EXPERTISE

Interconnected expertise for a complex regulatory landscape.

Regulatory requirements increasingly operate across legal, technical, standards and market boundaries.

OSTRAI helps organisations understand what applies, anticipate regulatory change and navigate the path from requirements to implementation.

Principal focus: European regulation · International perspective

Discuss a regulatory matter
Limestone passage and steps connecting a layered courtyard
01 – 06 Expertise

OSTRAI advises across privacy and data, cybersecurity and product regulation, artificial intelligence, digital regulation, standards and standardisation, and regulatory market access and conformity.

OUR EXPERTISE

Focused expertise in a wider regulatory context.

The relevant task is to identify the requirements that matter to the organisation, product, technology or activity concerned, together with the wider regulatory environment that may affect their interpretation or implementation.

Where regulatory frameworks interact, OSTRAI examines the resulting dependencies, interfaces and potential conflicts as part of the wider regulatory pathway.

01

Privacy & Data

GOVERNANCE · TRANSFERS · REPRESENTATION

Data regulation across governance, operations and borders.

KEY LEGISLATION

GDPR · UK GDPR · ePrivacy Directive

Privacy and data regulation shapes how organisations use information, structure processing activities, design governance and operate across jurisdictions.

View scope of expertise

OSTRAI advises on the interpretation and implementation of data protection requirements, including regulatory applicability, accountability and governance, privacy risk, international data transfers, ongoing regulatory roles, regulatory representation and cross-border privacy matters.

Where relevant, we also examine the interaction between privacy and other regulatory frameworks, including artificial intelligence, cybersecurity and digital regulation.

Explore Privacy & Data
02

Cybersecurity & Product Regulation

CYBERSECURITY · PRODUCT REGULATION · LIFECYCLE OBLIGATIONS

Cybersecurity across organisations, products and the regulatory lifecycle.

KEY LEGISLATION

Cyber Resilience Act · NIS2 · Cybersecurity Act

Cybersecurity regulation increasingly extends beyond organisational security into the development, supply, operation and continuing compliance of products and technologies.

View scope of expertise

OSTRAI advises on regulatory applicability, regulated roles and responsibilities, governance, vulnerability and incident obligations, supply-chain requirements, documentation, standards, conformity and market-access implications.

Our work includes the Cyber Resilience Act, NIS2 and related European cybersecurity, product and technology regulatory frameworks, including sector-specific requirements where cybersecurity forms part of a wider regulatory regime.

Where a matter involves several product, cybersecurity or sector-specific regimes, we examine their requirements together and identify the resulting regulatory pathway.

Explore Cybersecurity & Product Regulation
03

Artificial Intelligence

AI ACT · CLASSIFICATION · GOVERNANCE

AI regulation across development, deployment and use.

KEY LEGISLATION

EU AI Act

Artificial intelligence regulation engages questions of governance, data, cybersecurity, product regulation, standards and conformity.

View scope of expertise

OSTRAI advises on the application of the EU AI Act and related requirements across the AI system lifecycle, including regulatory roles and classification, governance, documentation, transparency, human oversight, risk-management structures, standards, conformity and continuing obligations.

A mandate may concern a discrete AI Act question, such as classification, applicability or a particular obligation. It may also require consideration of how the AI Act interacts with privacy, cybersecurity, product regulation or other applicable frameworks.

Explore Artificial Intelligence
04

Digital Regulation

DSA · DATA ACT · DIGITAL SERVICES

Regulation of digital services, platforms and the data economy.

KEY LEGISLATION

Digital Services Act · Data Act · Data Governance Act

Digital businesses operate within an expanding regulatory environment governing platforms, data, online services and technology-enabled business models.

View scope of expertise

OSTRAI advises on applicability and regulatory roles, platform and intermediary governance, transparency, regulatory representation, implementation and continuing obligations.

Our work includes the Digital Services Act, Data Act and their interaction with privacy, artificial intelligence, cybersecurity and the wider European digital regulatory landscape.

Where the relevant question concerns a single regime, our work can remain focused. Where several digital frameworks apply to the same service or business model, we analyse their combined effect.

Explore Digital Regulation
Limestone facade with precisely arranged bronze-green structural screens

STANDARDS, CONFORMITY AND MARKET ACCESS

Where regulation moves towards implementation.

Some regulatory questions extend beyond the substantive legal framework itself.

