Reference
EU Compliance Glossary
A working dictionary of the terms that appear in EU compliance documentation — NIS2, DORA, the AI Act and the regulation around them. Each entry gives a one-line definition you can quote, a short explanation, why it matters, and links to the pages where the term matters in practice.
A
- AI Act·AI Act overview
Regulation (EU) 2024/1689, the EU's law on artificial intelligence, regulating AI systems according to the risk they pose.
- AI Literacy·What high-risk AI requires
The Article 4 duty, in force since February 2025, to ensure staff working with AI systems have sufficient AI knowledge and skills.
- AI Office·AI Act fines and enforcement
The European Commission body that supervises general-purpose AI models and coordinates AI Act enforcement across the EU.
- All-Hazards Approach·The 10 NIS2 security requirements
The NIS2 principle that security measures must protect against all threats to network and information systems, not just cyber attacks.
- Annex I·Which sectors NIS2 covers
The list of 11 sectors under NIS2 considered most critical, whose in-scope organisations are classified as essential entities.
- Annex II·Which sectors NIS2 covers
The list of 7 sectors under NIS2 considered important but generally lower-risk than Annex I.
- Annex III (AI Act)·The AI Act risk pyramid
The AI Act's list of use-case areas in which AI systems are classified as high-risk.
- Article 20·NIS2 penalties and management liability
The NIS2 provision requiring management bodies to approve, oversee, and be trained on cybersecurity risk measures.
- Article 21·The 10 NIS2 security requirements
The section of the NIS2 Directive that sets out the 10 mandatory cybersecurity risk-management measures.
- Article 23·NIS2 incident reporting timeline
The NIS2 provision setting the mandatory incident reporting timeline.
B
- Business Continuity·The 10 NIS2 security requirements
The Article 21(c) measure requiring backup management, disaster recovery, and crisis management to keep services running during and after incidents.
C
- CE Marking (AI Act)·What high-risk AI requires
The conformity mark that high-risk AI systems must carry before being placed on the EU market, signalling compliance with the AI Act.
- CER Directive·NIS2 overview
Directive (EU) 2022/2557 on the resilience of critical entities — NIS2's sister directive covering physical resilience.
- CERT-SE·NIS2 incident reporting timeline
Sweden's national CSIRT, operated by MSB, which receives incident reports under Cybersäkerhetslagen.
- Competent Authority·Who NIS2 applies to
The national body in an EU member state responsible for supervising NIS2 compliance.
- Conformity Assessment·What high-risk AI requires
The process of verifying that a high-risk AI system meets the AI Act's requirements before it can be CE-marked and sold in the EU.
- Critical ICT Third-Party Provider (CTPP)·DORA overview
An ICT provider designated as critical to the EU financial system and placed under direct European supervisory oversight.
- CSIRT·NIS2 incident reporting timeline
Computer Security Incident Response Team — the national body organisations report significant incidents to under NIS2.
- Cyber Hygiene·The 10 NIS2 security requirements
The Article 21(g) measure covering basic security practices and cybersecurity training for all staff.
- Cyber Resilience Act (CRA)·NIS2 overview
Regulation (EU) 2024/2847 setting mandatory cybersecurity requirements for products with digital elements sold in the EU.
- Cybersäkerhetslagen·NIS2 in Sweden
Sweden's national law transposing the NIS2 Directive, in force since 2026.
D
- Directive vs Regulation·NIS2 overview
The two main types of EU law: a regulation applies directly in all member states, while a directive must be transposed into national law first.
- DORA·DORA overview
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, the EU's ICT security law for the financial sector, applicable since 17 January 2025.
E
- Early Warning·NIS2 incident reporting timeline
The first NIS2 incident report, due to the CSIRT within 24 hours of becoming aware of a significant incident.
- ENISA·NIS2 overview
The European Union Agency for Cybersecurity, which supports NIS2 implementation with guidance, coordination, and reporting.
- ESAs (EBA, ESMA, EIOPA)·DORA overview
The three European Supervisory Authorities for banking, securities markets, and insurance, which jointly develop DORA's technical standards and oversee critical ICT providers.
- Essential Entity·Who NIS2 applies to
An organisation classified under NIS2 Annex I sectors that faces the strictest supervisory regime and highest penalty ceiling.
F
- Final Report·NIS2 incident reporting timeline
The concluding NIS2 incident report, due no later than one month after the incident notification.
- Finansinspektionen·DORA overview
Sweden's Financial Supervisory Authority, the competent authority for DORA compliance among Swedish financial entities.
- FRIA (Fundamental Rights Impact Assessment)·What high-risk AI requires
An assessment of the impact on fundamental rights that certain deployers must complete before using a high-risk AI system.
G
- GDPR Overlap·NIS2 incident reporting timeline
The interplay between NIS2 and GDPR — one incident can trigger both a CSIRT report and a personal data breach notification, on different clocks and to different authorities.
