This article provides general informational guidance. See Legal Disclaimer .
There is no single midcap compliance law. Seven overlapping EU frameworks apply, each on a different test: headcount, turnover, sector, or what you make and sell. A company can sit in scope for some and out of scope for others at the same time. This guide gives you one matrix to check your position across all seven, with a link to a detailed guide for each.
The essentials in 4 points
- Size alone doesn't answer the question. CSRD is almost purely size-driven. GDPR, AI Act, DORA, and AML apply based on what you do, not how big you are. Most midcaps land somewhere in between.
- You can be in scope for one framework and out of scope for another, at the same time. A 400-person industrial software company might sit outside CSRD scope, squarely inside NIS2 scope, and directly hit by the Cyber Resilience Act as a product manufacturer, all at once.
- Post-Omnibus, several thresholds moved up. CSRD's threshold rose from 250 to 1,000 employees in March 2026. That's real relief for many midcaps, and easy to miss if you haven't rechecked your position since.
- This is an orientation tool, not a legal determination. Use the matrix to identify which frameworks deserve a closer look, then confirm your specific position with a qualified adviser.
The scope matrix
The table below uses standard EU size bands (Commission Recommendation 2003/361/EC) as the starting axis. It shows how each framework applies in practice, since for several of these, headcount isn't the main test.
This matrix summarises general tests only. NIS2, CRA, DORA, and AML/CFT are driven primarily by sector and activity, not headcount: a company can sit squarely in scope at any size if it's a covered entity type. Confirm your specific position with a qualified adviser; this table is a starting point for orientation, not a scope determination for your organisation.
Reading the matrix for your situation
A 300-person B2B software company selling to enterprises almost certainly falls under GDPR (it processes personal data), likely under the AI Act if any product feature uses AI, and likely under NIS2 if it supplies critical sectors or sits in one itself. If it places any product with digital elements on the market, which covers most software, the Cyber Resilience Act applies too. It probably sits outside CSRD, DORA, and AML/CFT scope unless it's specifically a financial entity or a reporting company.
A 150-person regional bank or payment institution falls under GDPR, DORA (directly, regardless of size), and AML/CFT as an obliged entity. NIS2 likely applies as a financial-sector entity, and the AI Act may apply depending on its systems and any AI-driven credit or fraud tools. CSRD sits outside scope unless the company crosses the 1,000-employee/€450M threshold.
An 800-person industrial manufacturer falls under GDPR and the Cyber Resilience Act if any of its products carry digital elements, increasingly common even in traditional manufacturing. NIS2 likely applies depending on sector. Since Omnibus I, the manufacturer very likely sits outside direct CSRD scope now that the threshold moved to 1,000 employees, though it may still receive value-chain sustainability-data requests from larger customers (see our CSRD guide for the value-chain cap).
What changed recently, and why it's worth checking again
Two things shifted in the last 12 months that move where midcaps land on this matrix:
- CSRD's threshold rose sharply. Before March 2026, a 300-person company with modest turnover could sit inside CSRD scope. Since Omnibus I, the threshold is 1,000 employees and €450 million turnover. Many midcaps that budgeted for CSRD compliance now sit outside direct scope (see our full CSRD guide ).
- DORA's third-party pillar became live-enforced. The November 2025 designation of the first critical ICT third-party providers means DORA's third-party risk-management pillar is no longer theoretical for financial entities and their vendors (see our DORA guide ).
If you last checked your regulatory position more than six months ago, recheck it. Not because new rules appeared, but because the boundaries of the existing ones moved.
Frequently Asked Questions
Chief Regulation Untangler
Product Development
Strategy
AI Expert
This article provides general information on EU regulatory scope. It does not constitute legal advice. The matrix above is an orientation tool: it does not replace a lawyer, auditor, or specialist adviser's assessment of your organisation's specific position. Sources: see the individual framework guides linked above, each with its own primary-source citations, cross-checked 24 August 2026. Last updated: September 18, 2026.