Organization
2. Compliance and evidence capability
For: architects · finance, risk and compliance · executives and CIOsPrerequisites: None.
European cybersecurity and AI texts have one thing in common: they expect an organization to prove, on request, what happened, when, and how it responded. Observability is the natural infrastructure for this evidence, provided it is designed for it.
The timeline, verified as of 2 October 2026
Section titled “The timeline, verified as of 2 October 2026”| Text | Reference | What applies, and since when |
|---|---|---|
| GDPR | Regulation (EU) 2016/679 | applicable since 25 May 2018 |
| DORA | Regulation (EU) 2022/2554 | applicable to the financial sector since 17 January 2025 |
| NIS2 | Directive (EU) 2022/2555 | transposition due by 17 October 2024. In France, the so-called resilience bill has not been enacted. The Commission referred France to the Court of Justice of the European Union on 8 July 2026 for failure to transpose. In Belgium, the law of 26 April 2024 has applied since 18 October 2024 |
| AI Act | Regulation (EU) 2024/1689 | in force since 1 August 2024; prohibited practices since 2 February 2025; general-purpose AI models since 2 August 2025 |
| Amended AI Act | Regulation (EU) 2026/1744 (Digital Omnibus on AI) | Annex III high-risk systems postponed to 2 December 2027, Annex I systems to 2 August 2028. Article 50 (transparency) applicable since 2 August 2026. Marking of synthetic content is postponed to 2 December 2026 only for systems placed on the market before 2 August 2026 |
| CRA | Regulation (EU) 2024/2847 | reporting of actively exploited vulnerabilities since 11 September 2026; main obligations on 11 December 2027 |
In France, ANSSI estimates that about 15,000 entities will fall under NIS2, compared with a few hundred under the first directive. Not having a national law is no excuse for not preparing: customers, insurers and clients in the financial sector already require these measures by contract.
The central idea: operational evidence
Section titled “The central idea: operational evidence”For a long time, keeping logs was a matter of good practice. For a growing part of the European economy, it has become an obligation backed by penalties. Three consequences for the CIO:
- traceability comes before freshness: logs in cheap cold storage are better than no logs;
- the burden of proof shifts: after an incident, the organization must show what it detected, when, and what it did;
- the dialogue with the authorities potentially becomes continuous: notifications, requests for information, inspections.
The opposite trap exists too: faced with several texts, keeping everything, for a very long time, on the most expensive platform. The bill explodes, GDPR exposure gets worse, and compliance does not improve. The right approach is to map what is required, for which scope, for how long, with what integrity, and to keep only that.
Who is concerned. The directive distinguishes between essential and important entities, according to sector (Annexes I and II, eighteen sectors in total) and size. As a general rule, it targets medium-sized and large companies in the listed sectors, with exceptions that cover certain entities regardless of their size. The first question to ask your lawyer is therefore simple: are we essential, important or out of scope? The answer must be written and dated.
The ten measures of Article 21, and the evidence observability can provide.
| Point | Measure (Article 21(2)) | Evidence telemetry can provide |
|---|---|---|
| a | policies on risk analysis and information system security | asset inventory kept up to date by automatic discovery, dated review |
| b | incident handling | alerts, timestamped timelines, tickets linked to traces and logs |
| c | business continuity, backups, disaster recovery, crisis management | backup success, timed restore tests, logged exercises |
| d | supply chain security | availability and errors of supplier services measured, supplier access logged |
| e | security in acquisition, development and maintenance, including vulnerability handling | deployed versions tracked, software bill of materials (SBOM), patch times measured |
| f | assessment of the effectiveness of measures | security indicators tracked over time, quarterly reviews archived |
| g | cyber hygiene and training | patch and configuration status, training rate tracked |
| h | cryptography and encryption | certificate inventory and expiry, key rotation logged |
| i | human resources security, access control, asset management | access logs, review of privileged accounts, departures processed |
| j | multi-factor authentication, secured communications, emergency communications | share of access with MFA, authentication logs, emergency channel tests |
The article contains ten, from a to j. The NIS2 Article 21 self-assessment uses this grid to position your organization, measure by measure.
