Advisory
Risk mapping, governance frameworks and regulatory readiness, delivered by specialists who have shipped AI Act and NIS2 programmes end to end.
From exposed to compliant.
The EU AI Act. NIS2. CSRD. Some of it applies today. Some of it just moved to 2027. We tell you which is which, then fix what is actually live. Fixed price, no legal team, no surprises.
Start the free scan. In 30 minutes you will know whether the Cyberbeveiligingswet applies to you, whether your registration is in order, and where your AI use is exposed today.
Last verified 29 September 2026
EU AI Act, NIS2, ISO 42001 and GDPR. All mapped to the same controls. One workflow, not four.
Policies and reports written for owners and operators, not legal teams. Auditors get what they need. You stay in control.
Fixed scope, fixed price, no surprise hours. We handle the complexity so your team keeps building the business.
Risk mapping, governance frameworks and regulatory readiness, delivered by specialists who have shipped AI Act and NIS2 programmes end to end.
The most complete compliance platform for regulated AI. Live scoring, automated assessments and audit-ready documentation that evolves faster than the frameworks you face.
Boards, process owners and teams, trained to act. Programmes, materials and action lists that turn compliance from a burden into a capability.
We map your controls to these frameworks. Where a certification is required, we bring in a certified partner.
The Heldr platform turns EU AI Act, NIS2, CSRD and ISO 42001 obligations into clear, repeatable workflows. Five modules interpret, classify and document. So your team doesn't need a legal degree to stay ahead.
Map every AI tool in your company, classified by EU AI Act scope and risk.
A ranked action list: what is urgent, what is next, and what Heldr closes for you.
Policies, registers and DPIAs generated for you. And updated when the law changes.
One PDF for regulators, clients and procurement. Share it with confidence.
Live monitoring for prompt injection, data leaks, shadow AI and API flows.
The only sustainability figure we report is the one we can actually measure. What your AI use consumes, per model and per team, based on real token volume rather than an estimate.
Actual consumption across the models your teams use, not a projection.
Reported with confidence intervals, and with API-measured usage clearly separated from estimated SaaS usage.
Energy and usage limits checked before a new AI tool goes live, not after.
Free scoping call. We map your AI systems against the Act, NIS2 and GDPR, and hand you the first things to fix.
Become HeldrThree obligations that are live today. Three that are coming, with the dates we know.
The Cyberbeveiligingswet has applied since 15 August 2026 with no transition period. Registration, duty of care and incident reporting all started on day one.
Since 2 August 2026, chatbots must identify themselves and AI-generated or AI-edited content must be recognisable. In most companies this is sitting unflagged somewhere in marketing.
This never moved. Processing without a lawful basis or a DPIA is a problem today, not in 2027.
Annex III still classifies HR, credit and healthcare decisions as high-risk. The obligations are delayed while technical standards are finalised, phasing toward the end of 2027.
Added through the digital omnibus, taking effect at the end of 2026. A prohibition rather than a duty of care, so it applies immediately and without exception.
NIS2 already makes you answerable for your vendors. Your customers are not waiting for a deadline to start asking.