How these areas connect

Standards may influence how requirements are implemented or evidenced. Harmonised standards may, where the applicable regulatory framework provides for it, support a presumption of conformity. Conformity mechanisms may determine how compliance must be demonstrated. Market-access requirements may determine whether and how a product, technology or regulated service can enter or remain on a market.

OSTRAI therefore maintains dedicated expertise in Standards & Standardisation and Regulatory Market Access & Conformity.

These areas can form part of mandates across artificial intelligence, cybersecurity and product regulation, digital regulation and other regulated technologies.

05

Standards & Standardisation

Understanding the standards that shape regulatory implementation.

Standardisation intelligence

  • Standards landscape
  • Developing standards
  • Harmonisation & citation status
  • Regulation-to-standards analysis

Informs where relevant

Regulatory implications

  • Implementation
  • Evidence & documentation
  • Conformity relevance
  • Market-access implications
Explore the standards perspective

Standards, including European harmonised standards, increasingly form part of the infrastructure through which regulatory requirements are translated into technical and organisational practice.

OSTRAI advises organisations on the standards landscape relevant to their regulatory obligations, including the relationship between legislation, developing standards, conformity mechanisms, regulatory evidence and implementation.

Our work includes standardisation intelligence, standards landscape mapping, regulation-to-standards analysis, standards strategy and assessment of the regulatory implications of developing or evolving standards.

Standardisation intelligence

Standardisation can develop alongside legislation and continue evolving after regulatory requirements enter into force.

OSTRAI monitors relevant standardisation activity to help organisations understand:

  • which standards and developing standards are relevant to their regulatory obligations;
  • their stage of development and regulatory significance;
  • how standards may affect implementation;
  • where harmonised standards may support conformity or regulatory evidence;
  • where gaps remain between legislative requirements and available standards;
  • how changes in the standards landscape may affect products, systems, governance or access to market.

The objective is not simply to identify standards by reference number.

It is to understand what they mean within the regulatory framework and what organisations may need to prepare for.

Standards in regulatory context

We consider standards in relation to legal and regulatory requirements, conformity assessment, technical documentation and evidence, governance and management systems, market-access pathways and continuing compliance.

OSTRAI's work in this area is informed by direct participation in relevant European and international standardisation activities across cybersecurity, privacy, artificial intelligence and technology regulation, including work within CEN-CENELEC, ISO/IEC and ETSI.

Our perspective is informed by direct participation in European and international standardisation activities, including CEN-CENELEC, ISO/IEC and ETSI.

Explore Standards & Standardisation
06

Regulatory Market Access & Conformity

From regulatory requirements to access to market.

Key dimensions of the regulatory pathway. Their relevance and sequence depend on the applicable regulatory framework.

  • 01SCOPE & REGULATED ROLES

    Classification
    Applicable regulatory frameworks
    Economic-operator / regulated roles

  • 02REQUIREMENTS & STANDARDS

    Applicable regulatory requirements
    Harmonised standards and other relevant standards
    Technical and organisational requirements

  • 03EVIDENCE, CONFORMITY & CERTIFICATION

    Technical documentation and evidence
    Conformity assessment route
    Applicable certification schemes, where relevant
    Testing or certification where required
    Conformity assessment or certification bodies where applicable

  • 04MARKET ENTRY & CONTINUING COMPLIANCE

    Declarations, markings, registrations or representation where applicable
    Market-entry readiness
    Market surveillance
    Continuing obligations and corrective action

Explore the regulatory pathway

Regulatory market access and conformity can arise across several areas of OSTRAI's work, particularly where products, technologies or regulated services must satisfy defined requirements before entering or remaining on a market.

OSTRAI advises on the regulatory pathway from classification and applicable requirements through economic-operator roles, harmonised standards, conformity strategy, technical documentation and evidence, representation, market-entry readiness, market surveillance and continuing obligations.

The role is broader than determining whether a particular conformity procedure applies. We consider how legislation, standards, regulated roles, evidence and continuing obligations fit together within the overall route to market.

Where testing, certification or third-party conformity assessment is required, OSTRAI coordinates the relevant inputs, including engagement with appropriate notified or other conformity assessment bodies where required, while maintaining an integrated view of the applicable requirements, dependencies, evidence and regulatory objective.