Incident notification (Article 23). For a significant incident: an early warning within 24 hours, a notification within 72 hours, a final report no later than one month after the notification. These deadlines can only be met if observability provides factual elements from the moment of detection: reliable timestamps, affected scope, probable vector, volume affected. Reconstructing a timeline from scattered logs, several tens of hours after the facts, puts the organization in a weak position.
Management liability (Article 20). Management bodies approve the risk management measures, oversee their implementation, can be held liable for failures and must follow training. For the CIO, keeping a record of decisions and trade-offs on detection and logging becomes a form of protection.
Penalties (Article 34). For a breach of Articles 21 or 23, the maximum is at least €10M or 2% of total worldwide annual turnover for an essential entity. It is at least €7M or 1.4% for an important entity. In each case, the higher amount applies. For a mid-sized company with €120M in revenue classified as important, 1.4% would only amount to €1.7M. So the €7M amount applies, unless national law raises it: it is the minimum the directive sets for this ceiling.
DORA, for the financial sector
Section titled “DORA, for the financial sector”DORA applies to banks, insurers, asset management companies, payment service providers, market infrastructures, and indirectly to their IT service providers. Three workstreams affect observability:
- A verifiable map of critical functions and the assets that support them. The attributes carried by telemetry (service, business function, criticality) link each technical component to its function; without them, the map remains a document disconnected from reality.
- Accelerated notification of major ICT-related incidents. The implementing texts set an initial notification within four hours of the incident being classified as major, and no later than 24 hours after its detection. An intermediate report and a final report follow. You therefore have to measure the impact, not just the incident: how many customers, what duration, what scope.
- Resilience testing and management of critical providers: a register of providers, continuous measurement of their availability and errors. A contractual service level that nobody measures is not a service level.
CRA, for those who place digital products on the market
Section titled “CRA, for those who place digital products on the market”The Cyber Resilience Act governs the cybersecurity of products with digital elements. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours, then a final report. This requires detecting exploitation in production and linking it to a known vulnerability. This often relies on fleet telemetry at customer sites, with everything that implies in terms of GDPR and contracts.
A CIO who buys without manufacturing has no obligation of their own under the CRA. The manufacturer draws up the software bill of materials (SBOM) and keeps it available to market surveillance authorities. The CIO still has an interest in requesting SBOMs from suppliers and keeping them. It is also worth tracking the versions deployed across their estate and monitoring announced end-of-support dates.
AI Act, for AI systems
Section titled “AI Act, for AI systems”For observability, three requirements matter. The first is automatic logging for high-risk systems (Article 12). The second is retention of these logs by the organization deploying the system, for at least six months (Article 26). The third is post-market monitoring (Article 72). The postponement decided in 2026 gives time, not an exemption. Penalties can reach €35M or 7% of worldwide turnover for prohibited practices. The details, signal by signal, are in the evidence matrix of the GenAI method.
GDPR, the reminder that gets lost
Section titled “GDPR, the reminder that gets lost”A log that contains an IP address, an identifier, an email address or personal request parameters is processing of personal data, from the moment of collection. Four disciplines follow, to be carried with the DPO:
- a documented legal basis for security logging, usually legitimate interest;
- justified retention periods for each log category;
- up-to-date data processing agreements with each observability vendor;
- transfers outside the European Union that are governed and documented.
The defensive practice is to pseudonymize as early as possible: salted hashing preserves the ability to correlate, and free-text fields, names and addresses are masked before sending. An OpenTelemetry Collector can perform these transformations in the pipeline.
