Cybersecurity for SMEs

The complete guide to cybersecurity compliance for small and medium enterprises. Discover which regulations apply to your business, the requirements to meet, the penalties involved and the compliance costs for your sector.

Cybersecurity Compliance by Sector

Banks & Credit

Banks, credit institutions and financial intermediaries

Discover regulations

Insurance

Insurance and reinsurance companies

Discover regulations

Finance & Investments

Asset management companies, investment firms and fintech

Discover regulations

Energy

Electricity, gas and oil producers, distributors and suppliers

Discover regulations

Transport

Air, rail, maritime and road transport operators

Discover regulations

Healthcare

Hospitals, clinics, laboratories and healthcare providers

Discover regulations

Manufacturing

Manufacturing industry, production and industrial automation

Discover regulations

Digital & IT

Software houses, system integrators, MSPs and tech companies

Discover regulations

Telecommunications

Telecom operators, ISPs and communication service providers

Discover regulations

Public Administration

Municipalities, regions, ministries and public bodies

Discover regulations

Retail & Commerce

Large-scale distribution, e-commerce and retail chains

Discover regulations

Food & Agriculture

Food production, processing and distribution

Discover regulations

Chemical & Pharmaceutical

Chemical, pharmaceutical and biotech industry

Discover regulations

Water & Utilities

Water management, sewage networks and environmental services

Discover regulations

Trust Services

Certification authorities, identity providers and trust service providers

Discover regulations

Space & Aerospace

Space, satellite and aerospace industry

Discover regulations

Postal & Courier Services

Postal operators, express couriers and logistics

Discover regulations

Professional Services

Law firms, consultancies, accountants and auditors

Discover regulations

Digital Infrastructure

Data centres, cloud providers, CDNs and IXPs

Discover regulations

Other Sectors

Companies in other sectors with basic cybersecurity obligations

Discover regulations

Supported Cybersecurity Regulations

ComplyDev covers the 13 main European regulations on cybersecurity, data protection and digital resilience.

GDPR

EU Regulation 2016/679

Personal data protection in the European Union

Up to €20M or 4% of annual global turnover

NIS2

Deadline

EU Directive 2022/2555 - Legislative Decree 138/2024

Network and information security for essential and important entities

Up to €10M or 2% of annual turnover

DORA

Deadline

EU Regulation 2022/2554

Digital operational resilience for the financial sector

Up to €10M or 5% of annual turnover

ISO 27001

ISO/IEC 27001:2022 - International standard

Information Security Management System (ISMS)

N/A (voluntary standard)

PCI-DSS

PCI-DSS v4.0 (effective March 31, 2024)

Security standard for entities that handle, process, or transmit payment card data

Fines from card networks (Visa, Mastercard) up to $500K/month + revocation

PSNC

Law 133/2019 - Decree-Law 105/2019

Protection of national critical infrastructure

Criminal and administrative penalties up to €150K

Circolare 285

Circular No. 285 of December 17, 2013 (continuously updated)

Prudential supervisory provisions for banks (Title IV, Ch. 4-5)

Administrative penalties + formal reprimands from Bank of Italy

IVASS 38

IVASS Regulation No. 38 of July 3, 2018

Corporate governance system for insurance undertakings

Administrative penalties from IVASS

eIDAS

Deadline

EU Regulation 910/2014 + EU Regulation 2024/1183 (eIDAS 2.0)

Digital identity and qualified trust services (digital signature, certified email, time stamp)

Up to €5M or 2% of annual turnover

CAD

Legislative Decree 82/2005 (and subsequent amendments)

Digitalization of Public Administration

Managerial liability + administrative penalties

AgID

AgID Circular No. 2/2017 + subsequent Guidelines

Minimum ICT security measures for Public Administrations

Managerial liability + administrative penalties

AI Act

Deadline

EU Regulation 2024/1689

Regulation of artificial intelligence systems in the EU with a risk-based approach. Phased application: prohibited practices from Feb 2, 2025, GPAI obligations from Aug 2, 2025, high-risk systems from Aug 2, 2026

Up to €35M or 7% of turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (inaccurate information). SMEs: proportionate caps

Verify Your Company's Compliance

In just a few minutes, discover which regulations apply to your SME, your current compliance level and the priority actions to take.

Start Free Assessment