Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 21 April 2026 the European Commission issued a conditional clearance under the EU Foreign Subsidies Regulation (FSR, Regulation 2022/2560), requiring the exclusion of CRRC (China's largest rolling-stock manufacturer) from the Lisbon Metro Violet Line procurement — the first-ever FSR procurement remedy ordering a Chinese supplier exclusion from a specific EU public contract. The Commission found that CRRC received foreign subsidies enabling it to submit an unduly advantageous tender, and as a condition of clearance mandated CRRC's removal from the tender. CRRC was replaced by PESA (Polish rail manufacturer) as the selected bidder. Unlike the 2024 Bulgaria/CRRC case (FSP.100147) where CRRC voluntarily withdrew before a formal decision, the Lisbon case produced the first binding FSR exclusion remedy, establishing mandatory supplier-removal as an available enforcement outcome in EU public procurement.
On 4 March 2026 the Council of the EU adopted its general approach (negotiating position) on proposed amendments to the Critical Raw Materials Act (Regulation (EU) 2024/1252) under the RESourceEU package. The Council position transfers from member states to the European Commission the responsibility for identifying large companies using critical raw materials and mandates Commission notification to member states and company boards of CRM supply risks. It endorses mandatory permanent-magnet labelling and recycled-content declarations, product passports for permanent-magnet information obligations, and expanded Commission authority to propose risk-mitigation measures. Adoption of the general approach unlocks interinstitutional trilogue negotiations with the European Parliament.
Directive (EU) 2026/470 of 24 February 2026, published in the EU Official Journal on 26 February 2026 and entered into force on 18 March 2026, amends the Corporate Sustainability Reporting Directive (CSRD, Directive (EU) 2022/2464) and the Corporate Sustainability Due Diligence Directive (CSDDD, Directive (EU) 2024/1760). It raises CSRD scope thresholds to undertakings with more than 1,000 employees and more than EUR 450 million net turnover, raises CSDDD scope thresholds to entities with more than 5,000 employees and EUR 1.5 billion turnover (and non-EU entities with EUR 1.5 billion EU turnover), drops the requirement to adopt or put into effect a climate transition plan under CSDDD, and replaces reasonable-assurance with limited-assurance for CSRD reports. CSRD-related provisions must be transposed by 19 March 2027; CSDDD-related provisions by 26 July 2028.
On 3 February 2026 the European Commission opened an in-depth Phase II investigation under the Foreign Subsidies Regulation (FSR) — the second FSR ex officio case and the first targeting the renewable-energy wind-OEM sector — into whether Xinjiang Goldwind Science & Technology Co., Ltd. and its EU affiliates received Chinese foreign subsidies (grants, preferential tax treatment, and state-bank preferential financing) that distort competition for wind-turbine supply and services in the EU internal market. The case (FS.100143) follows the April 2024 preliminary-review opening and subjects Goldwind to an 18-month Phase II investigation with potential redressive-measures decision. The action structurally extends the FSR enforcement perimeter from security equipment (Nuctech, FS.100068) into the green-transition energy-equipment supply chain.
Regulation (EU) 2026/261 of the European Parliament and of the Council (adopted 26 January 2026, in force 3 February 2026) sets a legally binding stepwise ban on imports of Russian-origin natural gas — both liquefied (LNG) and pipeline. Russian LNG under short-term contracts signed before 17 June 2025 is prohibited from 25 April 2026; long-term LNG contracts from 1 January 2027. Russian pipeline gas under short-term contracts is prohibited from 17 June 2026; long-term pipeline gas from 30 September 2027 (latest 1 November 2027 if EU storage targets remain on track). The regulation operates outside the Russia-sanctions architecture (Article 215 TFEU) as a REPowerEU internal-market instrument, with narrow operational-amendment carve- outs and no provision for volume increases.
The European Commission adopted Communication C(2026) 43 final on 9 January 2026, issuing the first formal interpretive guidelines on the Foreign Subsidies Regulation (FSR, Regulation (EU) 2022/2560). The guidelines codify a four-pillar analytical framework — distortion assessment, public-procurement distortion test, balancing test, and ex officio call-in scope — that DG COMP will apply in every future FSR enforcement proceeding. As the operational blueprint for the FSR regime, the guidelines materially shape Chinese SOE and Gulf SWF EU-market access planning for concentrations, public-procurement tenders, and sub-threshold transactions.
