Service 09

ML2Law

Compliance and technology

Integrated regulatory oversight of the main obligations impacting IT and business: AI Act, NIS2, CRA, GDPR, ESG, Model 231 and the management of contracts and licenses. From risk analysis to obligations and deadlines, every area is managed with method and technology. Compliance becomes the springboard toward ISO certifications and access to dedicated funding.

AI Act, NIS2, CRAGDPR & Model 231ESG / CSRDToward ISO certificationsMEPA-registered

Compliance as competitive advantage

Integrated regulatory oversight: AI Act, NIS2, CRA, GDPR, ESG, 231 and contracts, managed with method and technology.

ML2Law

Compliance and technology

Integrated regulatory oversight of the main obligations impacting IT and business, managed with method and technology. From risk analysis to obligations and deadlines, through to contracts and licenses.

AI Act EU Reg. 2024/1689 and Italian Law 132/2025. Risk classification, obligations for providers and deployers, FRIA for the public sector. High-risk systems from 2 August 2026.
NIS 2 EU Dir. 2022/2555 and Legislative Decree 138/2024. Cybersecurity measures, supply chain and incident notification to the CSIRT. Full compliance by 31 October 2026.
CRA EU Reg. 2024/2847 (Cyber Resilience Act). Cybersecurity requirements and CE marking for products with digital elements (hardware and software). Main obligations from 11 December 2027.
ESG / CSRD EU Dir. 2022/2464 and Legislative Decree 125/2024. Sustainability reporting on ESRS standards with mandatory assurance and the double-materiality principle.
GDPR EU Reg. 2016/679 and Legislative Decree 101/2018. Accountability, privacy by design, DPO appointment and data breach notification within 72 hours.
Model 231 Legislative Decree 231/2001. Administrative liability of entities: Organization and Management Model, Supervisory Body and whistleblowing channels.
Contracts & Licenses Management of IT contracts, software licenses and compliance clauses, aligned with the applicable regulatory framework.

Added value: compliance is the springboard toward ISO certifications (42001, 27001, 27701, 22301, 14001, 45001, 37001) and access to dedicated funding — NRRP and Transition 5.0, Digital Europe funds, regional ERDF calls and INAIL grants.

The areas of regulatory oversight

Each area can be engaged on its own or as an integrated path, scaled to your real needs.

01
AI

AI Act

EU Reg. 2024/1689 and Italian Law 132/2025: the European and Italian framework for artificial intelligence, managed across the whole compliance cycle.

  • Risk classification of AI systems
  • Distinct obligations for providers and deployers, FRIA for the public sector
  • High-risk systems from 2 August 2026

What you getMapping of systems and a compliance plan with deadlines under control.

02
Cyber

NIS 2

EU Dir. 2022/2555 and Legislative Decree 138/2024: cybersecurity measures for essential and important entities, from supply chain to incident notification.

  • Cybersecurity measures and supply chain oversight
  • Incident notification to the CSIRT
  • Full compliance by 31 October 2026

What you getGap analysis and technical and organizational measures aligned to the obligations.

03
Products

CRA

EU Reg. 2024/2847 (Cyber Resilience Act): cybersecurity requirements for products with digital elements, hardware and software.

  • Cybersecurity requirements across the product life cycle
  • CE marking for products with digital elements
  • Main obligations from 11 December 2027

What you getA product compliance path toward CE marking.

04
Sustainability

ESG / CSRD

EU Dir. 2022/2464 and Legislative Decree 125/2024: sustainability reporting on ESRS standards, with mandatory assurance and double materiality.

  • Reporting on ESRS standards
  • Mandatory assurance
  • Double-materiality principle

What you getA compliant, verifiable ESG reporting framework.

05
Privacy

GDPR

EU Reg. 2016/679 and Legislative Decree 101/2018: oversight of personal data protection, from accountability to data breach management.

  • Accountability and privacy by design
  • DPO appointment
  • Data breach notification within 72 hours

What you getDocumented, audit-ready privacy governance.

06
Entities

Model 231

Legislative Decree 231/2001: the administrative liability of entities, with the Organization and Management Model and its control safeguards.

  • Organization and Management Model
  • Supervisory Body
  • Whistleblowing channels

What you getA Model 231 adopted and overseen by the Supervisory Body.

07
Contracts

Contracts & Licenses

Management of IT contracts, software licenses and compliance clauses, aligned with the applicable regulatory framework.

  • IT contracts
  • Software licenses
  • Compliance clauses aligned with the regulation

What you getContracts and licenses consistent with current obligations.

A Four-Step Path

Every project starts from where you really are: a no-commitment initial assessment to define priorities and goals.

01
Risk analysis

Review of the applicable obligations and assessment of regulatory risk across IT and business.

02
Compliance plan

Gap analysis and a roadmap of obligations, with deadlines mapped regulation by regulation.

03
Obligations

Implementation of measures, models and contracts compliant with the applicable regulatory framework.

04
Certifications & deadlines

Continuous oversight of deadlines and access to ISO certifications and dedicated funding.

Let's Talk, No Commitment

Tell us your need: you'll get a clear picture of the priorities, even if the path continues without us.

Contact ML TWO

Or write directly to info@mltwo.it