The Compliance Maze: Why "Are We Compliant?" No Longer Has a Simple Answer
A decade ago, "are we compliant?" had one owner and one answer. Today the honest answer is "compliant with what, in which capacity, as of which date?" That shift, from a question to a maze, is the most under-managed risk in European business.

Part of the pillar series Sovereignty You Can Actually Operate.
This is practical guidance for compliance teams, not legal advice; your obligations depend on your jurisdiction, sector and facts. Current as of July 2026.
Consider a mid-sized European SaaS company. It processes personal data, so it falls under GDPR. It operates in a covered sector above the size threshold, so it falls under NIS2. It sells software into the EU market, so the Cyber Resilience Act applies to its product. It ships an AI feature, so the AI Act applies. If it serves banks, its customers pull it into DORA. Five laws, five different triggers, five sets of obligations, deadlines, and penalties, landing on the same organization at the same time.
None of them replaced the others. They stacked. And that stacking is why "are we compliant?" stopped being a checkbox and became the subject of this whole series.
The maze is real, but it is not random
Here's the good news buried in the complexity. When you lay these laws side by side, they target different legal objects (personal data, cyber risk, financial resilience, AI systems, products), but they demand strikingly similar organizational work. Every one of them asks you to:
- define scope and inventory your systems, data, and suppliers;
- assign accountable owners (increasingly at board level);
- assess risk and treat it;
- document controls and operate them;
- oversee third parties;
- detect, handle, and report incidents;
- and, the thread through all of it, retain evidence that you actually did these things.
The report underpinning this series calls these the shared control domains, and there are only about seven of them. That is the single most useful fact in compliance today: the laws differ in what they govern, not in the work they force you to do.
Why it feels impossible anyway
If the underlying work overlaps, why does compliance feel like it's multiplying? Because most organizations run it the way the laws are written: one program per law.
Each new law becomes another project, another questionnaire, another spreadsheet, another audit binder; and, quietly, another copy of the same "truth" that will drift out of sync with the others. This produces two failure modes worth naming:
- Duplication. You implement, document, and evidence access control four times because four frameworks ask for it, instead of once.
- Evidence theater. Policies and questionnaires get produced faster than the working, inspectable controls behind them. You have a binder that says you're compliant and no traceable proof that you are.
Add an EU cybersecurity workforce gap of roughly 299,000 (ISC2, 2024), and the spreadsheet model doesn't just underperform: it burns out the team and still fails audits.
The stakes, in plain numbers
This isn't abstract. The penalty ceilings across the stack are real and, increasingly, enforced.
| Law | Max penalty | Enforcement signal |
|---|---|---|
| GDPR | €20M or 4% of global turnover | Over €6bn in cumulative fines to date |
| NIS2 | €10M or 2% (essential entities) | Commission referred 4 states to the EU Court in July 2026 for non-transposition |
| DORA | Daily penalties on critical providers (up to 1% of daily turnover) | First 19 critical ICT providers designated Nov 2025 |
| AI Act | €35M or 7% (prohibited practices) | Phased enforcement underway |
| CRA | €15M or 2.5% | Reporting duties from Sep 2026 |
Sources: EUR-Lex primary texts; European Commission.
The way through: run compliance as one system
The organizations that cope are not the ones that work hardest per law. They're the ones that stopped treating each law as a separate program and built one mapped control library: obligations mapped to shared controls, each control owned and evidenced once, and that evidence reused across every framework it satisfies. Collect proof of access control once, and count it toward GDPR, NIS2, DORA, ISO 27001, and SOC 2 simultaneously.
To be fair to the alternative: the law-by-law model has one virtue: clean traceability of a single obligation back to its source. But it doesn't scale, and it drifts. The shared-control model costs more to design up front and wins on every marginal law after that. Given that the laws only accumulate, that's the bet worth making.
Where Soveryne fits
This is precisely the problem Command exists to solve. Instead of a program per law, Command gives you one workspace where controls are drafted, mapped to every framework that applies to you (GDPR, NIS2, DORA, ISO 27001 and more), and evidenced continuously across People, Organization, and Technology, so the work you do to satisfy one obligation is counted toward all the others it covers. That's the "map once, prove many" model, delivered.
And when the question is the other half of the maze (which obligations actually apply, and what a given rule requires), Counsel answers from the frameworks themselves and cites every source, so you get a grounded answer instead of a guess. Together they cover the two questions the maze keeps asking: what applies to me (Counsel) and can I prove I've done it (Command). Both run on EU-sovereign infrastructure: fitting, for a compliance stack built around European law.
The rest of this series walks the maze one wall at a time: the frameworks, the timeline, the privacy laws, the cyber laws, DORA, AI, the overlap, the gaps, and the boardroom. If you'd rather see the whole program in one place now, start with a conversation.
FAQ
Why is compliance harder now than five years ago? Because multiple EU laws (GDPR, NIS2, DORA, AI Act, CRA) now apply to the same organization simultaneously, each with its own trigger, deadlines, and penalties; and they stacked rather than replaced one another.
Is compliance the same as security? No. Compliance is meeting a legal or framework obligation and being able to prove it; security is actually reducing risk. You can have one without the other, which is why evidence and traceability matter.
Do I need a separate program for each regulation? It's the intuitive approach, but it duplicates work and creates drift. Mapping obligations to a single shared control library, evidenced once and reused across frameworks, scales far better.
What's the fastest way to reduce compliance overhead? De-duplication: identify the controls that satisfy multiple frameworks at once, evidence them once, and reuse that evidence (the subject of the "overlap dividend" later in this series).
The maze is real, but it has a map. See your whole program, controls mapped and evidenced across every framework, in Command, or get cited answers on what applies to you with Counsel.
Sources
- EUR-Lex, primary legislative texts (GDPR, NIS2, DORA, AI Act, CRA): https://eur-lex.europa.eu/
- European Commission, NIS2 CJEU referral, 8 July 2026 (IP/26/1499): https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499
- ESAs, first designation of critical ICT third-party providers (Nov 2025): https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital
- GDPR Enforcement Tracker (cumulative fines): https://www.enforcementtracker.com/statistics




