Previous Article Back to Blog
September 18, 2026 M. Skrijelj , N. Pinault , N. Fetiveau , K. Lefèvre 8 min read COMPLIANCE STACK

The EU Compliance Stack for Midcaps: Which Regulations Apply to You

Executive Summary

There is no single midcap compliance law. Seven overlapping EU frameworks apply, each on a different test: headcount, turnover, sector, or what you make and sell. A company can sit in scope for some and out of scope for others at the same time. This guide gives you one matrix to check your position across all seven, with a link to a detailed guide for each.

7
EU Frameworks

governing digital, operational, AI, cybersecurity, and ESG reporting for European midcaps.

1,000+
CSRD Post-Omnibus Threshold

employees (and >€450M turnover) required for direct CSRD scope since March 2026.

The essentials in 4 points

  • Size alone doesn't answer the question. CSRD is almost purely size-driven. GDPR, AI Act, DORA, and AML apply based on what you do, not how big you are. Most midcaps land somewhere in between.
  • You can be in scope for one framework and out of scope for another, at the same time. A 400-person industrial software company might sit outside CSRD scope, squarely inside NIS2 scope, and directly hit by the Cyber Resilience Act as a product manufacturer, all at once.
  • Post-Omnibus, several thresholds moved up. CSRD's threshold rose from 250 to 1,000 employees in March 2026. That's real relief for many midcaps, and easy to miss if you haven't rechecked your position since.
  • This is an orientation tool, not a legal determination. Use the matrix to identify which frameworks deserve a closer look, then confirm your specific position with a qualified adviser.

The scope matrix

The table below uses standard EU size bands (Commission Recommendation 2003/361/EC) as the starting axis. It shows how each framework applies in practice, since for several of these, headcount isn't the main test.

The EU Compliance Stack for Midcaps Scope Matrix: GDPR, AI Act, NIS2, CRA, DORA, CSRD, and AML

This matrix summarises general tests only. NIS2, CRA, DORA, and AML/CFT are driven primarily by sector and activity, not headcount: a company can sit squarely in scope at any size if it's a covered entity type. Confirm your specific position with a qualified adviser; this table is a starting point for orientation, not a scope determination for your organisation.

Reading the matrix for your situation

A 300-person B2B software company selling to enterprises almost certainly falls under GDPR (it processes personal data), likely under the AI Act if any product feature uses AI, and likely under NIS2 if it supplies critical sectors or sits in one itself. If it places any product with digital elements on the market, which covers most software, the Cyber Resilience Act applies too. It probably sits outside CSRD, DORA, and AML/CFT scope unless it's specifically a financial entity or a reporting company.

A 150-person regional bank or payment institution falls under GDPR, DORA (directly, regardless of size), and AML/CFT as an obliged entity. NIS2 likely applies as a financial-sector entity, and the AI Act may apply depending on its systems and any AI-driven credit or fraud tools. CSRD sits outside scope unless the company crosses the 1,000-employee/€450M threshold.

An 800-person industrial manufacturer falls under GDPR and the Cyber Resilience Act if any of its products carry digital elements, increasingly common even in traditional manufacturing. NIS2 likely applies depending on sector. Since Omnibus I, the manufacturer very likely sits outside direct CSRD scope now that the threshold moved to 1,000 employees, though it may still receive value-chain sustainability-data requests from larger customers (see our CSRD guide for the value-chain cap).

What changed recently, and why it's worth checking again

Two things shifted in the last 12 months that move where midcaps land on this matrix:

  1. CSRD's threshold rose sharply. Before March 2026, a 300-person company with modest turnover could sit inside CSRD scope. Since Omnibus I, the threshold is 1,000 employees and €450 million turnover. Many midcaps that budgeted for CSRD compliance now sit outside direct scope (see our full CSRD guide ).
  2. DORA's third-party pillar became live-enforced. The November 2025 designation of the first critical ICT third-party providers means DORA's third-party risk-management pillar is no longer theoretical for financial entities and their vendors (see our DORA guide ).

If you last checked your regulatory position more than six months ago, recheck it. Not because new rules appeared, but because the boundaries of the existing ones moved.

What Themio does for you

Themio's audit assesses your AI Act and GDPR position today: scope, obligations, gaps, and a prioritized remediation plan. Modules for NIS2, CRA, CSRD, DORA, and AML/CFT are rolling onto the platform module by module — DORA is next, launching early 2027.

Frequently Asked Questions

Is there one single EU compliance law for midcaps?
No. Each framework in this matrix has its own scope test: some based on size, some on sector, some on activity. A midcap typically needs to check its position against several frameworks independently, which is what this matrix is built to shortcut.
We're a 260-person company. Does that automatically make us a "midcap" for regulatory purposes?
Not in a single, unified sense. Different frameworks use different size bands and different definitions of "midcap" or "large undertaking." No single EU-wide legal category decides that for a 260-person company across every purpose at once.
How often should we recheck our scope across these frameworks?
At minimum annually, and immediately after any threshold change (like the CSRD move in March 2026), after crossing a headcount or turnover band, after a merger, or on entering a new regulated sector.
We're a SaaS company with 80 employees. Which of these are most likely to apply to us?
GDPR applies automatically if you process personal data. The Cyber Resilience Act applies if you place software on the EU market. The AI Act applies if you build or deploy AI features. NIS2 may apply if your customers include essential or important entities and you fall under supply-chain obligations. CSRD, DORA, and AML/CFT are unlikely unless you operate in regulated financial or reporting sectors.
Does this table cover every EU rule that could apply to a midcap?
No. It covers the frameworks most relevant to Themio's current focus areas. Other rules, including sector-specific financial regulation, product-safety regimes outside CRA's scope, and national-level requirements, may also apply depending on your activity.