Back to playbooks
    Playbook

    From regulation to controls

    A repeatable method for turning a legal instrument into control objectives, controls, evidence and owners, worked end to end on NIS2 and on the CRA.

    Compliance4 Sept 202622 min read

    Directive (EU) 2022/2555ISO/IEC 27001:2022Regulation (EU) 2024/2847
    On this page

    Scope: one instrument turned into a control set · Who: the compliance lead who owns the mapping · Prerequisites: the official text and a control inventory · First result: one register

    1. Why this exists (the failure mode it prevents)

    Most regulatory mapping ends in one spreadsheet: article numbers, control identifiers, a colour. It is opened again only when someone outside asks a question.

    The question has a predictable shape. Show how Article 21(2)(d) is met. Show where the vulnerability-handling evidence for this product sits. The spreadsheet answers neither, because it never captured what the obligation requires, what was decided, or which record proves it.

    What follows is a finding or an information request. Under NIS2 a competent authority may require evidence of implementation of cybersecurity policies, such as security audit results 1. Under the Cyber Resilience Act a manufacturer must hold technical documentation covering every essential requirement, and a justification wherever one does not apply 2.

    The method below replaces the spreadsheet with a chain: identifier, objective, control, record, owner. An answer then becomes producible on demand, not assembled under pressure.

    2. Definitions (only the ones that cause disputes)

    Nine terms carry most of the argument.

    TermWorking definitionSource
    ObligationThe smallest piece of an instrument that can be complied with, breached and pointed at: a paragraph or lettered point. Article 21(2) carries ten.3
    Control objectiveThe outcome intended, stated so an outsider can test whether it holds. It names no mechanism.Clause 6.2, Information security objectives and planning to achieve them 4
    ControlThe mechanism chosen to produce the objective, determined from the treatment decision and only then compared against the reference set.Clause 6.1.3; Annex A, Information security controls reference 5
    EvidenceA record an outsider can inspect, with a producer, frequency and retention. A system name is a location.Clause 7.5.3, Control of documented information 6
    OwnerThe role accountable for the objective holding true, distinct from the body approving the measures.Clause 5.3, Organizational roles, responsibilities and authorities 7
    In scope vs applicableIn scope: the instrument reaches this entity or product. Applicable: a given obligation inside it bites here. The CRA demands a written justification where it does not.8
    Product with digital elementsA software or hardware product and its remote data processing solutions, reached where use includes a logical or physical connection to a network.9
    ManufacturerWhoever develops such a product, or has one developed, and markets it under their own name. Whoever substantially modifies one and makes it available is a manufacturer for the part affected, or for the whole product where its cybersecurity as a whole is affected.10
    Important and critical classImportant: the core functionality of an Annex III category, in class I or class II, routed under Article 32(2) and (3). Critical: an Annex IV category, which may need a certificate at assurance level at least substantial.11

    3. The method — numbered steps, each with input, activity, output and owner

    Eight steps in dependency order, each with an input, an activity, a named output and an owning role.

    3.1 Fix the scope before touching any control

    Scope is two questions: does the instrument reach this organisation or product, and in what capacity? For NIS2 the answer comes from Articles 2 and 3. An Annex I entity above the medium-sized ceilings is essential. So are qualified trust service providers, top-level domain name registries and DNS service providers, whatever their size. Everything else of a listed type is important 12. The class sets the supervisory regime. Essential entities face a comprehensive ex ante and ex post regime; important entities a light, ex post only, regime acted on when non-compliance is indicated 13.

    For the CRA the questions are the operator role and the product class. The four roles carry different obligation sets, and a substantial modification moves Articles 13 and 14 onto whoever made it 14. Class decides the conformity route 15.

    • Input: the official text; sector, headcount and turnover data; the product portfolio with connectivity and core function.
    • Activity: run each test in order; record the answer and the article behind it; list what it excludes, and why.
    • Output: scope determination memo, one citation per step, with an exclusion list.
    • Owner: compliance lead drafts; legal counsel confirms contested steps.

    3.2 Decompose the instrument into obligations

    The unit is the paragraph or lettered point. Mapping at article level is the commonest defect: one article holds obligations with different owners, evidence and clocks. Article 13 of the CRA carries twenty-five paragraphs 16, and a row against "Article 13" cannot be evidenced.