- GPAI (General-Purpose AI)·General-purpose AI models (GPAI)
AI models trained for broad capability and usable across many tasks, subject to their own obligations under the AI Act since August 2025.
H
- High-Risk AI System·The AI Act risk pyramid
An AI system in a use case listed by the AI Act as high-risk, subject to the law's full compliance regime.
I
- ICT Risk Management Framework·DORA overview
The documented set of strategies, policies, and tools that DORA requires financial entities to maintain for managing ICT risk.
- Important Entity·Who NIS2 applies to
An organisation under NIS2 Annex I or II sectors that meets the medium-enterprise threshold without reaching essential-entity status.
- Incident Notification (72 Hours)·NIS2 incident reporting timeline
The second NIS2 incident report, due within 72 hours, updating the early warning with an initial assessment of severity and impact.
- ISO 27001·The 10 NIS2 security requirements
The international standard for information security management systems, widely used as a framework for implementing NIS2's requirements.
L
- Lead Overseer·DORA overview
The European Supervisory Authority appointed to directly oversee a critical ICT third-party provider under DORA.
- Lex Specialis·DORA overview
The legal principle that a sector-specific law overrides a general one — the reason financial entities follow DORA instead of NIS2.
M
- Major ICT-Related Incident·DORA overview
An ICT incident meeting DORA's classification thresholds, triggering mandatory reporting to the financial supervisor.
- Management Body·NIS2 penalties and management liability
The board of directors, executive committee, or equivalent governing body of an organisation.
- MSB·Who NIS2 applies to
The Swedish Civil Contingencies Agency, the central coordinating authority for NIS2 in Sweden.
- Multi-Factor Authentication (MFA)·The 10 NIS2 security requirements
A login security method requiring more than one form of verification, required under NIS2 Article 21(j).
N
- National Transposition·NIS2 by country
The process by which an EU member state converts the NIS2 Directive into its own national law.
- NIS1 (The Original NIS Directive)·NIS2 overview
Directive (EU) 2016/1148, the EU's first cybersecurity law, replaced by NIS2 in 2023.
- NIS2 Directive·NIS2 overview
The EU's Directive (EU) 2022/2555, the updated cybersecurity law covering critical sectors across the Union.
- Notified Body·What high-risk AI requires
An independent organisation designated by a member state to perform third-party conformity assessments of certain high-risk AI systems.
P
- Prohibited AI Practices·The AI Act risk pyramid
The AI uses banned outright under Article 5 of the AI Act, applicable since 2 February 2025.
- Proportionality Principle·DORA overview
The DORA principle that requirements scale with an entity's size, risk profile, and the criticality of its services.
- Provider vs Deployer·Who must comply with the AI Act
The AI Act's two central roles: the provider develops or places an AI system on the market; the deployer uses it under its own authority.
R
- Register of Information·DORA overview
The mandatory register of all contractual arrangements with ICT third-party providers that DORA requires financial entities to maintain and report.
- Registration Requirement·Who NIS2 applies to
The NIS2 duty for in-scope entities to identify themselves to the national authority with basic information about their organisation.
- Regulatory Sandbox·Who must comply with the AI Act
A controlled environment, run by authorities, where AI systems can be developed and tested under regulatory supervision before market launch.
- Risk-Based Approach·AI Act overview
The AI Act's structure of four risk tiers — unacceptable, high, limited, and minimal — with obligations scaled to each.
- RTS and ITS·DORA overview
Regulatory and Implementing Technical Standards — the detailed EU rules that specify how DORA's high-level requirements work in practice.
S
- Significant Incident·NIS2 incident reporting timeline
An incident that has caused, or could cause, severe operational disruption, financial loss, or considerable damage to others.
- Size-Cap Rule·Who NIS2 applies to
The NIS2 rule that brings organisations into scope based on size: at least 50 employees or over EUR 10 million in annual turnover, in a covered sector.
- Supply Chain Security·The 10 NIS2 security requirements
One of the 10 Article 21 measures, requiring entities to assess and manage cybersecurity risk from suppliers and service providers.
- Systemic Risk (GPAI)·General-purpose AI models (GPAI)
The AI Act's designation for the most capable general-purpose AI models, whose reach could cause large-scale harm across the EU.
T
- TIBER-EU·DORA overview
The European framework for Threat Intelligence-Based Ethical Red Teaming, developed by the ECB, on which DORA's TLPT requirements build.
- TLPT (Threat-Led Penetration Testing)·DORA overview
Advanced penetration testing based on real threat intelligence, required at least every three years for significant financial entities under DORA.
- Transparency Obligations (Article 50)·The AI Act risk pyramid
The AI Act duties to disclose when people interact with AI, and when content is AI-generated or manipulated.
V
- Vulnerability Disclosure (CVD)·The 10 NIS2 security requirements
Coordinated Vulnerability Disclosure — a structured process for receiving, handling, and remediating vulnerability reports from third parties.