Explore Regulatory Market Access & Conformity

REGULATION IN CONTEXT

Understanding the regulatory position as a whole.

The regulatory position is shaped by the applicable legislation and by its interaction with adjacent frameworks, standards, certification schemes, conformity mechanisms, regulatory guidance and market-access conditions.

Where relevant

  • Applicable legislation
  • Adjacent regulatory frameworks

Regulatory position

  • Standards
  • Certification schemes
  • Conformity mechanisms
  • Regulatory guidance
  • Market-access conditions

OSTRAI examines those relationships to identify the dependencies, tensions and practical consequences that shape the regulatory position and its implementation.

INTEGRATED REGULATORY DELIVERY

From regulatory complexity to a coherent pathway.

Complex regulatory matters can involve more than legislation alone.

The wider regulatory pathway

Legal and regulatory requirements may need to operate alongside technical considerations, standards, conformity mechanisms, evidence, documentation, operational processes and market-access conditions.

Where a matter requires that broader view, OSTRAI approaches it through two distinct but complementary functions: regulatory integration and regulatory coordination.

01 / CONVERGENCE

Regulatory integration

Legal & regulatoryTechnical & operationalStandards & conformityEvidence & market access

One coherent regulatory position

Regulatory integration is about bringing the different dimensions of a regulatory problem into one coherent picture.

How integration works

OSTRAI connects the applicable legal and regulatory requirements with relevant standards, technical and operational considerations, conformity mechanisms, evidence requirements and market-access conditions.

We identify how those elements interact, where dependencies arise and how decisions in one part of the regulatory pathway may affect another.

The result is an integrated view of what must be achieved, why it is required and how the different elements fit together.

02 / PROGRESSION

Regulatory coordination

CapabilitiesWorkstreamsDecision points

The regulatory pathway moves forward

Regulatory coordination is about moving that integrated pathway forward.

How coordination works

OSTRAI coordinates the capabilities, workstreams and decision points required to deliver the regulatory objective, maintaining visibility across their interfaces, sequencing and dependencies.

Where an organisation already has relevant capabilities and functions in place, we can work across those functions and coordinate their contribution to the regulatory pathway.

Where additional capabilities are required, we can help structure the appropriate delivery model and bring the necessary inputs into the process.

Throughout, OSTRAI maintains oversight of the regulatory pathway as a whole.

HOW WE WORK

Intelligence. Advisory. Representation.

These describe the principal ways in which OSTRAI supports organisations. Depending on the mandate, one or several may be relevant.

Direction & significance

Intelligence

We monitor and analyse regulatory, policy, standardisation and certification developments to understand their direction, significance and practical implications.

More about intelligence

The objective is not simply to identify what has changed, but to determine what is material, what may follow and what organisations should prepare for.

Regulatory intelligence may support a specific decision, an ongoing regulatory function or early preparation for requirements still developing.

Interpretation & response

Advisory

We interpret regulatory requirements and advise organisations on the decisions, structures and actions required to address them.

More about advisory

Our work may include applicability and classification, regulatory strategy, governance, implementation, documentation, standards and conformity pathways, remediation and continuing compliance.

Advisory may concern a discrete regulatory question or form part of a wider integrated regulatory mandate.

Role & responsibility

Representation

Where regulatory frameworks require or provide for formal representation, OSTRAI acts within the regimes and jurisdictions in which we offer that capability.

More about representation

Our representative role is supported by an understanding of the underlying regulatory framework and the organisation's continuing obligations, rather than treated as a purely administrative appointment.

An architectural outlook across a coastal city and its wider urban context

OUR PERSPECTIVE

European focus. International context.

European regulation is OSTRAI's principal centre of gravity.

We follow regulatory frameworks from policy and legislative development through interpretation, standards, implementation, conformity, operation and subsequent change.

At the same time, organisations, technologies, products and data flows frequently operate across jurisdictions.

The international perspective

Our work therefore also considers relevant international regimes, cross-border requirements and the interaction between European regulation and regulatory developments in other markets.

The objective is not simply to determine which rule applies.

It is to understand the regulatory environment in which an organisation must operate, how its relevant elements interact and the direction in which that environment is developing.

Continue the conversation

Complex regulation requires more than interpretation.

OSTRAI helps organisations understand what matters, anticipate what is changing and translate regulatory requirements into a clear path forward.

Discuss your regulatory challenge