Legal 500
  • Rankings

    • Jurisdictions

    • Submissions

    • Research+

    • Future Lawyers

  • Firms & Lawyers

    • Service Providers

    • Barristers’ Sets

    • Networks

    • Interview with…

  • In-House

    • In-House Content

    • GC Powerlist

  • Knowledge Centre

    • Data Products

    • Legal Business

    • News & Developments

    • About us

      • Legal 500

      • FAQs

      • Marketing

      • Careers

      • Contact us

  • Comparative Guides

  • Events

  • Legal 500 TV

About us

  • Legal 500

  • FAQs

  • Marketing

  • Careers

  • Contact us

  • Deutschland DE

  • Paris FR

  • Rankings

    • Jurisdictions

    • Submissions

    • Research+

    • Future Lawyers

  • Firms & Lawyers

    • Service Providers

    • Barristers’ Sets

    • Networks

    • Interview with…

  • In-House

    • In-House Content

    • GC Powerlist

  • Knowledge Centre

    • Data Products

    • Legal Business

    • News & Developments

    • About us

      • Legal 500

      • FAQs

      • Marketing

      • Careers

      • Contact us

  • Comparative Guides

  • Events

  • Legal 500 TV

About us

  • Legal 500

  • FAQs

  • Marketing

  • Careers

  • Contact us

  • Deutschland DE

  • Paris FR

© 2026 Legalease Ltd. All rights reserved

Registered company in England & Wales No. 02427356 VAT GB 321 5727 22

Registered address: 188 Fleet Street, London, EC4A 2AG

  • Data Protection policies
  • Cookies Policy
  • Contact Us
  • Article

    The European Cybersecurity Reform – Expanded Overview

    May 2026 – We are pleased to share our updated and extended overview and critical analysis of the European cybersecurity reform, Cybersecurity Act 2.0 (CSA2), now including additional jurisdictions.
    AfghanistanTechnology
    Kinstellar
    Kinstellar
  • Article

    ESAs Publish First Report On Major ICT-Related Incidents Under DORA

    The European Supervisory Authorities have released their inaugural annual report on major ICT-related incidents across the EU financial sector in 2025, revealing 3,383 incidents reported under DORA regulations.
    European UnionStrategy
    Katten
    Katten
  • Article

    Ready, respond, report: the Cyber Resilience Act’s reporting regime is here

    The EU's Cyber Resilience Act introduces mandatory vulnerability and incident reporting obligations for manufacturers of digital products starting 11 September 2026, well before the broader regulatory framework takes effect. Manufacturers must navigate tight reporting deadlines, determine when they become "aware" of security events, and establish governance structures to comply with 24-hour early warnings and subsequent detailed notifications through a platform that is not yet operational.
    AfghanistanTechnology
    CMS Wistrand
    CMS Wistrand
  • Article

    European Commission Proposes New European Technology Sovereignty Package

    The European Commission has unveiled its European Technology Sovereignty Package, aiming to reduce the EU's heavy reliance on non-EU providers for over 80% of its digital products and infrastructure.
    European UnionTechnology
    Matheson
    Matheson
  • Article

    Frontier AI And DORA: AI Service Providers To European Financial Entities Take Note

    European financial regulators have issued new guidance on managing ICT risks from frontier AI models under DORA, setting expectations that will reshape how financial entities assess their technology providers. The statement from the European Supervisory Authorities outlines three core risk mitigation strategies—prevention, detection, and management—that will drive increasingly detailed scrutiny of AI service providers' cybersecurity, governance, and operational resilience. ICT service providers,
    European UnionMedia, Telecoms, IT, Entertainment
    Goodwin Procter LLP
    Goodwin Procter LLP
  • Article

    EU Cyber Resilience Act's New Vulnerability And Incident Reporting Requirements For Products With Digital Elements Entered Into Force

    Starting September 11, 2026, manufacturers of digital products in the EU must report cybersecurity vulnerabilities and incidents within strict 24-hour and 72-hour deadlines under the new Cyber Resilience Act. Companies face penalties up to €15 million or 2.5% of global turnover for non-compliance, requiring immediate preparation of incident response procedures and assessment of product portfolios to meet these unprecedented product-focused cybersecurity obligations.
    European UnionStrategy
    Steptoe LLP
    Steptoe LLP
  • Article

    EU Tech Sovereignty Package: Implications For Digital Infrastructure Developers And The Energy Sector

    The European Union has unveiled a comprehensive digital infrastructure package aimed at tripling data centre capacity by 2030 while strengthening semiconductor manufacturing capabilities. This ambitious regulatory framework introduces acceleration zones, strategic project designations, and new procurement requirements that will fundamentally reshape how digital infrastructure is developed, operated, and integrated into Europe's energy systems.
    European UnionMedia, Telecoms, IT, Entertainment
    Arthur Cox
    Arthur Cox

Showing 1–7 of 7 results