Regulatory Resource Center

Insights and compliance guides for European SMEs

Stay up to date with the EU AI Act , GDPR , NIS2 , DORA , and the Cyber Resilience Act. Practical methods to master digital compliance without unnecessary legal expenses.

Themio Editorial Mission

The wave of European digital regulations is fundamentally transforming operational requirements for SMEs. Our team of compliance experts translates official texts (EUR-Lex, CNIL, ENISA) into clear summaries, ready-to-use documentation templates, and actionable roadmaps tailored for founders, DPOs, and technical leaders.

Featured

Latest published guide

Topical Clusters

Explore our analysis by regulatory framework

AI Act & AI Governance
Risk classification, mandatory AI inventory, and Article 4 literacy training.
6 articles Filter
GDPR & Privacy
Data governance, SME compliance checklist, and generative AI privacy controls.
2 articles Filter
Cybersecurity (NIS2 · DORA · CRA)
Supply chain security, digital operational resilience, and incident reporting.
4 articles Filter
CSRD & ESG Sustainability
Omnibus I threshold updates and ESG reporting expectations for suppliers.
1 article Filter
Filter :
All Guides & Practical Analyses 14 articles
24h / 72h
CRA Deadlines
21 September 2026 Majda Skrijelj 9 min read CRA · Incidents

Incident Reporting Under the Cyber Resilience Act: The Practical Guide for SMEs and Product Teams (2026)

The EU Cyber Resilience Act sets strict 24h and 72h reporting deadlines for exploited vulnerabilities and severe incidents. A practical guide to ENISA single reporting and SME duties.

7
EU Frameworks
18 September 2026 Majda Skrijelj et al. 8 min read EU Stack · Midcaps

The EU Compliance Stack for Midcaps: Which Regulations Apply to You

GDPR, AI Act, NIS2, CRA, DORA, CSRD and AML: a single scope matrix for European midcaps and growing SMEs to see which EU frameworks apply, at a glance.

5
Key Pillars
16 September 2026 Majda Skrijelj 6 min read DORA · FinTech

DORA Compliance for Fintech SMEs: What Actually Applies to You (2026)

DORA has applied since January 2025 and the EU just designated its first critical ICT providers. A practical DORA scope and requirements guide for fintech SMEs and their ICT partners.

9 Fields
Template
11 September 2026 Nicolas Pinault 7 min read AI Act · Template

How to Build an AI System Inventory: The Template Every AI Act Deployer Needs

The first document every AI Act deployer needs is a simple one, a list of every AI tool in use. Here is the template and the method to build it properly.

7 Steps
Decision Test
8 September 2026 Nicolas Fetiveau 8 min read AI Act · Risk

High-Risk AI Classification: The 7-Step Test (2026)

The European Commission's May 2026 draft guidelines clarify how to classify high-risk AI systems. Here is the 7-step test SMEs should run on every AI tool they use.

68%
Unmonitored Use
4 September 2026 Nicolas Pinault 6 min read AI Act · Shadow AI

Shadow AI in European SMEs: The Compliance Risk Hiding in Your Team’s Browser Tabs

Employees are using AI tools you haven’t approved, can’t see, and can’t audit. Why shadow AI is now a compliance problem, not just an IT one, and how to get visibility.

6 Points
Key Controls
31 August 2026 Majda Skrijelj 7 min read GDPR & AI

Is ChatGPT (or Copilot, Gemini) GDPR-Compliant for Your Business in 2026?

ChatGPT, Copilot, and Gemini aren’t GDPR-compliant or non-compliant by default. Your use of them is. Here’s what determines it, and what to fix first.

1,000 Empl.
Omnibus Cap
24 August 2026 Nicolas Fetiveau 6 min read CSRD · ESG

CSRD After Omnibus I: Is Your Company Still in Scope in 2026?

CSRD after Omnibus I: the new 1,000-employee and €450M thresholds, the SME value chain cap, and how to confirm whether your company is still in scope.

11 Sept.
2026 Deadline
14 August 2026 Nicolas Pinault 7 min read CRA · Software

Cyber Resilience Act Reporting from 11 September 2026: SME Requirements

Cyber Resilience Act reporting starts 11 September 2026. What software SMEs must have ready: the 24/72-hour cascade, SBOM requirements, and open source scope.

10 Measures
Article 21
3 August 2026 Majda Skrijelj 8 min read NIS 2 · Cyber

NIS2 Compliance for SMEs in 2026: Does It Apply to You and What Do You Need to Implement?

NIS2 applies to medium and large companies in covered sectors - but three categories of smaller companies are caught even below the official thresholds.

8 Steps
Action Plan
27 July 2026 Majda Skrijelj 9 min read GDPR · Checklist

GDPR Compliance Checklist for SMEs in 2026: 8 Actionable Steps

Six years after GDPR came into effect, 60% of SMEs are still not fully compliant. Discover the 8 practical steps to protect your business and demonstrate compliance.

€15M
Penalty Cap
20 July 2026 Nicolas Fetiveau 8 min read AI Act · France

AI Act Compliance for French SMEs: What You Must Do in 2026

French SMEs are subject to the EU AI Act without exemption. Discover what resources are available and the CNIL's enforcement trends for small businesses.

5 Steps
Deployment
10 July 2026 Majda Skrijelj 8 min read AI Act · Method

How to Comply with the EU AI Act in 5 Steps (2026 Guide)

If your company uses any AI tool (a chatbot, recruitment screening, analytics, or assistants) you are subject to the EU AI Act. Learn the 5 concrete steps to achieve compliance without a legal team.

7 Tools
Comparison
6 July 2026 Nicolas Pinault 8 min read AI Act · Comparison

Best AI Act Compliance Tools for SMEs in 2026: A Practical Buyer's Guide

The EU AI Act's Article 4 (mandatory AI literacy) has been in force since February 2, 2025. Any organization using AI tools professionally is already a 'deployer' subject to obligations.