    Build each identifier from instrument, article, paragraph and point, so NIS2-21-2-d reads the same in a register, a ticket and a finding. Identifiers are never reused or renumbered, and a removed obligation is closed with a date so a past assessment still resolves. Mark the addressee too: a directive binds Member States, so several NIS2 obligations reach an organisation only through the transposing act 17.

    • Input: the official text, read in full rather than through a summary.
    • Activity: split to paragraph or point; paraphrase each in one sentence; record the citation; flag obligations addressed to Member States.
    • Output: obligation register with identifier, citation, paraphrase and applicability flag.
    • Owner: compliance lead.

    3.3 Classify each obligation

    Five classes are enough: governance, organisational, technical, reporting and documentation. The class predicts the owner, the evidence type and the review cadence. A register that is almost all technical has skipped the governance obligations an authority opens with.

    • Input: the obligation register from step 3.2.
    • Activity: assign one class per obligation; where one spans two, split the row rather than tagging both.
    • Output: obligation register with a class column and a distribution count.
    • Owner: compliance lead.

    3.4 Write one control objective per obligation

    One obligation, one objective. Three rules keep objectives usable: state a condition capable of being false, name the population, and include the interval that measures it. "Manage supply chain risk" fails all three. "Every direct supplier inside scope holds a current assessment of its vulnerabilities and secure development practice, refreshed annually" passes. It traces to Article 21(3), which asks entities to weigh each direct supplier's vulnerabilities 18.

    • Input: the classified register.
    • Activity: write the objective; test it against the three rules; have the owner confirm they could be held to it.
    • Output: obligation register with an objective column, confirmed by the owners.
    • Owner: compliance lead writes; the accountable role confirms.

    3.5 Select or design controls, and name the gaps

    Only now does a control set enter. Determine what is necessary from the objective, then compare that against the reference set for omissions. ISO/IEC 27001:2022 asks for that order at clause 6.1.3, where Annex A is the comparison set, not the starting inventory 5.

    Two outcomes are legitimate. Either an existing control already produces the objective, or nothing covers it and a new control is designed. The second is common with product regulation. No reference control matches a software bill of materials or a coordinated disclosure policy, both of which the CRA requires 19. A register that never records a gap was written backwards.

    • Input: the register with objectives; the control inventory and Statement of Applicability.
    • Activity: map each objective to existing controls; mark partial coverage as partial; design controls for the rest; record every addition against the Statement of Applicability.
    • Output: control mapping matrix, coverage recorded as full, partial or none, plus a gap list.
    • Owner: compliance lead owns the matrix; control owners confirm what their control does.

    3.6 Define the evidence per control

    Evidence is a record, not a system. Four fields make it inspectable: the record, its producer, how often, and how long it is kept. Retention is sometimes a legal figure. Technical documentation and the declaration of conformity stay available to market surveillance authorities for ten years, or the support period if longer 20. Each security update stays available for ten years or the rest of that period 21. NIS2 sets no equivalent rule.

    • Input: the control mapping matrix.
    • Activity: name the record per control, with producer, frequency and retention; check it exists, and open an action where it does not.
    • Output: evidence catalogue, one row per record, cross-referenced to obligation identifiers.
    • Owner: compliance lead owns the catalogue; each record's producer owns the record.

    3.7 Assign owners as roles

    Two owner columns, not one. The accountable role answers for the objective; the approving body signs off the measure set. Under NIS2 those differ: management bodies approve the measures, oversee implementation, can be held liable, and must themselves follow training 22. Never record a person; a register of names decays at the first reorganisation.

    • Input: the evidence catalogue and the organisation's role model.
    • Activity: assign an accountable role per obligation and an approving body; check no role owns more than it can evidence; record the approval with a date.
    • Output: owner matrix; the minuted approval of the measure set.
    • Owner: compliance lead prepares; the management body approves.

    3.8 Keep the mapping alive

    A register with no change triggers will be wrong within a year. Six triggers cover most movement, each naming the artefact it reopens.

    • Amendment. The register is re-decomposed; closed rows are dated, never deleted.

    • Implementing acts. NIS2 required implementing acts by 17 October 2024 for the listed digital categories 23. That act is Commission Implementing Regulation (EU) 2024/2690 24; objectives then follow its wording.

    • Delegated acts. The Commission may amend the Annex III categories, set minimum support periods, and add Annex VII elements 25.

    • Harmonised standards. A product conforming to a harmonised standard published in the Official Journal is presumed to conform to what that standard covers 26. A new publication can retire a bespoke control.

