Published Aug 23, 2026 · Updated Aug 23, 2026 · 8 min read
EU Compliance Checklist for Websites 2026: GDPR, NIS2, DORA & EAA
Four regulations, dozens of requirements — here's the practical checklist every website serving EU users needs to work through in 2026. Use the free compliance scanner to check your site as you go.
⚡ Quick start: Enter your URL in the free EUComply scanner to see which checks your site passes and fails right now — no sign-up, no installation.
Why this matters in 2026
European digital regulations are no longer theoretical. Enforcement has accelerated across all four major frameworks:
- GDPR (General Data Protection Regulation) — now in its 8th enforcement year. Fines in 2025 exceeded €2.5 billion across the EU. National DPAs are increasingly targeting technical compliance, not just data-breach notification.
- NIS2 (Network and Information Security Directive) — transposed into national law across EU member states. Applies to medium-sized businesses in critical and important sectors, with direct supply-chain obligations.
- DORA (Digital Operational Resilience Act) — effective January 2025. Applies to financial entities and their ICT third-party providers. ICT risk management and testing are now mandatory.
- EAA (European Accessibility Act) — effective June 2025. Requires digital services and e-commerce to meet accessibility standards. An accessibility statement on your website is the minimum requirement.
Test your site right now
The free EUComply scanner checks all technical compliance gaps in under 10 seconds.
Run free scan →
No sign-up. No installation. Works on every platform.
The complete checklist
Work through each section. Items marked with ☐ are free-checks you can run with the online scanner. Items requiring documentation are Pro features.
1. Security & Encryption (GDPR Art. 32, NIS2 Art. 21)
- ☑ SSL / TLS certificate installed and valid on every subdomain
- ☑ HSTS header (Strict-Transport-Security) with a minimum age of 1 year
- ☑ HTTP requests redirect to HTTPS (301 redirect)
- ☐ Content Security Policy (CSP) header configured to prevent XSS
- ☐ X-Content-Type-Options: nosniff header present
- ☐ X-Frame-Options (DENY or SAMEORIGIN) or frame-src CSP directive
- ☐ Referrer-Policy header set (strict origin-when-cross-origin recommended)
- ☐ Mixed content audit — no HTTP resources loaded on HTTPS pages
2. Cookie Consent & Tracking (ePrivacy Directive, GDPR Art. 7)
- ☑ Cookie consent banner or mechanism present before any non-essential cookies
- ☐ Consent management platform (CMP) integrated — Cookiebot, OneTrust, CookieYes, Complianz or equivalent
- ☐ Granular consent: separate toggles for necessary, functional, analytics, marketing cookies
- ☐ Consent recorded with timestamp and proof (audit log)
- ☐ "Reject all" as prominently available as "Accept all"
- ☐ Cookie declaration / cookie policy page updated with current cookies
- ☐ Analytics and marketing scripts blocked until consent is given
3. Forms & Data Collection (GDPR Art. 5, 13)
- ☑ Every form has a visible link to the privacy policy
- ☐ Contact forms include a consent checkbox (not pre-checked)
- ☐ Newsletter signup has explicit opt-in (double opt-in recommended)
- ☐ Data collected is limited to what is necessary for the stated purpose
- ☐ Privacy policy explains what data is collected, for what purpose, how long it's stored, and who it's shared with
- ☐ Data retention schedule documented and enforced
4. Legal Pages (GDPR, eCommerce Directive, EAA)
- ☑ Privacy Policy linked from every page footer
- ☑ Imprint / Impressum linked (required for commercial sites in Germany, Austria, Switzerland)
- ☑ EAA Accessibility Statement page published (required from June 2025)
- ☐ Terms of Service / Terms and Conditions for commercial sites
- ☐ Cookie Policy page explaining what cookies are used
- ☐ Return / cancellation policy (for e-commerce sites — EU Consumer Rights Directive)
5. Backup & Recovery (NIS2 Art. 18, DORA Art. 6)
- ☐ Automated backups configured (daily for critical data)
- ☐ Backups stored in a separate location from production
- ☐ Recovery tested at least quarterly with documented results
- ☐ Backup retention policy defined and enforced
- ☐ Incident response plan documented (NIS2 Art. 23)
6. Supply Chain & Vendor Management (NIS2 Art. 21, DORA Art. 28)
- ☐ Data Processing Agreement (DPA) signed with every third-party vendor handling EU personal data
- ☐ Vendor risk assessment conducted and documented
- ☐ Incident notification clauses included in vendor contracts
- ☐ Sub-processor list maintained and updated
- ☐ ICT third-party register (DORA requirement for financial entities)
Which regulation applies to you?
Not all regulations apply to all businesses. Here's a quick decision guide:
| Regulation | Applies to | Enforcement |
| GDPR | Any organisation processing EU personal data | Active (2018+) |
| NIS2 | Medium+ enterprises in critical sectors (energy, transport, digital infrastructure, healthcare, public admin) | Active (2024-2026, national transposition) |
| DORA | Financial entities + their ICT providers | Active (Jan 2025) |
| EAA | Digital services, e-commerce, banking, transport, education | Active (June 2025) |
Bottom line: If you serve EU users, GDPR applies to you regardless of size. EAA applies if you sell to consumers. NIS2 and DORA are sector-specific. When in doubt, aim for the GDPR+NIS2 baseline — it covers the most common requirements.
Common gaps (based on real scans)
Based on scans run through EUComply, here are the most common compliance gaps we see:
- Missing or weak HSTS — ~40% of sites lack the HSTS header entirely, leaving users vulnerable to SSL stripping.
- No cookie consent mechanism — ~25% of smaller sites have no cookie banner at all, despite serving EU users.
- Privacy policy not linked from forms — forms are GDPR's top enforcement target for 2026 (Meta received multiple fines for unclear data handling).
- Missing accessibility statement — EAA went into effect June 2025; many sites still lack the mandated statement page.
- Missing security headers — CSP, X-Content-Type-Options, and Referrer-Policy are absent on most non-enterprise sites.
What good looks like
A fully compliant mid-sized site typically has:
- HTTPS with HSTS (grade A on SSL Labs)
- A consent management platform (cookie banner with granular controls)
- Privacy policy + imprint + accessibility statement in the footer
- DPA signed with all vendors
- Weekly automated backups tested quarterly
- Security headers: CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy
- An accessibility statement page (minimum EAA requirement)
How to maintain compliance
Compliance is not a one-time project. Regulations evolve, your site changes, and plugins go out of date. Here's a maintenance cadence:
- Monthly: Run a compliance scan (free scanner here)
- Quarterly: Review and update privacy policy, cookie declaration, DPA
- Annually: Full compliance audit + vendor risk review
- On change: Run a scan after every major site update, new plugin, or redesign
Need documented proof? The ComplianceDocs store has Pro templates: DPA agreements, NIS2 vendor clauses, EAA statements, and audit-report kits — ready to download and fill in. Pro annual subscription ($79/yr) includes automated PDF reports and document generators.
Check your compliance in 10 seconds
Free. No sign-up. Works on any website platform.
Run your free scan →
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for formal compliance requirements specific to your jurisdiction and business.