For years, regulatory compliance had a very clear goal: to avoid penalties. Companies would identify which laws applied to them, implement the necessary measures, and prepare documentation in case of an inspection. It was a reactive model, designed to respond to government agencies.
That situation has changed completely—and not just because there are more rules.
European regulation is growing at an unprecedented rate: NIS2, DORA, the AI Act, the Due Diligence Directive (CSDDD), the GDPR, and the ENS. Each one redefines how organizations manage their risks, their suppliers, their cybersecurity, and their use of artificial intelligence.
But the real, fundamental change is something else: more and more companies must continually demonstrate that they are compliant—and increasingly, it is not a regulator but a customer who is demanding this.
From Legal Compliance to Business Compliance
A company may not be directly subject to NIS2 or the Due Diligence Directive.
But if you work for a larger company, you’ll most likely start receiving requests like these:
- Please complete our cybersecurity questionnaire.
- Simplify your corporate policies.
- Please describe how you evaluate your suppliers.
- Demonstrate that you have an internal information channel.
- Please submit evidence of your security controls.
- Please describe the measures you have in place to ensure the responsible use of artificial intelligence.
It’s not the government that’s asking for it. It’s the customer.
And that is why more and more organizations are discovering an uncomfortable truth: compliance is no longer just a legal obligation—it has become a prerequisite for retaining customers, participating in bids, and opening up new business opportunities.

It’s no longer enough just to comply. You have to be able to prove it.
The question that matters has changed.
It is no longer:
Do you comply with these regulations?
It is:
Can you prove it? And how long will it take?
To demonstrate means to have evidence on hand: who approved a policy, when a procedure was reviewed, what controls are in place, what risks were assessed, which suppliers were approved, and what training each employee received.
Compliance is no longer just a folder of static documents. It has become a living system that must be accessible at any time—not something that has to be reconstructed every time someone requests it.
The mistake that many organizations continue to make
Most organizations continue to treat each new regulation as a standalone project: one policy for ISO 27001, another for NIS2, a questionnaire for DORA, a control for the ENS, and an assessment for the AI Act.
The result is predictable: duplicate information, parallel processes, and an administrative burden that grows with each new regulation instead of building on what has already been established.
And it’s an unnecessary effort, because the underlying premise is flawed. These regulations are not completely separate; they share many of the same requirements. Access management, vendor assessment, risk analysis, training, and incident response appear—with slight variations—in virtually all regulatory frameworks.
Controls are the responsibility of the organization, not the regulations
This is probably the most important shift in approach that companies will need to make in the coming years: moving away from designing controls to comply with a specific standard, and instead designing them to protect the organization.
A multi-factor authentication control does not exist to comply with NIS2. It exists to reduce the risk of unauthorized access. That same control, once implemented, can then be used to demonstrate compliance with ISO 27001, NIS2, ENS, DORA, the AI Act—and any future regulations requiring equivalent measures.
The same applies to a policy, a supplier evaluation, or a risk analysis: they are managed only once and can be linked to as many regulatory frameworks as necessary.
The Role of Technology
Maintaining this level of traceability using spreadsheets, emails, and shared folders is no longer sustainable. That complexity needs to be handled by technology, not people.
A platform designed for this purpose should be able to:
- maintain a single catalog of controls;
- automatically link them to different regulatory frameworks;
- identify which pieces of evidence apply to multiple regulations at the same time;
- detect duplicates;
- automate reviews and reminders;
- maintain complete traceability for each action.
The goal isn’t to have more tools. It’s for people to spend their time managing risks and making decisions—not copying the same information into five different systems.
The Future of Compliance
For years, the goal was to deliver. Today, the goal is to prove ourselves. Tomorrow, it will be to automate.
Organizations that understand this change early on will not only reduce their administrative burden—they will also be better prepared for audits, certification processes, and the requirements of clients, investors, and government agencies.
Because, at the end of the day, compliance in the future won’t be about managing regulations. It will be about managing trust—built on evidence, not on promises.
And that trust will increasingly become one of the most valuable assets of any organization.
At ithikios, we help you efficiently demonstrate compliance.
* This article was written by humans and enhanced with AI.