    • National transposition. Member States adopted the NIS2 measures by 17 October 2024 and apply them from 18 October 2024 17. Sweden's Cybersäkerhetslag (2025:1506) took effect on 15 January 2026 27; the citation column moves to the national act.

    • Product change. A substantial modification brings Articles 13 and 14 onto the modified part 28. Series production carries its own conformity duty 29.

    • Input: the four artefacts, plus a watchlist of the instruments and standards touching them.

    • Activity: review the watchlist quarterly; open the affected artefact per hit; record the review even when nothing moved.

    • Output: change-trigger watchlist with a dated review record.

    • Owner: compliance lead, fed by horizon scanning.

    Worked pass A — Directive (EU) 2022/2555, Article 21(2)

    The Article 21 measures must be appropriate and proportionate, rest on an all-hazards approach, and protect the physical environment too 30. Paragraph 2 sets a floor of ten, at points (a) to (j). The table takes each through steps 3.3, 3.6 and 3.7; objective and controls are in section 7.

    IDClassEvidence recordOwner
    NIS2-21-2-agovernanceRisk methodology; register with owner and acceptance dateCompliance lead
    NIS2-21-2-borganisationalIncident record with classification, timestamps, significance decisionIncident manager
    NIS2-21-2-corganisationalRestore-test result; exercise report; crisis contact list, testedContinuity manager
    NIS2-21-2-dorganisationalSupplier assessment with date; contract terms; reassessment scheduleProcurement
    NIS2-21-2-etechnicalGate records with the security decision; remediation queue with timesEngineering lead
    NIS2-21-2-fgovernanceMeasurement results; independent review report; a change traced to oneCompliance lead
    NIS2-21-2-gorganisationalPer-person completion record; management-body attendance recordPeople function
    NIS2-21-2-htechnicalCryptographic standard; key inventory with rotation dates; review outputEngineering lead
    NIS2-21-2-iorganisationalLeaver disablement times; access review results; asset ownersPeople and technology operations
    NIS2-21-2-jtechnicalAuthentication coverage report; out-of-band channel test recordTechnology operations
    Article 21(2) register rows

    Four duties sit around it. Article 20(1) puts approval and oversight on the management body, with liability attached; Article 20(2) requires its members to follow training. Article 21(4) requires an entity that finds it does not comply to take corrective measures without undue delay 31. Article 23(4) sets the clock: early warning within 24 hours of awareness, notification within 72 hours, final report within one month 32. Significance is defined at Article 23(3) by severe disruption or financial loss, or considerable damage to others 33.

    Worked pass B — Regulation (EU) 2024/2847, manufacturer obligations

    The CRA has a product half and a process half. A product may be made available only where it meets the requirements in Annex I Part I. The manufacturer's processes must meet the vulnerability-handling requirements in Part II 34. Part I point (2) lists thirteen product properties, at (a) to (m); Part II lists eight process requirements 35.

    IDObligation, in shortClassEvidence recordOwner
    CRA-13-01Build to the requirements in Annex I Part ItechnicalConformity record per requirement, per versionProduct owner
    CRA-13-03Document the product risk assessment; state how each Part I requirement applies, and justify what does notdocumentationDated assessment with applicability statement and justificationsProduct security lead
    CRA-13-05Due diligence on third-party and open-source components; report upstreamorganisationalDue-diligence record; upstream report logEngineering lead
    CRA-13-08Set the support period; hold a coordinated disclosure policygovernanceDetermination record; published disclosure policyProduct owner
    CRA-13-09Keep each update available ten years, or the rest of the periodtechnicalUpdate archive; retrieval sampleRelease engineering
    CRA-13-12Documentation, assessment, declaration, CE marking; series production stays in conformitydocumentationThe four artefacts, dated; change record with the conformity decisionProduct compliance role
    CRA-13-17A single contact for users; support-period end date at purchaseorganisationalPublished contact with response times; purchase-path evidenceProduct security lead
    CRA-13-21Immediate corrective measures on known non-conformitygovernanceNon-conformity record with decision and dateProduct owner
    CRA-14-02Notify an actively exploited vulnerability, and a severe incidentreportingTimestamped submissions; awareness and severity recordsProduct security lead
    CRA-A1-II-1Produce a bill of materials; disclose fixed vulnerabilitiesdocumentationMachine-readable bill of materials; published advisoriesEngineering lead
    Manufacturer obligations as register rows

    Both reporting duties share a route: simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform 36. For a vulnerability the final report is due within 14 days of a corrective or mitigating measure becoming available. For a severe incident it is due within one month of the 72-hour notification 37. Severity has two tests. One is an effect on the product's ability to protect sensitive data or functions. The other is the introduction or execution of malicious code 38.

