AI Act high-risk obligations enter force 2026-08-02

EU compliance,
article-by-article.

GDPR + NIS2 + EU AI Act + DORA — the 4 frameworks EU regulators actually enforce against SaaS. $199, laser-focused. Skip the SOC 2 / PCI / ISO bundle if you only sell into Europe.

GDPR
in force since 2018-05-25

Articles 5, 7, 13, 17, 25, 28, 30, 32, 33, 34, 35. Erasure endpoints, breach notification timelines, processor agreements, lawful basis logs.

NIS2
in force since 2024-10-17

Annex II + Art. 21 measures. MFA, encryption at rest, incident reporting within 24h to ENISA, supply-chain risk management.

EU AI Act
high-risk rules in force 2026-08-02

Risk classification, prohibited practices, transparency obligations, conformity assessment, post-market monitoring.

DORA
in force since 2025-01-17

ICT risk management, incident classification & reporting, digital operational resilience testing, third-party risk.

$199 vs the alternatives

ApproachCostLead time
Consultant audit€5,000+3-6 weeks
Vanta / Drata€10K+/yrOnboarding 1 month
Full Bryxe Compliance (7 frameworks)$34960 seconds
Bryxe EU-only audit$19960 seconds