Back to GRC

EU Cybersecurity and Privacy Regulations for SaaS: Which Ones Apply to You?

EU cybersecurity regulations for SaaS illustration: six regulation cards connected to a single shielded control library

Short answer: Most SaaS companies that process personal data of people in the EU must comply with GDPR. NIS 2 covers many cloud, managed service and digital providers above size thresholds. DORA arrives through contracts with EU financial firms, the AI Act applies to AI systems you build or deploy, and the Cyber Resilience Act mainly targets products rather than pure SaaS.

Related guides:

Key takeaways

  • The EU regulates security through several overlapping laws. Each has its own scope test, so start by asking "does this one apply to us?" rather than trying to comply with all of them at once.
  • GDPR is the baseline for anyone processing personal data of people in the EU, including companies with no EU office.
  • NIS 2 and DORA focus on operational resilience. NIS 2 applies directly to in-scope entities. DORA mostly reaches SaaS vendors through the contracts their financial customers must sign.
  • The AI Act, Cyber Resilience Act and Data Act apply based on what you build: AI systems, products with digital elements, or cloud and data processing services.
  • The controls behind these laws overlap heavily. One well-run security program, mapped to each regulation, is far cheaper than separate projects.

Which EU regulations matter for SaaS companies?

Six regulations cover most of what a SaaS company selling into Europe will encounter, and each is triggered by a different factor.

Regulation Applies from Main trigger for a SaaS company Core security themes
GDPR May 25, 2018 Processing personal data of people in the EU Security of processing, breach notification, processor contracts
NIS 2 National laws, transposition deadline October 17, 2024 Being a medium or large provider in a listed sector, such as cloud or managed services Risk management measures, incident reporting, management accountability
DORA January 17, 2025 Selling ICT services to EU financial entities Contractual requirements, resilience testing support, exit plans
AI Act Phased from February 2, 2025; most high-risk rules from December 2, 2027 Providing or deploying AI systems in the EU Risk classification, transparency, governance of high-risk AI
Cyber Resilience Act Reporting duties from September 11, 2026; most obligations from December 11, 2027 Placing products with digital elements on the EU market Secure-by-design, vulnerability handling, SBOMs
Data Act September 12, 2025 Offering cloud or data processing services, or connected products Cloud switching, data portability, data access

Use the sections below to test each one against your business.

GDPR: does it apply if you are not based in the EU?

Yes, if you offer services to people in the EU or monitor their behavior, GDPR applies to you wherever you are established.

For most B2B SaaS companies, you act as a processor for customer data and a controller for your own marketing, billing and account data. The security obligations that matter most are:

  • Article 32: appropriate technical and organizational measures, such as encryption, access control, resilience and regular testing.
  • Article 28: a data processing agreement with each customer and flow-down terms with your sub-processors.
  • Breach notification: controllers notify the supervisory authority within 72 hours of becoming aware of a qualifying breach, and processors must inform controllers without undue delay.
  • International transfers: a valid mechanism, such as the EU-US Data Privacy Framework or standard contractual clauses, for data leaving the EU.

HealthTech companies should note that health data is a special category under Article 9, which raises the bar for lawful basis and security. Our step-by-step GDPR guide for US companies, linked above, covers the practical setup.

NIS 2: is your SaaS company an essential or important entity?

You are likely in scope if you provide cloud computing, data center, managed or managed security services, or certain digital platforms in the EU and you are at least a medium-sized enterprise.

NIS 2 replaced the original NIS Directive and expanded the list of covered sectors. Key points for SaaS and infrastructure providers:

  1. Size threshold. Under Article 2 of the directive, NIS 2 generally applies to entities that are medium-sized or larger as defined in Commission Recommendation 2003/361/EC, which sets the staff headcount and financial thresholds. Some member states go beyond this minimum, so check the national law and confirm borderline cases with counsel. Some providers are covered regardless of size, including providers of public electronic communications networks or services, trust service providers, top-level domain name registries and DNS service providers.
  2. Risk management measures. Policies on risk analysis, incident handling, business continuity, supply chain security, secure development, cryptography, access control and MFA.
  3. Incident reporting. Under Article 23, an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours that updates the early warning, and a final report within one month of that incident notification. National laws define "significant incident" and reporting channels in more detail, so check the rules in each member state where you operate.
  4. Management accountability. Management bodies must approve and oversee the measures and can be held liable.
  5. Non-EU providers. Under Article 26, certain providers established outside the EU that offer services in the EU, including cloud computing, data center, managed and managed security service providers, must designate a representative in a member state where they offer services.

Because NIS 2 is a directive, each member state writes its own law, and several transposed late. Check the national rules in the countries where you operate. Our NIS 2 scope guide, linked above, walks through the entity classifications in detail.

DORA: what changes when you sell to EU financial firms?

DORA applies directly to financial entities, but if your SaaS supports their operations, you will feel it through contract terms, due diligence and audit rights.

EU banks, insurers, payment institutions and investment firms must manage ICT third-party risk and include specific provisions in contracts with ICT service providers. Expect requests for:

  • Clear service descriptions, locations of data processing and service levels.
  • Incident notification and cooperation commitments.
  • Access, inspection and audit rights for the customer and its regulators.
  • Participation in the customer's resilience testing, where relevant.
  • Termination rights and exit plans that allow orderly transition.

A small number of providers may be designated as critical ICT third-party providers and placed under direct EU oversight. Most SMB vendors will not be, but will still need DORA-ready contract terms. The DORA compliance checklist explains what your financial customers are working through.