    The evidence catalogue has a spine here. Annex VII lists eight items the technical documentation must contain, from the product and process descriptions to the bill of materials 39. Two dates set the sequencing. Article 14 applies from 11 September 2026 and the rest of the Regulation from 11 December 2027 40. Products placed on the market before that date escape the substantive requirements unless substantially modified, yet the Article 14 duties reach all of them 41. A shipped fleet reports long before the essential requirements apply.

    4. Deliverables

    Four artefacts carry the method and two support it. No template ships yet, so the column says so.

    DeliverableFormatTemplateRetention
    Scope determination memodocumenttemplate pendingcurrent plus one certification cycle
    Obligation registerspreadsheet or registertemplate pendinglife of the instrument; closed rows kept
    Control mapping matrixspreadsheet or registertemplate pendingevery version, whole cycle
    Evidence catalogueregistertemplate pendingas long as the longest record it points at
    Owner matrixregistertemplate pendingcurrent plus one cycle, approval dates kept
    Change-trigger watchlistregistertemplate pendingwhole cycle, with the dated review record

    For CRA artefacts the retention floor is legal; for NIS2 artefacts it is a choice, held in the document control register under ISO/IEC 27001:2022 clause 7.5.3 6.

    5. What the auditor or authority will ask

    Each question is answered by one artefact from section 4, via the obligation identifier. More than two hops means the chain is broken.

    6. Failure modes and how they surface as findings

    Five patterns account for most of the avoidable damage: the pattern, the finding it produces, and the smallest fix.

    7. Mapping to standards

    Each row carries its own article citation, read at the EU Publications Office. Annex A control titles come from the ISO Online Browsing Platform contents listing 42, as do the ISO/IEC 27001:2022 clause titles 43. That listing stops at 8.1, so technological controls are cited at clause level.

    Art. 21(2)Control objective, in shortAnnex A controlsVerified
    (a) Risk analysis and security policiesRisk analysis runs to approved criteria, each entry with an ownerA.5.1 Policies for information security; A.5.2 Information security roles and responsibilities44
    (b) Incident handlingIncidents are classified against written significance criteriaA.5.24 to A.5.27, the information security incident management controls45
    (c) Continuity, backup, recovery, crisis managementRecovery targets are met under test; crisis roles sit above technologyISO/IEC 27002:2022 clause 5, Organizational controls, at clause level46
    (d) Supply chain securityEvery direct supplier in scope holds a current assessmentA.5.19 Information security in supplier relationships, through A.5.22 Monitoring, review and change management of supplier services47
    (e) Acquisition, development, maintenance; vulnerability handlingSecurity enters at design; vulnerabilities carry a clockISO/IEC 27002:2022 clause 8, Technological controls, at clause level48
    (f) Assessing the effectiveness of the measuresEach measure has a check; one result changed something this cycleA.5.35 Independent review of information security; A.5.36 Compliance with policies, rules and standards for information security49
    (g) Cyber hygiene and trainingEveryone trains for their role, the management body separatelyA.6.3 Information security awareness, education and training50
    (h) Cryptography and encryptionAlgorithms and key lifecycles are defined; configurations matchISO/IEC 27002:2022 clause 8, Technological controls, at clause level51
    (i) HR security, access control, asset managementJoiner, mover and leaver changes complete within a stated intervalISO/IEC 27002:2022 clauses 5 and 6, at clause level52
    (j) Multi-factor or continuous authentication; secured and emergency communicationsAuthentication covers the stated population; one channel survives an outageISO/IEC 27002:2022 clauses 5 and 8, at clause level53
    Article 21(2) to objective to Annex A control
    Article or Annex itemControl objective, in shortControls, and the gapVerified
    Art. 13(1); Annex I Part IA recorded decision covers each Part I requirement, per versionClause 8, at clause level. Gap: product properties are not a management-system control54
    Art. 13(2) to 13(4)A current product risk assessment exists per versionClauses 6.1.2 and 8.2, as a separate product register. Gap: the scope is the product55
    Art. 13(5), 13(6)No component ships unchecked; upstream reports go on a clockA.5.19 to A.5.22, supplier controls. Gap: reporting a fix upstream56
    Art. 13(8), 13(9); Annex I Part II point (5)The support period rests on recorded grounds; the policy is publicA.5.1 Policies for information security. Gap: a declared support period has none57
    Art. 13(12) to 13(14); Art. 31The four conformity artefacts stay retrievable through changeClause 7.5.3 Control of documented information; clause 8.1 Operational planning and control; A.5.37 Documented operating procedures58
    Art. 13(17), 13(19), 13(21)A contact is published, the end date shows at purchase, non-conformity is correctedClause 10.2 Nonconformity and corrective action; A.5.24 to A.5.27, partly. Gap: an external intake address59
    Art. 14(1) to 14(4)Submissions leave within the 24-hour, 72-hour and final windowsA.5.24 to A.5.27, incident management. Gap: the external clock, the two-recipient route, the statutory severity test60
    Annex I Part II points (1), (3), (4), (7), (8)Each release carries a bill of materials, is tested, and ships advisoriesA.5.35 and A.5.36 for testing; clause 8 for distribution. Gap: no reference control requires a bill of materials61
    CRA obligation to objective to control, with the gap named

