CABIER Global Assurance · Europe

    Europe: one connected rulebook

    DORA, NIS2, the AI Act, MiCA and AMLR overlap on the same institutions. CABIER treats them as one connected set, so one event and one control can answer several instruments at once.

    Mapping only, not legal advice. Reporting clocks are summarised; check the primary text before reliance.

    The five regimes

    DORA

    ICT risk, incident reporting, testing and third-party risk for financial entities.

    Gate: Resilience

    NIS2

    Cyber risk management and incident notification for essential and important entities.

    Gate: Security

    AI Act

    Risk-based obligations on AI providers and deployers, including general-purpose models.

    Gate: Policy

    MiCA

    Authorisation and conduct for crypto-asset service providers and token issuers.

    Gate: Regulatory

    AMLR and AMLA

    A single anti-money-laundering rulebook and an EU-level supervisor.

    Gate: Regulatory

    Reporting clocks side by side

    DORA

    Initial notice within 4 hours of classifying a major incident (and no later than 24 hours from detection); intermediate at 72 hours; final within one month.

    NIS2

    Early warning within 24 hours; incident notification within 72 hours; final report within one month.

    AI Act

    Serious incident reports from providers of high-risk systems within 15 days, shorter for critical infrastructure and deaths.

    MiCA

    Notify the competent authority of events affecting authorisation conditions and client assets without undue delay.

    AMLR

    Suspicious transactions reported to the financial intelligence unit promptly; no tipping-off.

    How they connect

    One incident, five views

    A compromised AI-driven custody workflow at a crypto-asset service provider can engage all five regimes at once. CABIER records the event once in TrustGraph and derives each regime's obligation, clock and recipient from it.

    One control, several answers

    An ICT third-party register satisfies DORA, supports NIS2 supply-chain duties and supplies the provider chain the AI Act expects deployers to know. The control is written once and cited by each instrument.

    Lead regime by entity

    For a financial entity, DORA is the lead ICT regime and NIS2 applies through it. The platform records which regime leads for each legal entity so reports are not duplicated or missed.

    Honest dates

    AI Act high-risk dates subject to the proposed amendment are shown as pending until the Official Journal text is confirmed.

    Last regulatory review: 26 September 2026. Mapping only – not legal advice.

    In force, in transition, proposed or stalled.

    See where each instrument stands