In the early hours of 11 December 2025 the Council of the EU and the European Parliament reached provisional political agreement in trilogue on the "EU Pharma Package" — the revised pharmaceutical Regulation (COM 2023/0131) and Directive (COM 2023/0132) — the most significant overhaul of EU pharmaceutical legislation in over two decades. The package replaces Directive 2001/83/EC (Community Code on medicinal products for human use) and Regulation (EC) 726/2004 (the EMA Regulation), and consolidates the orphan-medicine (Regulation 141/2000) and pediatric-medicine regulations into a single framework. Headline provisions: (i) a new "8+1(+1)(+1)" IP-incentive architecture — 8 years of regulatory data protection plus 1 year of market protection, with up to two additional 12-month extensions for products addressing unmet medical need or new active substances meeting comparative-trial conditions, capped at 11 years total; (ii) an EU-wide list of critical medicines under enhanced governance via the Medicines Shortages Steering Group (MSSG) and an EMA "list of critical shortages in the EU"; (iii) mandatory shortage-prevention plans on marketing-authorisation holders for prescription medicines and Commission-designated products; (iv) modernisation of clinical-trial requirements, environmental-risk assessment, antimicrobial stewardship, and a transferable-exclusivity-voucher (TEV) regime to incentivise novel antibiotic R&D. The COREPER I committee endorsed the compromise text on 6 March 2026 and final adoption by Parliament and Council is expected during summer 2026, with the regulatory framework becoming applicable in 2028.
On 10 December 2025 the European Commission opened an in-depth investigation under the Foreign Subsidies Regulation (FSR) — its first ex officio Phase II investigation — into whether Chinese state-controlled security-scanner producer Nuctech received foreign subsidies enabling it to offer prices and conditions that EU competitors could not match across airport, port, and border-crossing markets. Nuctech Technology, controlled by Tsinghua Tongfang (PRC state-linked), operates EU subsidiaries in Poland and the Netherlands (Nuctech Warsaw and Nuctech Netherlands), supplying threat-detection scanners to roughly 80% of EU airports and 70% of EU sea and land border crossings. The case (FS.100068) followed April 2024 unannounced FSR dawn raids at Nuctech's Polish and Dutch premises — one of the first uses of FSR inspection powers — and sets a precedent for ex officio scrutiny of state-subsidised foreign incumbents beyond the M&A and public-procurement tracks where FSR had previously operated.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
On 25 June 2025 the European Commission adopted COM(2025) 335 final, a proposed Regulation establishing a single market for space activities — the first EU-level framework harmonising the authorisation, registration and supervision of space activities across Member States, replacing 13 fragmented national regimes. The Act rests on three pillars: safety (mandatory tracking of space objects, space- debris mitigation rules, an EU registry of space objects), resilience (cybersecurity requirements scaled to company size and risk profile) and sustainability (environmental impact assessment and active debris-removal R&D). It applies to both EU and non-EU operators providing space services in Europe, giving it extraterritorial reach over SpaceX/Starlink, Amazon Kuiper, OneWeb, Chinese SatNet/G60 and ISRO. The proposal is being negotiated under the ordinary legislative procedure; the Competitiveness Council of 9 December 2025 broadly endorsed its objectives, and the public consultation closed on 7 November 2025.
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
Regulation (EU) 2025/40, published in the Official Journal on 22 January 2025 and entering into force on 11 February 2025, replaces the 1994 Packaging and Packaging Waste Directive 94/62/EC with a directly-applicable Regulation. It mandates binding recycled-content targets for plastic packaging (by polymer and format, reaching 30–65% by 2030 with higher targets by 2040), minimum reusable-packaging shares for beverages and transport, recyclability standards for all packaging placed on the EU market from 2030, deposit-return-scheme obligations for beverage containers from 2029, and bans on specified single-use plastic packaging formats. General application begins 12 August 2026, with staggered compliance windows extending to 2030 and beyond, affecting all non-EU exporters shipping consumer goods, beverages, or e-commerce fulfilment into the EU single market.
