Skip to content

Compliance

Regulation, translated into engineering work

A standard is a document until somebody turns it into a backlog with owners and dates. That translation is most of the job.

In short

Compliance work translates regulatory and standards requirements into specific engineering and process changes, and produces the evidence that they operated. Cloudgap delivers certification programmes against ISO 27001, ISO 42001, SOC 2, Cyber Essentials and PCI DSS, and readiness work for the EU AI Act, DORA and UK data protection law.

The translation

Compliance budget as an investment, or as a cost centre

The difference is whether the work leaves anything behind. A programme run to pass an audit produces a certificate and a set of documents that decay from the day they are signed. A programme run to change how the organisation operates produces the same certificate and a set of controls that are still working at the surveillance audit.

In practice the divergence happens early, at scoping. Scope drawn to satisfy the auditor produces the first outcome. Scope drawn around what the business actually needs to be able to prove - to a customer, a regulator or an investor - produces the second, and it is usually smaller.

The other divergence is who does the work. A programme where a consultant writes everything and the internal team learns nothing fails at the first surveillance audit, because nobody inside the organisation understands what they are maintaining.

Regulatory horizon

The deadlines behind the standards

Every date below is checked against the regulator, the Commission or the issuing body, and stamped with the day it was last read. Where a deadline has moved, what moved it is stated. If you only read one thing here, read the deferrals - a postponed obligation is not a withdrawn one.

Last verified 25 August 2026 · 11 obligations tracked

UK and EU cyber security and AI governance obligations, with the date each applies, who it affects and the source it was verified against on 25 August 2026.
ObligationDateStatusWho it hitsSource
EU AI ActAnnex III standalone high-risk system obligations applyDeferred from 2 August 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. A 16-month deferral, granted because harmonised standards and national competent authorities were not ready. The obligation was postponed, not withdrawn.14 months awayDeferredProviders and deployers of AI used in employment, education, credit and insurance scoring, essential services, law enforcement, migration and the administration of justice.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
EU AI ActAnnex I high-risk obligations apply to AI embedded in regulated productsDeferred by Regulation (EU) 2026/1744, the Digital Omnibus on AI. A 12-month deferral.22 months awayDeferredManufacturers placing AI inside products already covered by EU product-safety law - medical devices, machinery, lifts, toys, vehicles.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
UK Cyber Security and Resilience BillBefore Parliament. Not yet law, and no commencement date is set.Introduced to the Commons on 12 November 2025. Passed Commons stages and moved to the Lords. Commencement is staged from Royal Assent, with the substantive duties left to secondary legislation. The government has said it intends to consult on implementation during 2026.Before ParliamentIf enacted as drafted: existing NIS sectors plus medium and large managed service providers, data centres, large load controllers and designated critical suppliers. Initial incident notification within 24 hours, fuller report within 72.How we handle this ->GOV.UK, Cyber Security and Resilience Bill factsheets (page last updated 30 June 2026)Read 25 August 2026
EU AI ActArticle 50 transparency obligations apply2 months agoIn forceAny provider or deployer whose AI interacts with people or generates synthetic audio, image, video or text. Chatbots must disclose they are machines; synthetic media must be machine-readably marked.How we handle this ->European Commission, Shaping Europe's digital futureRead 25 August 2026
Cyber EssentialsRequirements for IT Infrastructure v3.3 and the Danzell question set applyStricter marking on MFA and on timely security updates, where a shortfall is now an automatic fail rather than a finding. Greater emphasis on passwordless authentication and passkeys. Scoping tightened: any specified device connected to the internet is in scope.5 months agoIn forceEvery organisation certifying or recertifying. Applies to all applications registered from 27 April 2026.How we handle this ->IASME, Cyber Essentials delivery partner for the NCSCRead 25 August 2026