EU AI Act: when do your AI features create obligations?

The AI Act applies when you provide or deploy an AI system in the EU, and your obligations depend on the system's risk category.

The regulation entered into force on August 1, 2024 and applies in phases. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force in July 2026 and postponed the high-risk rules. The key dates now are:

  • February 2, 2025: prohibitions on certain AI practices.
  • August 2, 2025: obligations for general-purpose AI model providers.
  • August 2, 2026: Article 50 transparency obligations. Providers of systems that generate synthetic audio, image, video or text have until December 2, 2026 to meet the Article 50(2) marking requirements.
  • December 2, 2027: obligations for high-risk systems listed in Annex III, such as those used in employment or credit decisions.
  • August 2, 2028: obligations for AI embedded in products covered by EU product legislation, such as medical devices.

The Omnibus also revised the AI literacy provision in Article 4. Check the amended regulation text on EUR-Lex for the current wording of any provision you rely on.

For most SaaS companies with AI features such as chat assistants, summarization or recommendations, the practical obligations are transparency (users should know they are interacting with AI) and good governance. If your AI is used in areas the Act lists as high-risk, such as employment decisions, credit scoring or certain medical uses, expect requirements for risk management, data governance, logging, human oversight and conformity assessment. See our EU AI Act compliance guide for the categories.

Cyber Resilience Act and Data Act: do they cover pure SaaS?

The Cyber Resilience Act mostly does not cover standalone SaaS, while the Data Act does affect cloud and data processing services.

Cyber Resilience Act (CRA). The CRA applies to products with digital elements placed on the EU market, such as installable software, mobile apps, firmware and connected devices. Standalone SaaS generally falls outside its scope, since cloud services are mainly regulated through NIS 2. It can still reach you if you ship desktop agents, SDKs, on-premises versions or connected hardware, or if your cloud backend is a remote data processing solution without which such a product could not perform one of its functions. Vulnerability and incident reporting duties have applied since September 11, 2026, and most other obligations apply from December 11, 2027.

Data Act. The Data Act has applied since September 12, 2025. For SaaS and cloud providers, the main impact is on switching: contracts must allow customers to move to another provider or on-premises, with defined notice periods and support. Until January 12, 2027, providers may charge only reduced switching charges that do not exceed their direct costs, and after that date switching charges are abolished (Article 29). Providers of connected products also face data access requirements. More detail is in our overview of the EU Data Act.

How do you run one program for several EU regulations?

Build one security and privacy control set, map each control to every regulation it satisfies, and manage the regulation-specific pieces as small add-ons.

A workable approach for an SMB:

  1. Scope first. Record which regulations apply, why, and which products and entities are in scope. Revisit this when you enter a new market or launch a new product.
  2. Anchor on a framework. ISO 27001 maps well to GDPR Article 32 and NIS 2 risk management measures, and it partly supports the ICT risk expectations your DORA customers will check, though DORA's contract terms still need separate handling. Many teams pair it with SOC 2 for US buyers.
  3. Unify incident handling. One process with regulation-specific clocks: 72 hours for GDPR supervisory authorities, 24 and 72 hours for NIS 2, and whatever your DORA contracts specify.
  4. Centralize vendor risk. GDPR sub-processors, NIS 2 supply chain security and DORA ICT third-party risk all draw on the same vendor inventory.
  5. Keep contract terms modular. Maintain a standard DPA, a DORA addendum and Data Act switching terms so legal reviews do not start from zero.
  6. Track the calendar. Several of these laws apply in phases, so a dated roadmap avoids surprises.

How SecureSlate helps

SecureSlate helps SMBs and HealthTech teams map one control library across GDPR, DORA, ISO 27001, SOC 2, HIPAA and more. Automated evidence collection and vendor risk management help you track where a new EU requirement is already covered by existing controls, which can reduce the effort of adding it to your program. You can then share evidence with customers and assessors from one place.

Start your free SecureSlate trial

FAQ

Does a US SaaS company need to comply with EU regulations?

In many cases, yes. GDPR applies to companies outside the EU that offer services to people in the EU or monitor their behavior. NIS 2 can apply to non-EU providers offering in-scope services in the EU, which may need to designate an EU representative. DORA requirements arrive through contracts with EU financial customers.

Is ISO 27001 enough to comply with NIS 2 or GDPR?

No single certification guarantees compliance, but ISO 27001 covers a large share of the security measures these laws require. You still need regulation-specific elements such as GDPR processing records, NIS 2 incident reporting timelines and DORA contract terms.

Which EU regulation should a startup tackle first?

Usually GDPR, because it applies once you process personal data of people in the EU while offering them services or monitoring their behavior. Then assess NIS 2 scope as you grow past the size thresholds, and DORA or the AI Act if your customers or product features trigger them.

Do these regulations apply to healthcare software?

Yes. GDPR treats health data as a special category, NIS 2 lists healthcare among covered sectors, and AI used in medical devices can be high-risk under the AI Act. The European Health Data Space Regulation will add further requirements for some health data systems as it phases in over the coming years.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

Keep reading

Oct 2, 2026 · GRC

Risk Acceptance: When to Accept a Risk, Who Signs Off and What to Document

Oct 1, 2026 · GRC

Inherent Risk vs Residual Risk: Definitions, Scoring and a Worked Example

Oct 1, 2026 · GRC

Japan Compliance Frameworks: A Buyer-Driven Map for SaaS and HealthTech Vendors

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?