EU compliance automation for NIS2, DORA, and the EU AI Act

re-entry.ai is an AI-powered compliance platform built in the DACH region and hosted in Frankfurt. Engineering and security teams use it to continuously collect evidence, map their existing stack to NIS2, DORA, and EU AI Act controls, and export audit-ready packages in BSI-aligned format. Re-entry operates as a regulatory heat shield: when an auditor sends a request, when an incident triggers a reporting obligation, or when a new regulation phases in, the team has evidence, controls mapping, and exports ready in hours instead of weeks.

NIS2 compliance and evidence collection

NIS2 (EU Directive 2022/2555) has been in force since October 2024 with administrative fines up to €10 million or 2% of global annual revenue. Article 20 makes management bodies personally liable for compliance failures. re-entry maps the evidence requirements across Articles 21 (cybersecurity risk management), 23 (24-hour early-warning incident reporting), and 27 (registry of essential and important entities) to artefacts already produced by GitHub, AWS, Okta, Entra, incident ticketing systems, and vendor registers.

DORA digital operational resilience for financial entities

The Digital Operational Resilience Act (EU Regulation 2022/2554) has been in force since January 2025 for financial institutions. re-entry tracks ICT third-party registers per Article 28, digital operational resilience testing per Article 25, and incident classification per Article 18 — and exports the evidence pack EBA and national competent authorities expect.

EU AI Act risk-tier classification and oversight

The EU AI Act (Regulation 2024/1689) phases in through August 2026, with prohibited-practice fines up to €35 million or 7% of global revenue per Article 99. re-entry discovers AI systems already deployed inside the organisation (internal LLM routers, copilots, HR screeners, automated decisioning tools), classifies them by risk tier, and tracks the obligations attached to each tier — DPIAs, transparency notices, human-oversight controls, and post-market monitoring.

EU-hosted, BSI-aligned, German support

Application and evidence storage are hosted in Frankfurt. No US sub-processor sits on the data path. The published sub-processor list follows BSI C5 conventions so the data protection officer can sign off without a separate Schrems II analysis. Customer support is available in German and English.

Integrations

Built for compliance leaders in regulated SaaS

re-entry is built for CISOs, compliance officers, and heads of engineering at mid-market SaaS companies inside the European Union subject to NIS2, DORA, or the EU AI Act. Design partner engagements are €1,000 per month for six months in exchange for product feedback and a published case study. Full team licenses are announced once the design partner cohort is full.

Frequently asked questions about EU compliance automation

How is re-entry different from Vanta or Drata?
Vanta and Drata were built US-first for SOC 2 and ISO 27001. NIS2, DORA, and the EU AI Act are roadmap items on their platforms. re-entry is EU-native from day one: the control library is the regulation, the export format is what a BSI auditor expects, support is German, and the hosting never leaves Frankfurt.
Which regulation should a team start with?
Teams operating in NIS2 essential or important sectors start with NIS2 because it has been in force since October 2024 and management bodies are personally on the hook. Financial entities have DORA in parallel from January 2025. Teams building or deploying AI systems layer the EU AI Act on top.
Do customers still need a compliance consultant?
Yes for legal interpretation and final sign-off, no for the 70% of the work that is evidence collection, control mapping, and report assembly. re-entry replaces the spreadsheet-and-Confluence phase.
Is data hosted in the EU?
Yes, in Frankfurt, with no US sub-processor on the data path.
AI Agent Governance & PR Risk Scoring | Re-entry.ai