Dec 2027EU AI Act compliance
    Security pack · NIS2 · CRA · GDPR

    The Security pack: NIS2-led compliance

    For essential and important entities under NIS2, and for manufacturers of products with digital elements. The ten Article 21 measures, the incident deadlines and your product files in one platform — with GDPR included.

    What is in the pack

    Laws included

    NIS2, CRA and GDPR — switched on from day one

    Who it is for

    Essential and important entities in the NIS2 sectors, and manufacturers heading for the Cyber Resilience Act

    Why now

    NIS2 is enforced today; CRA reporting duties start in September 2026, full requirements in December 2027

    The pack is the full LandingRed platform with these laws switched on. The other regulations stay out of sight until you need them.

    What you manage

    The measures, deadlines and files these three laws ask for — in one workspace.

    1

    The ten NIS2 measures

    Document each Article 21 risk-management measure with its evidence and its owner.

    2

    Incident deadlines

    Early warning in 24 hours, notification in 72, final report — tracked with legal clocks.

    3

    CRA product files

    Product risk assessment, the Annex I essential requirements and vulnerability notifications, per product.

    4

    GDPR records

    Records of processing activities, the breach register and controller instructions, in the same workspace.

    How the pack works

    One door in, less noise, and a platform that grows with you.

    One door, less noise

    You see the laws you bought, not all seven. Menus stay small and every screen is relevant.

    Do it once, it counts everywhere

    Requirements are cross-mapped: one documented control satisfies every law in the pack that asks for it.

    Grow by a switch

    When the AI Act or another law reaches you, it switches on in the same platform. No migration, no new tool.

    Audit-ready evidence

    An immutable audit trail records every change, and reports export to PDF.

    Frequently asked questions

    How do we know we are in NIS2 scope?

    The sector lists plus a size line decide most cases, and some entities are covered regardless of size. The free scope check gives you an orientation; the final call deserves verification.

    When does the CRA start to apply?

    Reporting duties for actively exploited vulnerabilities start in September 2026. The full requirements apply from December 2027.

    Can we add more laws later?

    Yes. Every regulation is already in the platform. Adding one is a setting, not a migration.

    Does LandingRed certify us?

    No. It is a tool that keeps your registers, deadlines and evidence in order. It is not legal advice and it does not certify compliance.

    See where you stand

    Answer seven plain questions and see which laws apply to you — then try the platform free for 7 days.