Regulation Decoded

EU regulation, written for the people who have to implement it.

Practical guides to the Cyber Resilience Act, NIS2, DORA, the EU AI Act and the GDPR — for compliance, security and product teams.

What this is

Regulation Decoded publishes working guides to EU regulation. Not commentary, and not a summary of the recitals: each book traces every obligation to the article that creates it, and ends each chapter with something you can put in front of an auditor.

The books are written for the person who has to deliver the work — a product security lead, a compliance manager, a founder who has just discovered that a regulation applies to them — rather than for a lawyer advising from outside.

Updates

Regulatory books date. When the law covered by a book changes materially, a dated change note is published in the public change log — stating what changed and which chapters and templates it affects.

The change log is open to everyone. No registration, no purchase, no marketing list.

Read the change log and update policy →

Contact

Questions about a book, a change you think has been missed, or a bulk or licensing enquiry: tiina@regulationdecoded.com