Regulation (EU) 2024/3015 of the European Parliament and of the Council of 27 November 2024 establishes the first EU-wide binding prohibition on placing, making available on, or exporting from the EU single market any products made with forced labour at any stage of production, manufacture, harvest, extraction or processing. The regulation is cross-sector and horizontal — no sectoral exemptions apply. It entered into force on 13 December 2024, with a phased implementation schedule; procedural and institutional framework provisions apply from 13 December 2024, while full operational application begins on 14 December 2027. The regulation empowers national competent authorities (and the Commission for state-imposed forced-labour cases involving third countries) to investigate, require withdrawal, and order destruction of non-compliant goods, and establishes a Commission-maintained publicly accessible database of high-risk geographic areas, sectors, and products.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
Regulation (EU) 2024/2747, adopted on 9 October 2024 and published in the Official Journal on 8 November 2024, establishes the EU's first dedicated framework to anticipate, prepare for and respond to crises affecting the internal market. IMERA creates a two-tier "vigilance" / "emergency" mode architecture, sets up the Internal Market Emergency and Resilience Board (IMERB) to coordinate Member States and advise the Commission, and equips the Commission with last-resort powers including mandatory information requests to economic operators, priority-rated orders for crisis-relevant goods, fast-track conformity-assessment procedures, and rules to safeguard free movement of goods, services and persons. The regulation amends Council Regulation (EC) No 2679/98 (the "Strawberries Regulation") and becomes applicable on 29 May 2026.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation (ESPR), replaces the 2009 Ecodesign Directive with a cross-cutting product-sustainability framework covering nearly all physical goods placed on the EU single market. It empowers the Commission to adopt binding delegated acts setting ecodesign requirements (durability, reparability, recyclability, recycled content, chemical restrictions, energy and resource efficiency) by product category, establishes a mandatory Digital Product Passport (DPP) for supply-chain traceability, and bans the destruction of unsold consumer products. The regulation entered into force on 18 July 2024; the Commission's first ESPR and Energy Labelling Working Plan (2025–2030, COM(2025) 187) was adopted in April 2025, prioritising textiles, furniture, tyres, electronics, and iron/steel/aluminium.
Directive (EU) 2024/1760, adopted 13 June 2024 and entering into force 25 July 2024, imposes binding human-rights and environmental due-diligence obligations on large in-scope EU and non-EU companies across their chains of activities (upstream supply chain, own operations, and a limited part of downstream distribution). In-scope companies must identify, prevent, mitigate, and bring to an end actual and potential adverse human-rights and environmental impacts — covering forced labour, child labour, hazardous chemicals, and biodiversity loss — with obligations phased in from FY 2027 (EU companies with >5 000 employees and >EUR 1.5 bn turnover) through FY 2029 (>1 000 employees and >EUR 450 m). Companies must also adopt a climate transition plan compatible with the Paris Agreement 1.5 °C pathway (Art 22), and face civil liability for damages in national courts (Art 29); the original transposition deadline of 26 July 2026 was postponed and scope narrowed by the EU Omnibus I package (Directive 2026/470).
The European Commission formally notified the Republic of Senegal on 27 May 2024 of the possibility of being identified as a non-cooperating third country in fighting illegal, unreported and unregulated (IUU) fishing, under Article 32 of Regulation (EC) No 1005/2008. The decision (C/2024/3277) cites specific shortcomings in Senegal's monitoring, control and surveillance (MCS) of Senegalese-flagged vessels operating outside national waters, inadequate oversight of foreign vessels using Dakar port as a transhipment hub, and traceability failures enabling illegal fish exports to the EU. A formal dialogue period now opens during which Senegal must remediate identified deficiencies; failure to do so would lead to red-card escalation and a full EU import prohibition on Senegalese seafood.
On 3 April 2024 the European Commission opened two simultaneous FSR Phase II in-depth investigations — the second and third ever under the Foreign Subsidies Regulation (Regulation 2022/2560) — concerning a Romanian public-procurement procedure for the design, construction and operation of a 454.97 MW EU-co-funded photovoltaic park (Rovinari Est). The first investigation targeted the ENEVO Group consortium including LONGi Solar Technologie GmbH (German subsidiary wholly owned by HK-listed LONGi Green Energy Technology Co., Ltd.); the second targeted Shanghai Electric UK Co. Ltd. and Shanghai Electric Hong Kong International Engineering Co., Ltd. (Chinese SOE). Both respondents withdrew from the procurement procedure after the Commission's opening; the Commission subsequently closed both investigations. This was the first FSR Phase II enforcement action in the renewable-energy / solar-PV sector and the first targeting a private Chinese-listed company's EU subsidiary.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
On 16 February 2024 the European Commission opened case FSP.100147, the first-ever in-depth Phase II investigation under the EU Foreign Subsidies Regulation (FSR, Regulation 2022/2560), to examine whether Chinese state-owned CRRC Qingdao Sifang Locomotive Co. Ltd. received foreign subsidies enabling it to submit an unduly advantageous tender for a EUR 614 million Bulgarian Ministry of Transport contract covering 20 zero-emission electric push-pull trains and 15 years of maintenance. The Commission identified approximately EUR 1.745 billion in total foreign financial contributions to CRRC — roughly five times the bid value. CRRC withdrew its tender on 26 March 2024 before the Commission could issue a final decision; the Commission closed the investigation following the withdrawal.
