CABIER Global Assurance · Europe
Europe: one connected rulebook
DORA, NIS2, the AI Act, MiCA and AMLR overlap on the same institutions. CABIER treats them as one connected set, so one event and one control can answer several instruments at once.
Mapping only, not legal advice. Reporting clocks are summarised; check the primary text before reliance.
The five regimes
DORA
ICT risk, incident reporting, testing and third-party risk for financial entities.
Gate: Resilience
NIS2
Cyber risk management and incident notification for essential and important entities.
Gate: Security
AI Act
Risk-based obligations on AI providers and deployers, including general-purpose models.
Gate: Policy
MiCA
Authorisation and conduct for crypto-asset service providers and token issuers.
Gate: Regulatory
AMLR and AMLA
A single anti-money-laundering rulebook and an EU-level supervisor.
Gate: Regulatory
Reporting clocks side by side
DORA
Initial notice within 4 hours of classifying a major incident (and no later than 24 hours from detection); intermediate at 72 hours; final within one month.
NIS2
Early warning within 24 hours; incident notification within 72 hours; final report within one month.
AI Act
Serious incident reports from providers of high-risk systems within 15 days, shorter for critical infrastructure and deaths.
MiCA
Notify the competent authority of events affecting authorisation conditions and client assets without undue delay.
AMLR
Suspicious transactions reported to the financial intelligence unit promptly; no tipping-off.
How they connect
One incident, five views
A compromised AI-driven custody workflow at a crypto-asset service provider can engage all five regimes at once. CABIER records the event once in TrustGraph and derives each regime's obligation, clock and recipient from it.
One control, several answers
An ICT third-party register satisfies DORA, supports NIS2 supply-chain duties and supplies the provider chain the AI Act expects deployers to know. The control is written once and cited by each instrument.
Lead regime by entity
For a financial entity, DORA is the lead ICT regime and NIS2 applies through it. The platform records which regime leads for each legal entity so reports are not duplicated or missed.
Honest dates
AI Act high-risk dates subject to the proposed amendment are shown as pending until the Official Journal text is confirmed.
Last regulatory review: 26 September 2026. Mapping only – not legal advice.
In force, in transition, proposed or stalled.
See where each instrument stands