ML2Law
Compliance and technology
Integrated regulatory oversight of the main obligations impacting IT and business, managed with method and technology. From risk analysis to obligations and deadlines, through to contracts and licenses.
AI Act
EU Reg. 2024/1689 and Italian Law 132/2025. Risk classification, obligations for providers and deployers, FRIA for the public sector. High-risk systems from 2 August 2026.
NIS 2
EU Dir. 2022/2555 and Legislative Decree 138/2024. Cybersecurity measures, supply chain and incident notification to the CSIRT. Full compliance by 31 October 2026.
CRA
EU Reg. 2024/2847 (Cyber Resilience Act). Cybersecurity requirements and CE marking for products with digital elements (hardware and software). Main obligations from 11 December 2027.
ESG / CSRD
EU Dir. 2022/2464 and Legislative Decree 125/2024. Sustainability reporting on ESRS standards with mandatory assurance and the double-materiality principle.
GDPR
EU Reg. 2016/679 and Legislative Decree 101/2018. Accountability, privacy by design, DPO appointment and data breach notification within 72 hours.
Model 231
Legislative Decree 231/2001. Administrative liability of entities: Organization and Management Model, Supervisory Body and whistleblowing channels.
Contracts & Licenses
Management of IT contracts, software licenses and compliance clauses, aligned with the applicable regulatory framework.
Added value: compliance is the springboard toward ISO certifications (42001, 27001, 27701, 22301, 14001, 45001, 37001) and access to dedicated funding — NRRP and Transition 5.0, Digital Europe funds, regional ERDF calls and INAIL grants.