    8. Checklist

    Each item is observable; "mapped" is not.

    References

    Primary sources only.

    1. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. Read at https://publications.europa.eu/resource/celex/32022L2555 62
    2. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. Read at https://publications.europa.eu/resource/celex/32024R2847 63
    3. European Commission. Commission Implementing Regulation (EU) 2024/2690. https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj/eng 24
    4. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 43
    5. ISO/IEC. Information security controls. ISO/IEC 27002:2022. Read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27002:ed-3:v2:en 42
    6. Sveriges riksdag. Cybersäkerhetslag (2025:1506), in force 15 January 2026. https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetslag-20251506_sfs-2025-1506/ 27

    Cadences and retention periods are organisational choices unless an article sets the figure.

    Sources

    1. 1EU Publications Office CELEX 32022L2555 Art. 32(2)(g) · verified 2026-09-04
    2. 2EU Publications Office CELEX 32024R2847 Art. 13(4) and Art. 31(1) · verified 2026-09-04
    3. 3EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-04
    4. 4ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
    5. 5ISO/IEC 27001:2022 clause 6.1.3 and Annex A, iso.org/obp · verified 2026-09-03
    6. 6ISO/IEC 27001:2022 clause 7.5.3, iso.org/obp · verified 2026-09-03
    7. 7ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    8. 8EU Publications Office CELEX 32024R2847 Art. 2(1) and Art. 13(4) · verified 2026-09-04
    9. 9EU Publications Office CELEX 32024R2847 Art. 3(1) and Art. 2(1) · verified 2026-09-04
    10. 10EU Publications Office CELEX 32024R2847 Art. 3(13) and Art. 22 · verified 2026-09-04
    11. 11EU Publications Office CELEX 32024R2847 Art. 7(1) and Art. 8(1) · verified 2026-09-04
    12. 12EU Publications Office CELEX 32022L2555 Art. 3(1) and 3(2) · verified 2026-09-04
    13. 13EU Publications Office CELEX 32022L2555 recital (122) and Art. 33(1) · verified 2026-09-04
    14. 14EU Publications Office CELEX 32024R2847 Art. 3(12) and Art. 22 · verified 2026-09-04
    15. 15EU Publications Office CELEX 32024R2847 Art. 7(1) and Art. 32(1) · verified 2026-09-04
    16. 16EU Publications Office CELEX 32024R2847 Art. 13 · verified 2026-09-04
    17. 17EU Publications Office CELEX 32022L2555 Art. 41(1) · verified 2026-09-04
    18. 18EU Publications Office CELEX 32022L2555 Art. 21(3) · verified 2026-09-04
    19. 19EU Publications Office CELEX 32024R2847 Annex I Part II points (1) and (5) · verified 2026-09-04
    20. 20EU Publications Office CELEX 32024R2847 Art. 13(13) · verified 2026-09-04
    21. 21EU Publications Office CELEX 32024R2847 Art. 13(9) · verified 2026-09-04
    22. 22EU Publications Office CELEX 32022L2555 Art. 20(1) and 20(2) · verified 2026-09-04
    23. 23EU Publications Office CELEX 32022L2555 Art. 21(5) · verified 2026-09-04
    24. 24standards register, publications.europa.eu CELEX 32024R2690 · verified 2026-09-03
    25. 25EU Publications Office CELEX 32024R2847 Art. 7(3), Art. 13(8) and Art. 31(5) · verified 2026-09-04
    26. 26EU Publications Office CELEX 32024R2847 Art. 27(1) · verified 2026-09-04