Regulation (EU) 2023/2842, published in the Official Journal on 20 December 2023, is the first comprehensive recast of the EU fisheries control framework since Council Regulation (EC) No 1224/2009, and amends the IUU Regulation (EC) No 1005/2008 alongside five sectoral regulations (1967/2006, 2016/1139, 2017/2403, 2019/473). Effective in phases from 10 January 2026, it mandates the CATCH electronic catch-certification IT system for ALL imports of wild-capture marine fishery products into the EU single market, replacing legacy paper catch certificates. It also introduces Remote Electronic Monitoring (REM) with CCTV on high-risk EU vessels ≥18 m, full electronic reporting for all vessels by 2028, and extended Vessel Monitoring System (VMS) coverage down to vessels ≥12 m. The regulation tightens the carding regime (red/yellow cards for non-cooperating flag states under the amended IUU Regulation) and requires digital traceability end-to-end through the supply chain, raising compliance cost and market-access barriers for all non-EU seafood exporters.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
Regulation (EU) 2023/2675 — the Anti-Coercion Instrument (ACI) — is the EU's first horizontal trade-defence framework explicitly empowering the Union to respond to economic coercion by third countries. Adopted by the European Parliament and Council on 22 November 2023, published in the Official Journal on 7 December 2023, and in force from 27 December 2023, it lets the European Commission (i) determine that a third country is applying economic coercion against the Union or a Member State, (ii) seek dialogue, cessation, and reparation, and (iii) impose Union response measures — including tariffs, services-trade restrictions, IP-rights restrictions, public-procurement restrictions, and FDI restrictions targeting nationals or controlled entities of the coercing state. It complements but does not duplicate the Foreign Subsidies Regulation (which addresses subsidies, not coercion).
Regulation (EU) 2023/1542 establishes a comprehensive EU statutory framework for all battery categories (portable, SLI, LMT, EV, industrial), imposing supply-chain due-diligence obligations for cobalt, lithium, nickel, and natural graphite; mandatory recycled-content thresholds; carbon-footprint declarations; a digital battery passport; and ambitious collection and recycling-efficiency targets, with rolling application dates running from February 2024 through August 2036. It repeals Battery Directive 2006/66/EC and applies to every economic operator placing batteries on the EU market, binding every EV, consumer-electronics, and stationary-storage supply chain that relies on DRC cobalt, Australian/Chilean lithium, Indonesian/Philippine nickel, and Chinese/Mozambican graphite.
Regulation (EU) 2023/1115, adopted 31 May 2023 and in force 29 June 2023, requires all EU operators and traders placing seven in-scope commodities and their derived products on the EU market — or exporting them from the EU — to file due-diligence statements certifying that goods are deforestation-free (no land cleared after 31 December 2020) and produced in compliance with the relevant legislation of the country of origin. A Commission-administered risk-classification system assigns producer countries to low, standard, or high-risk tiers with differentiated due-diligence burdens. Application was subsequently postponed twice: to 30 December 2026 for large operators (Reg (EU) 2024/3234 and Reg (EU) 2025/2650).
Regulation (EU) 2023/956 of the European Parliament and of the Council, published in OJ L 130 on 16 May 2023 and entering into force on 17 May 2023, establishes the EU Carbon Border Adjustment Mechanism (CBAM) — the Union's primary instrument for preventing carbon leakage at the external border. The regulation applies an equivalent carbon price to embedded greenhouse gas emissions in imports of six sector groups (iron and steel, aluminium, cement, fertilizers, electricity, and hydrogen) from non-EU/EEA/Swiss counterparts, complementing the EU Emissions Trading System's domestic coverage. A transitional reporting-only phase operated from 1 October 2023 through 31 December 2025; the definitive certificate-purchase-and-surrender regime entered full application from 1 January 2026.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
Council Directive (EU) 2022/2523, adopted 14 December 2022 and published in OJ L 328 on 22 December 2022, transposes the OECD/G20 Inclusive Framework Pillar Two model rules into binding EU law. It requires all 27 Member States to impose a minimum 15% effective tax rate (ETR) on the jurisdictional income of MNE groups with consolidated annual revenue ≥ EUR 750 million via three interlocking charges: an Income Inclusion Rule (IIR) for fiscal years beginning on or after 31 December 2023, an Undertaxed Profits Rule (UTPR) backstop from 31 December 2024, and an optional Qualified Domestic Minimum Top-up Tax (QDMTT). The directive is the largest international-tax instrument in EU history and the operative legal anchor for the cross-border Pillar Two architecture inside the single market, structurally rebalancing FDI location decisions for an estimated 12,000+ in-scope MNE groups globally.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).