EN Book a demo

Compliance

The rules and where we stand

This page is for whoever handles privacy and information security at your organisation. We also set out what is still in progress.

GDPRBy design, built into the architecture
Data processing agreementTemplate ready, open it directly
Cyber Resilience ActReporting duty from 11 September 2026
ISO 27001Programme in preparation
European Union flags in front of the Berlaymont building in Brussels
SubjectStatusWhere we stand
GDPRBuilt inGDPR-by-design. The development phase that built this into the architecture is complete. What that means concretely is set out in the technical note.
Data processing agreementTemplate readyTemplate available on the Documents page, open it directly
Data sovereigntyBy designCentrally vetted code, with data and administration inside the jurisdiction you choose
European Accessibility ActIn progressApplies to operating systems since 28 June 2025. We are working towards an accessibility statement at delivery
Cyber Resilience ActIn progressAn operating system falls under Annex III, Class I. Reporting duty from 11 September 2026, full application 11 December 2027
NIS2, in the Netherlands the Cybersecurity ActYour obligationIn force since 15 August 2026, for around eight thousand organisations in the designated sectors. At its core are a duty of care and a duty to report within 24 hours, and the board approves the measures and oversees how they are carried out. A workstation that carries on running on its last update after October 2028 falls under that duty of care.
DORAThrough your contractIn force since 17 January 2025 for twenty-one types of financial entity. If you are one, every ICT supplier goes into your information register and into your contractual requirements. We fall outside the designation as a critical ICT supplier; the agreement can carry the provisions your register needs.
ISO 27001In preparationProgramme in preparation. The certification comes after that, and we would rather say so now than at award
Escrow and auditOn offerCan be arranged, open for discussion per agreement

Nine subjects, with the status we would also put in a tender answer or a supplier questionnaire.

For a company

Who else asks you about this

Your own customers as well as a regulator

Customer audits and questionnaires

Anyone who supplies banks, insurers, healthcare or government receives a supplier questionnaire every year. It asks where your data sits, who can reach it and which subcontractors have sight of it. The compliance overview and the data processing agreement are written to answer those questions directly.

Your own supplier register

NIS2 and DORA shift part of the question to the supply chain: you have to be able to show which ICT suppliers you have and what is set down contractually. We supply the details for that register entry before you sign.

Your cyber insurance

Ask your insurer what happens to your cover and your premium if part of your workstations carry on running on their last update after October 2028. What your policy says is for your insurer to tell you; what we do know is that it is a question usually asked only after something has happened.

The dates and thresholds on this page come from the published legal texts and from the guidance of the NCSC and the regulators. They are meant for reference, and your own lawyer remains in charge.

What we bind ourselves to. Whether your organisation meets the GDPR depends on how you set it up; an operating system can never decide that for you. We supply the architecture and the documentation with which you can demonstrate it.

Why now

Four dates already in your calendar

The reason this decision belongs on the table now lies in four separate deadlines that land on the same workstations. Three of them are set in law, the fourth in licensing terms.

today
28 June 2025Accessibility Act applies to operating systems
11 September 2026Cyber Resilience Act: reporting duty starts
11 December 2027Cyber Resilience Act applies in full
October 2028Windows 10 ESU ends; the paid route finishes here
What each date means for you
Since 28 June 2025

The European Accessibility Act applies to operating systems. Software put on the market for consumers and for services in scope has to meet accessibility requirements, and anyone who supplies digital services inherits that question through what they deploy.

11 September 2026

The reporting obligations of the Cyber Resilience Act take effect. Manufacturers of products with digital elements have to report actively exploited vulnerabilities and severe incidents. An operating system sits in Annex III, Class I.

11 December 2027

The Cyber Resilience Act applies in full. From that point the product you deploy has to carry the conformity that goes with it, which turns supplier choice into a compliance question rather than only a cost question.

October 2028

The Windows 10 Extended Security Updates programme ends. Between now and then the cost per workstation runs 52, then 105, then 210 euro, and after that the same machine carries on running on the last update it received.

Those four dates make a decision in 2026 cheap and a decision in 2028 expensive. A workstation estate is replaced over three to five years in the normal course of things. If the decision is made now, the change rides along with the replacement rhythm you already have. If it is made in the last year, it arrives as one purchase, in one budget cycle, under a deadline, which is the most expensive way any organisation has ever bought anything.

What this site does. It sets a second route alongside the one you already have, with the figures, the statutory dates and the honest weak points in the same place, so your own people can hold them against your own estate. The judgement on Windows and the decision stay with you. If the answer for your organisation is to stay on Windows, the assessment report has still paid for itself as a document about your readiness for Windows 11.

Prototype