and already being simplified. The clerks decline to call this failure. They note only that the machinery has begun regulating its own regulations, which is either maturity or recursion, and that from below the treadmill the two are difficult to tell apart.
November 2025: The Omnibus arrives, and finance gets its list¶
On 19 November 2025 the Commission adopted the Digital Omnibus proposal, amending a large corpus of digital legislation at a stroke, with a stated aim of cutting administrative burden by roughly a quarter and a single entry point for incident reporting across NIS2, GDPR, DORA and the Critical Entities Resilience Directive. The day before, on 18 November 2025, the European supervisory authorities designated the first 19 critical ICT third-party providers under DORA, bringing the hyperscalers under direct financial-sector oversight. In the same week, Europe resolved to watch its suppliers more closely and to paper its own entities less. The clerks note that both could even be right.
May 2025: Nineteen member states receive a reasoned opinion¶
On 7 May 2025 the Commission sent reasoned opinions to 19 member states for failing to fully transpose NIS2, more than half a year past the October 2024 deadline, with referral to the Court of Justice as the next stop. The list includes Germany, France, Spain and the Netherlands, which is to say the machine room of the single market. Entities are expected to comply with a directive most of their governments had not finished writing into law, and the clerks observe that the treadmill runs regardless of whether the mechanics have assembled it.
April 2025: DORA’s first census¶
By 30 April 2025, competent authorities submitted to the European supervisory authorities the first registers of information on financial entities’ ICT third-party arrangements: the first system-wide map of who in European finance depends on whom. The registers exist because DORA, applicable since January 2025, requires them. The dependencies they record exist because for thirty years nothing required otherwise. Counting the debt is not paying it, but it is the first honest ledger, and the clerks have a professional fondness for honest ledgers.
The procession, with dates¶
The arc now repeats often enough to be told with dates. A directive is adopted. A transposition deadline passes with most member states absent, as NIS2’s did in October 2024. Guidance fogs, enforcement begins against the states themselves before any entity, as in May 2025, and within roughly a year the simplification proposals arrive, as they did in November 2025 and January 2026. The older strata carry on underneath: GDPR, applicable since May 2018 and still unevenly implemented, is itself now being amended by the same Omnibus that adds the new reporting plumbing.
One countertrend is on file. The Union has begun building infrastructure rather than only paperwork: ENISA’s European Vulnerability Database has been live since May 2025, launched while the American equivalent struggled with backlog and funding. The resourcing gap has not closed. It has been promoted: it is now the subject of legislation, rather than merely its victim.