What ‘Products With Digital Elements’ Actually Means Under the CRA

“Products with digital elements” sounds like it means smart devices and IoT gadgets. Read the Cyber Resilience Act’s actual definition and the scope is far wider — wide enough that a board assuming the CRA is someone else’s problem is very often wrong, and wrong in a way that only surfaces once a product is …

Read more

NIS2 vs CRA: Why ‘Entity’ and ‘Product’ Obligations Don’t Merge Into One Programme

NIS2 and the CRA are frequently discussed as if they’re the same regulatory push wearing two names. They regulate two entirely different things, aimed at two entirely different actors — and an organisation that’s mapped one against its obligations has often mapped nothing useful against the other. I’ve written separately about NIS2’s essential-entity obligations and …

Read more

The AI Act’s Obligations, Translated Into Actual Engineering Deliverables

Ask a compliance team what the AI Act requires and you get articles and annexes. Ask the engineering team building the actual system and you get a shrug, because nobody has translated “conduct a fundamental rights impact assessment” into a sprint they can actually plan. That translation gap is where AI Act compliance programmes quietly …

Read more

Writing a Technology Strategy That Actually Fits on Two Pages

Most technology strategy documents are unread by design. Forty pages, a dozen slides of architecture diagrams, an executive summary nobody wrote last because nobody was forced to compress the argument first. A strategy that can’t fit on two pages usually isn’t a strategy — it’s an inventory wearing a strategy’s title. The length isn’t the …

Read more

Book a Pillar 05 - Decision Rights & Accountability scoping call