Cybersecurity is no longer optional.
Now it is a legal obligation.

The demands on digital security are rising — and with them the regulatory obligations. With the Cyber Resilience Act (CRA), the NIS-2 Directive and the DORA Regulation, the EU has created a new legal foundation to strengthen the cyber resilience of companies, products and supply chains across Europe.

Lead counsel: Florian Hackel · deputy lead: Alexander Rohen.

Illustration for cybersecurity: protective shield

The new legal foundation.

[ Three regulatory frameworks ]
CRA

Cyber Resilience Act

Requires manufacturers and importers of digital products to embed security in the development process itself (“security by design”) and to ensure it across the entire product lifecycle.

NIS-2

NIS-2 Directive

Extends IT security obligations to a broad range of essential and important entities — from energy suppliers to software service providers.

DORA

DORA Regulation

Is aimed specifically at financial entities and IT service providers and requires robust processes for digital operational resilience.

How they interact

These frameworks interlock — and affect nearly every company that develops, distributes or operates digital products.

Our services.

[ Cyber Resilience ]

As a specialized law firm for IT law, we support you in the legally sound implementation of your cyber resilience obligations — from strategic assessment to operational implementation.

01
Readiness

Regulatory Readiness Check

Analysis of which obligations under the CRA, NIS-2 or DORA apply to your company — including classification of your role, product classification and a matrix of obligations.

02
Contracts

Contract drafting & supply chain security

Adapting your development, supplier and service contracts to the new security and liability requirements.

03
Training

Training & awareness

Workshops for management, developers and compliance teams on the new cyber regulations and internal implementation obligations.

04
Gap analysis

Gap analysis & compliance strategy

Identifying where action is needed and developing practical compliance roadmaps.

05
Incident Response

Reporting channels & incident response

Establishing legally sound processes for incident reporting, communication with authorities and liability prevention.

Law meets technology.

[ Partners ]

Cyber resilience emerges where law and technology interlock. That is why, at JUN Legal, we combine our legal expertise with the technical know-how of selected IT partners. Our cyber resilience packages thus pair legal precision with technical implementation expertise.

Bitsea

Bitsea is the specialist for software analysis and open-source compliance, supporting companies of all sizes in identifying risks in their software supply chain early and reducing them over the long term. With deep technical know-how, Bitsea creates full transparency in complex software landscapes and helps companies meet regulatory requirements securely and efficiently.