The common evidence foundation
Section titled “The common evidence foundation”NIS2, DORA, the CRA and the GDPR converge on six capabilities: traceability of critical events, reliable and synchronized timestamping, immutability of audit records, retention suited to each category, quick accessibility on request, consistency across sources. This convergence makes it possible to build a single foundation rather than four setups.
flowchart LR S["Sources<br/>authentication, admin,<br/>configuration, incidents"] --> C["1. Standardized collection<br/>timestamping, taxonomy"] C --> W["2. Immutable storage<br/>write once"] W --> R["3. Auditable search<br/>who viewed what"] R --> P["Evidence<br/>auditor, authority"]
- Standardized collection: all critical sources converge on a common infrastructure, timestamped with a reliable time source, tagged according to a shared taxonomy (team, application, environment, criticality, event type).
- Immutable storage: write-once media, object storage with locking. Immutability is a necessary condition for evidence, not a sufficient one: see a signed log is not an auditable log.
- Auditable search: the lookups themselves are traced.
Retention periods. They depend on the type of log, the sector and the recommendations of the authorities (CNIL, ANSSI, ACPR or AMF depending on the case). Only one rule is stable: classify logs by category and justify the period for each one. Authentication, incident and audit logs of the observability platform itself call for long periods; technical application logs, a short period calibrated on operational needs. Write down your grid, have it validated by the DPO and the CISO, review it every year.
Governance: CIO, CISO, DPO
Section titled “Governance: CIO, CISO, DPO”None of these roles carries compliance alone. The CIO provides the infrastructure, the CISO defines the policies and carries cyber accountability, the DPO protects individuals and limits collection. They need:
- a joint committee, at least quarterly;
- a one-page RACI: who decides on retention, who signs data processing agreements, who notifies the authority, who maintains the SBOM, who runs the tests (see the RACI matrix);
- an annual calendar: retention review, review of critical suppliers, restore test, incident simulation, internal audit;
- five indicators: coverage of critical functions by complete logging, share of critical logs in immutable storage, time demonstrated in simulation between detection and early warning, share of categories meeting their retention period, number of successful archive restores during the year.
Five common traps
Section titled “Five common traps”- Maximum retention for everything: a multiplied bill, worse GDPR exposure.
- A single expensive platform for everything: day-to-day operations and compliance archiving do not have the same needs; two tiers cost much less.
- Partial encryption: in transit, at rest, in backups, with managed and audited keys. Every forgotten link is a risk.
- Training models on your logs: require by contract that your data is not used to train a vendor’s models without explicit consent.
- Paper compliance: a policy that is written but not applied documents what the organization knew it should do. Inspections look for evidence of application.
Workshop: your evidence capability
Section titled “Workshop: your evidence capability”Duration: 45 minutes, in pairs, with the CISO if possible.
- Have your NIS2 status qualified in writing, and your DORA status if you serve the financial sector.
- Fill in the NIS2 Article 21 self-assessment, distinguishing “measure in place” from “measure demonstrable”.
- For the two weakest measures, name the missing evidence and the telemetry source that would produce it.
- Sort the actions: at three months, six months, twelve months, each with an owner.
Three exercises to run next
- Capability mapping (half a day): place each of the six capabilities of the foundation on the scale absent, in progress, partial, in place.
- Incident simulation (one day): time the path from detection to early warning, assess the timeline and the granularity of the measurable impact, and do it again six months later.
- Foundation audit (one week): for one critical function, produce the administrator access over several months, the timeline of a past incident, the list of suppliers involved. If this takes more than a day, the foundation is undersized.
My next action: what action, by what date, with whom?
Going further
Section titled “Going further”- A signed log is not an auditable log.
- The AI Act, NIS2, GDPR evidence matrix in the GenAI method.
- The organization dimension.
Revised on 2 October 2026: AI Act Article 50 timeline clarified (Regulation (EU) 2026/1744), Belgian NIS2 transposition law added, scope of the CRA for a buyer corrected. The NIS2 penalty ceiling is now presented as a minimum set by the directive; immutability, as a necessary but not sufficient condition for evidence.