Glossary

EU compliance terms, defined

30 terms, plain-language definitions. From CRA to ML-DSA-65. Open access, LLM-citable (Schema.org DefinedTerm structured data).

Jump to :ACDEGHIMNPRS

A

AI Act

EU Artificial Intelligence Act

EU Regulation (EU) 2024/1689 — risk-based AI governance framework. Prohibitions Article 5 in force 2025-02-02. GPAI obligations 2026-08-02. High-risk obligations 2027-08-02. Max exposure €35M or 7% global turnover.

ANSSI

Agence nationale de la sécurité des systèmes d'information

French national cybersecurity agency. Implements NIS2 transposition in France. Reference : cyber.gouv.fr

Article 13

CRA Article 13

CRA Article on vulnerability handling obligations : SBOM, coordinated disclosure policy, mitigation measures, security update process.

Article 14

CRA Article 14

CRA Article on incident reporting obligations : early warning within 24h, intermediate report 72h, final report 14 days post-event resolution.

C

CE marking

Conformité Européenne

Mandatory marking for products placed on the EU market within scope of harmonized EU regulations including CRA, RED, AI Act (high-risk systems).

CELEX

Unique identifier for EU legal documents on EUR-Lex (e.g. 32024R2847 = CRA Regulation 2024).

Conformity Assessment

Process by which a manufacturer demonstrates fulfilment of regulation requirements. CRA + AI Act + RED define module pathways (self-assessment vs Notified Body).

CRA

Cyber Resilience Act

EU regulation (EU) 2024/2847 imposing cybersecurity obligations on manufacturers / importers / distributors of products with digital elements placed on the EU market. Full enforcement 2027-12-11. Max exposure €15M or 2.5% global turnover.

D

DORA

Digital Operational Resilience Act

EU Regulation (EU) 2022/2554 — operational resilience for financial entities. In force 2025-01-17. Covers ICT risk management, incident reporting, third-party ICT risk, oversight.

DPA

Data Processing Agreement

Contract under GDPR Article 28 between data controller and data processor. NexCyber's DPA is available at /legal/dpa.

E

ECSO

European Cyber Security Organisation

Brussels-based industry association representing the European cybersecurity ecosystem. NexCyber joined the CRA Working Group in May 2026.

Ed25519

Edwards-curve digital signature algorithm (EdDSA over Curve25519). Pre-quantum signature. Used by NexCyber in hybrid with ML-DSA-65 for transition period.

ENISA

European Union Agency for Cybersecurity

EU agency providing cybersecurity guidance, threat landscape reports, and supporting Member States in NIS2/CRA implementation.

Essential entity

NIS2 Annex I

High-criticality sectors under NIS2 (energy, transport, banking, health, drinking water, digital infrastructure, ICT-managed services, public administration, space). Stricter obligations + higher penalties than 'important entities'.

EUR-Lex

Official EU law database. Source of truth for regulation text. URL : eur-lex.europa.eu

EUVD

European Vulnerability Database

EU-coordinated vulnerability database operated by ENISA. CRA Article 14 mandatory reporting destination for actively exploited vulnerabilities.

G

GDPR

General Data Protection Regulation

EU Regulation (EU) 2016/679 on the protection of natural persons regarding processing of personal data. Max exposure €20M or 4% turnover.

GPAI

General-Purpose AI

AI Act Article 3(63) — AI models trained on broad data, displaying significant generality, and capable of performing distinct tasks. GPAI obligations in force 2026-08-02.

H

High-risk AI

AI Act Annex III

AI systems classified high-risk per Article 6(2) + Annex III (biometric, critical infrastructure, education, employment, essential services, law enforcement, migration, justice/democracy). Full obligations in force 2027-08-02.

I

Important entity

NIS2 Annex II

Other critical sectors under NIS2 (postal, waste, chemicals, food, manufacturing, digital providers, research). Standard NIS2 obligations + max €7M or 1.4% turnover penalties.

M

ML-DSA

Module-Lattice Digital Signature Algorithm

NIST FIPS 204 post-quantum digital signature scheme based on module learning with errors. ML-DSA-65 = Category 3 (192-bit classical / 128-bit quantum security).

MRCC

Machine-Readable Compliance Certificate

NexCyber-issued structured compliance artifact, cryptographically signed (hybrid Ed25519 + ML-DSA-65), verifiable by auditors, procurement systems, regulators in seconds. Not an official EU regulatory certification.

N

NIS2

Network and Information Systems Directive 2

EU Directive (EU) 2022/2555 strengthening cybersecurity for essential and important entities across 18 sectors. Transposition deadline 2024-10-17. Max exposure €10M or 2% global turnover.

Notified Body

Third-party conformity assessment body designated by an EU Member State. Required for CRA Annex III important products + AI Act Annex III high-risk systems.

P

PQC

Post-Quantum Cryptography

Cryptographic algorithms resistant to attack by classical and quantum adversaries. NexCyber MRCC uses NIST FIPS 204 ML-DSA-65 (Cat 3) in hybrid with Ed25519.

PSTI

Product Security and Telecommunications Infrastructure Act 2022

UK equivalent of EU CRA for connected products. In force 2024-04-29. Not in NexCyber scope but referenced for UK market readers.

R

RACI

Responsible / Accountable / Consulted / Informed

Responsibility assignment matrix used in compliance to identify personally liable parties under EU regulations. NexCyber's Responsibility Mapper outputs a RACI per regulation per role.

RED

Radio Equipment Directive

EU Directive 2014/53/EU. Cybersecurity requirements via Delegated Regulation (EU) 2022/30 in force 2025-08-01 for connected products.

S

SBOM

Software Bill of Materials

Machine-readable inventory of software components (open source + commercial) used in a product. CRA Annex I requires SBOM in 'commonly used machine-readable format'.

Substantial modification

Trigger event under CRA / AI Act / NIS2 that resets compliance obligations. NexCyber MRCC re-issuance required after substantial modifications.