    27. 27riksdagen.se SFS 2025:1506 · verified 2026-09-03
    28. 28EU Publications Office CELEX 32024R2847 Art. 22(1) and 22(2) · verified 2026-09-04
    29. 29EU Publications Office CELEX 32024R2847 Art. 13(14) · verified 2026-09-04
    30. 30EU Publications Office CELEX 32022L2555 Art. 21(1) and 21(2) · verified 2026-09-04
    31. 31EU Publications Office CELEX 32022L2555 Art. 21(4) · verified 2026-09-04
    32. 32EU Publications Office CELEX 32022L2555 Art. 23(4) · verified 2026-09-04
    33. 33EU Publications Office CELEX 32022L2555 Art. 23(3) · verified 2026-09-04
    34. 34EU Publications Office CELEX 32024R2847 Art. 6 · verified 2026-09-04
    35. 35EU Publications Office CELEX 32024R2847 Annex I Part I and Part II · verified 2026-09-04
    36. 36EU Publications Office CELEX 32024R2847 Art. 14(1), 14(3) and 14(7) · verified 2026-09-04
    37. 37EU Publications Office CELEX 32024R2847 Art. 14(2)(c) and 14(4)(c) · verified 2026-09-04
    38. 38EU Publications Office CELEX 32024R2847 Art. 14(5) · verified 2026-09-04
    39. 39EU Publications Office CELEX 32024R2847 Annex VII · verified 2026-09-04
    40. 40EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-04
    41. 41EU Publications Office CELEX 32024R2847 Art. 69(2) and 69(3) · verified 2026-09-04
    42. 42ISO/IEC 27002:2022 contents, iso.org/obp · verified 2026-09-03
    43. 43ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
    44. 44EU Publications Office CELEX 32022L2555 Art. 21(2)(a) · verified 2026-09-04
    45. 45EU Publications Office CELEX 32022L2555 Art. 21(2)(b) · verified 2026-09-04
    46. 46EU Publications Office CELEX 32022L2555 Art. 21(2)(c) · verified 2026-09-04
    47. 47EU Publications Office CELEX 32022L2555 Art. 21(2)(d) · verified 2026-09-04
    48. 48EU Publications Office CELEX 32022L2555 Art. 21(2)(e) · verified 2026-09-04
    49. 49EU Publications Office CELEX 32022L2555 Art. 21(2)(f) · verified 2026-09-04
    50. 50EU Publications Office CELEX 32022L2555 Art. 21(2)(g) · verified 2026-09-04
    51. 51EU Publications Office CELEX 32022L2555 Art. 21(2)(h) · verified 2026-09-04
    52. 52EU Publications Office CELEX 32022L2555 Art. 21(2)(i) · verified 2026-09-04
    53. 53EU Publications Office CELEX 32022L2555 Art. 21(2)(j) · verified 2026-09-04
    54. 54EU Publications Office CELEX 32024R2847 Art. 13(1) and Annex I Part I · verified 2026-09-04
    55. 55EU Publications Office CELEX 32024R2847 Art. 13(2), 13(3) and 13(4) · verified 2026-09-04
    56. 56EU Publications Office CELEX 32024R2847 Art. 13(5) and 13(6) · verified 2026-09-04
    57. 57EU Publications Office CELEX 32024R2847 Art. 13(8), 13(9), Annex I Part II point (5) and Annex II point (2) · verified 2026-09-04
    58. 58EU Publications Office CELEX 32024R2847 Art. 13(12), 13(13), 13(14) and Art. 31(1) · verified 2026-09-04
    59. 59EU Publications Office CELEX 32024R2847 Art. 13(17), 13(19) and 13(21) · verified 2026-09-04
    60. 60EU Publications Office CELEX 32024R2847 Art. 14(1), 14(2), 14(3) and 14(4) · verified 2026-09-04
    61. 61EU Publications Office CELEX 32024R2847 Annex I Part II points (1), (3), (4), (7) and (8) · verified 2026-09-04
    62. 62EU Publications Office CELEX 32022L2555 · verified 2026-09-04
    63. 63EU Publications Office CELEX 32024R2847 · verified 2026-09-04