Which EU rules affect selecting a security vendor, beyond GDPR?

Short answer: Beyond the GDPR, three EU regimes increasingly shape vendor selection: DORA (operational resilience for financial entities and their ICT providers), NIS2 (cybersecurity obligations for essential and important entities, including supply-chain security), and the EU AI Act (risk-tiered rules for AI systems). Each pushes obligations toward vendors. Cyber Crucible's design — no customer content collected, local processing, on-premises option — supports a customer's obligations under all of them, without Cyber Crucible claiming compliance on the customer's behalf.

The landscape at a glance

How Cyber Crucible fits

The recurring theme is supply-chain and third-party risk. Because Cyber Crucible collects no customer content, credentials, or keys and can run entirely within the customer's boundary, it reduces the surface these regimes are written to control. The pages in this book address each regime and the larger member states. Documentation is available from dpo@cybercrucible.com.


Revision #2
Created 2026-07-23 15:19:05 UTC by Dennis Underwood
Updated 2026-07-23 18:20:29 UTC by Dennis Underwood