Back to News
    Regulatory update

    Regulation in motion 2026 — why a correct regulatory assessment starts ageing immediately.

    In January a regulatory assessment can be correct. In July the same assessment can be out of date — even though nothing in the company has changed. Here is what actually moved during the first seven months of 2026, and what it does to a one-off assessment.

    Five changes in seven months.

    The first seven months of 2026 produced an unusually dense sequence of changes to the rules that decide whether a company is in scope, from when, and on what evidence.

    • January: the Swedish Cybersecurity Act (2025:1506) enters into force, turning NIS2 from a directive into applicable national law in Sweden.
    • February: Omnibus I amends CSRD and CSDDD. CSRD scope moves to undertakings with more than 1,000 employees and more than EUR 450 million in net turnover, and CSDDD application moves to 26 July 2029.
    • June: the first parts of the Cyber Resilience Act start to apply — Chapter IV from 11 June 2026, the Article 14 reporting obligation from 11 September 2026, and the main body from 11 December 2027.
    • July: the AI Act high-risk dates become fixed and unconditional — 2 December 2027 for Annex III systems and 2 August 2028 for product-related high-risk systems under Annex I.
    • July: the implementing act for the product passport registry turns an earlier framework requirement into an operational one.

    None of these are interpretations. Each one is a change in the enacted text, in the date on which it applies, or in the national law that implements it.

    The changes are not the same kind of change.

    Treating all five as "regulatory news" hides the part that matters. They are five different mechanisms, and each one hits an assessment in a different place.

    • Changed scope or threshold — the same company falls in or out.
    • Moved application date — the obligation is unchanged, the deadline is not.
    • New national law — the directive was always there; the enforceable duty is new.
    • Staggered entry into application — parts of one act apply on different dates.
    • Implementing act — an earlier framework requirement becomes operational.

    This is why monitoring has to read legal significance, not merely detect that a new document exists. A feed tells you something was published. It does not tell you whether your conclusion still holds.

    What happens to a one-off assessment.

    A scoping assessment is a snapshot of the legal position on the day it is made. It can be accurate, well sourced and correctly reasoned — and still produce a different answer seven months later, without a single change inside the company.

    The problem is not that the assessment was poor. The problem is that it has no mechanism for revisiting the conclusion when the source changes.

    That gap is invisible until it is expensive: an obligation that started earlier than assumed, a threshold that now captures the company, a national act that made a directive enforceable while the assessment still described it as pending transposition.

    What control actually requires.

    Regulatory control therefore takes more than an accurate picture of the present. It takes versioning, source monitoring and a traceable judgement of whether a change actually affects this company and its value chain — quality-reviewed against consolidated legal text, with the citation kept.

    That is the task RegWatch is built for.

    How Regweaver helps.

    The three products form one ladder on a shared foundation. RegCheck establishes where a company stands across 45+ frameworks, with every threshold versioned and cited to consolidated legal text. RegWatch keeps that picture current by monitoring the EU sources daily and classifying each change before anyone is notified. The Regweaver platform turns the resulting obligations into operational control across the value chain.

    The implementing act for the product passport registry was captured and classified the same day it was published in the Official Journal of the European Union.

    What to do this quarter.

    • Date your current scoping assessment. If it predates February 2026, it describes the pre-Omnibus CSRD and CSDDD position.
    • Separate the five change types in your own register: scope, application date, national implementation, staggered entry, implementing act. They require different responses.
    • Check the Swedish position specifically — NIS2 became enforceable national law in January, not at some future transposition date.
    • Decide who owns re-assessment, and on what trigger. An annual review does not catch a change that applied in June.
    • Keep the citation with the conclusion. An assessment without a source cannot be re-verified when the source moves.

    Book a walkthrough if you want to see how a change moves from source to classified notice.

    Key takeaway

    An assessment made in January can give a different answer in July. Not because anyone changed their mind, but because the legal act, the application date or the national implementation changed.

    This article is for informational purposes only and does not constitute legal advice.

    Related reading