Built for SMBs · EU AI Act · NIS2 · ISO 42001 · GDPR

Become Heldr.

From exposed to compliant.

The EU AI Act. NIS2. CSRD. Some of it applies today. Some of it just moved to 2027. We tell you which is which, then fix what is actually live. Fixed price, no legal team, no surprises.

Start the free scan. In 30 minutes you will know whether the Cyberbeveiligingswet applies to you, whether your registration is in order, and where your AI use is exposed today.

Compliant
EU AI Act, NIS2, CSRD
Protected
Prompt injections, data leaks, shadow AI
Sustainable
Energy, water, CSRD reporting

What applies to you today

  • NIS2 · CyberbeveiligingswetLiveIn force since 15 August 2026. No transition period.
  • AI Act · transparency obligationsLiveIn force since 2 August 2026.
  • AI Act · high-risk obligationsDelayedTechnical standards pending. Phasing toward the end of 2027.
  • GDPRLiveApplies in full to any AI system processing personal data.

Last verified 29 September 2026

Why Heldr

Compliance built for SMBs, not lawyers.

One register, every framework

EU AI Act, NIS2, ISO 42001 and GDPR. All mapped to the same controls. One workflow, not four.

Plain-language evidence

Policies and reports written for owners and operators, not legal teams. Auditors get what they need. You stay in control.

Built with SMBs in mind

Fixed scope, fixed price, no surprise hours. We handle the complexity so your team keeps building the business.

What we deliver

Three ways to own compliance.

Available now01

Advisory

Risk mapping, governance frameworks and regulatory readiness, delivered by specialists who have shipped AI Act and NIS2 programmes end to end.

Talk to us
Coming soon02

Platform

The most complete compliance platform for regulated AI. Live scoring, automated assessments and audit-ready documentation that evolves faster than the frameworks you face.

Join waitlist
03

Training & Workshops

Boards, process owners and teams, trained to act. Programmes, materials and action lists that turn compliance from a burden into a capability.

Talk to us
Frameworks
Frameworks we cover

We map your controls to these frameworks. Where a certification is required, we bring in a certified partner.

ISO 27001ISO/IEC 42001NIS2GDPRSOC 2DORA
Platform · Waitlist open

Compliance that never sleeps. So you can.

The Heldr platform turns EU AI Act, NIS2, CSRD and ISO 42001 obligations into clear, repeatable workflows. Five modules interpret, classify and document. So your team doesn't need a legal degree to stay ahead.

EU AI Act
EU rules that classify AI systems by risk and define exactly what you must prove.
NIS2
EU directive that raises cybersecurity duties for essential and important entities.
CSRD
EU sustainability reporting that puts AI energy and water use on the record.
ISO 42001
International standard for building responsible AI management systems.
Five modules
Module 01

AI Inventory

Map every AI tool in your company, classified by EU AI Act scope and risk.

Module 02

Gap Analysis

A ranked action list: what is urgent, what is next, and what Heldr closes for you.

Module 03

Compliance Builder

Policies, registers and DPIAs generated for you. And updated when the law changes.

Module 04

Compliance Report

One PDF for regulators, clients and procurement. Share it with confidence.

Module 05

Active Protection

Live monitoring for prompt injection, data leaks, shadow AI and API flows.

Sustainability

AI usage, measured.

The only sustainability figure we report is the one we can actually measure. What your AI use consumes, per model and per team, based on real token volume rather than an estimate.

Token-level usage across providers

Actual consumption across the models your teams use, not a projection.

Energy and emissions per model

Reported with confidence intervals, and with API-measured usage clearly separated from estimated SaaS usage.

Thresholds in your approval workflow

Energy and usage limits checked before a new AI tool goes live, not after.

Become Heldr
in 30 minutes.

Free scoping call. We map your AI systems against the Act, NIS2 and GDPR, and hand you the first things to fix.

Become Heldr
The exposure

No countdown. Just what is true right now.

Three obligations that are live today. Three that are coming, with the dates we know.

LIVE TODAY

NIS2 registration is overdue for thousands of Dutch companies

The Cyberbeveiligingswet has applied since 15 August 2026 with no transition period. Registration, duty of care and incident reporting all started on day one.

AI output published without disclosure

Since 2 August 2026, chatbots must identify themselves and AI-generated or AI-edited content must be recognisable. In most companies this is sitting unflagged somewhere in marketing.

Special category data in training sets under GDPR Article 9

This never moved. Processing without a lawful basis or a DPIA is a problem today, not in 2027.

COMING, WITH DATES

High-risk AI obligations

Annex III still classifies HR, credit and healthcare decisions as high-risk. The obligations are delayed while technical standards are finalised, phasing toward the end of 2027.

New prohibitions on AI-generated child sexual abuse material and non-consensual nudification

Added through the digital omnibus, taking effect at the end of 2026. A prohibition rather than a duty of care, so it applies immediately and without exception.

Supply chain accountability

NIS2 already makes you answerable for your vendors. Your customers are not waiting for a deadline to start asking.