Compliance
The rules and where we stand
This page is for whoever handles privacy and information security at your organisation. We also set out what is still in progress.

| Subject | Status | Where we stand |
|---|---|---|
| GDPR | Built in | GDPR-by-design. The development phase that built this into the architecture is complete. What that means concretely is set out in the technical note. |
| Data processing agreement | Template ready | Template available on the Documents page, open it directly |
| Data sovereignty | By design | Centrally vetted code, with data and administration inside the jurisdiction you choose |
| European Accessibility Act | In progress | Applies to operating systems since 28 June 2025. We are working towards an accessibility statement at delivery |
| Cyber Resilience Act | In progress | An operating system falls under Annex III, Class I. Reporting duty from 11 September 2026, full application 11 December 2027 |
| NIS2, in the Netherlands the Cybersecurity Act | Your obligation | In force since 15 August 2026, for around eight thousand organisations in the designated sectors. At its core are a duty of care and a duty to report within 24 hours, and the board approves the measures and oversees how they are carried out. A workstation that carries on running on its last update after October 2028 falls under that duty of care. |
| DORA | Through your contract | In force since 17 January 2025 for twenty-one types of financial entity. If you are one, every ICT supplier goes into your information register and into your contractual requirements. We fall outside the designation as a critical ICT supplier; the agreement can carry the provisions your register needs. |
| ISO 27001 | In preparation | Programme in preparation. The certification comes after that, and we would rather say so now than at award |
| Escrow and audit | On offer | Can be arranged, open for discussion per agreement |
Nine subjects, with the status we would also put in a tender answer or a supplier questionnaire.
For a company
Who else asks you about this
Your own customers as well as a regulator
Customer audits and questionnaires
Anyone who supplies banks, insurers, healthcare or government receives a supplier questionnaire every year. It asks where your data sits, who can reach it and which subcontractors have sight of it. The compliance overview and the data processing agreement are written to answer those questions directly.
Your own supplier register
NIS2 and DORA shift part of the question to the supply chain: you have to be able to show which ICT suppliers you have and what is set down contractually. We supply the details for that register entry before you sign.
Your cyber insurance
Ask your insurer what happens to your cover and your premium if part of your workstations carry on running on their last update after October 2028. What your policy says is for your insurer to tell you; what we do know is that it is a question usually asked only after something has happened.
The dates and thresholds on this page come from the published legal texts and from the guidance of the NCSC and the regulators. They are meant for reference, and your own lawyer remains in charge.
What we bind ourselves to. Whether your organisation meets the GDPR depends on how you set it up; an operating system can never decide that for you. We supply the architecture and the documentation with which you can demonstrate it.

Why now
Four dates already in your calendar
The reason this decision belongs on the table now lies in four separate deadlines that land on the same workstations. Three of them are set in law, the fourth in licensing terms.
What each date means for you
The European Accessibility Act applies to operating systems. Software put on the market for consumers and for services in scope has to meet accessibility requirements, and anyone who supplies digital services inherits that question through what they deploy.
The reporting obligations of the Cyber Resilience Act take effect. Manufacturers of products with digital elements have to report actively exploited vulnerabilities and severe incidents. An operating system sits in Annex III, Class I.
The Cyber Resilience Act applies in full. From that point the product you deploy has to carry the conformity that goes with it, which turns supplier choice into a compliance question rather than only a cost question.
The Windows 10 Extended Security Updates programme ends. Between now and then the cost per workstation runs 52, then 105, then 210 euro, and after that the same machine carries on running on the last update it received.
Those four dates make a decision in 2026 cheap and a decision in 2028 expensive. A workstation estate is replaced over three to five years in the normal course of things. If the decision is made now, the change rides along with the replacement rhythm you already have. If it is made in the last year, it arrives as one purchase, in one budget cycle, under a deadline, which is the most expensive way any organisation has ever bought anything.
What this site does. It sets a second route alongside the one you already have, with the figures, the statutory dates and the honest weak points in the same place, so your own people can hold them against your own estate. The judgement on Windows and the decision stay with you. If the answer for your organisation is to stay on Windows, the assessment report has still paid for itself as a document about your readiness for Windows 11.