Compliance requirements for SaaS platforms and cloud services.
Sector Profile
| Attribute | Value |
|---|
| AI Act impact | HIGH |
| NIS2 category | Essential (Annex I — Digital Infrastructure) |
| GDPR impact | HIGH |
| Typical size | 10-500 employees |
| Typical revenue | EUR 1M - EUR 100M |
AI Act for SaaS
Typical AI Systems
| System | Classification | Obligations |
|---|
| Recommendation engine | Low/Medium | Transparency |
| Fraud detection | Medium | DPIA, monitoring |
| Customer support chatbot | Medium | Label as AI |
| Content moderation | Medium | Transparency |
| Predictive analytics | Low | Minimal |
GPAI Usage (Claude, GPT-4)
NIS2 for SaaS
Scope Determination
| Service type | NIS2 Annex | Category | Obligations |
|---|
| Cloud computing | Annex I | Essential | HIGHER obligations |
| DNS provider | Annex I | Essential | HIGHER obligations |
| Online marketplace | Annex II | Important | LOWER obligations |
| Search engine | Annex II | Important | LOWER obligations |
| SaaS (other) | — | Depends on criticality | Depends on service criticality |
ISMS Requirements
| Control | Requirement | Priority |
|---|
| Encryption at rest | AES-256 for all data | Critical |
| Encryption in transit | TLS 1.3 for all APIs | Critical |
| MFA | For all admin accounts | Critical |
| Access logging | SIEM, 1-year retention | Critical |
| Backup | Daily, tested monthly | Critical |
| Patch management | <30 days for critical | High |
| Penetration testing | 1-2x annually | High |
| ISO 27001 | Recommended | High |
Incident Response SLA
| Severity | Response Time | Notification |
|---|
| Critical | 1h | National CSIRT 24h |
| High | 4h | National CSIRT 72h |
| Medium | 24h | Internal |
| Low | 72h | Internal |
GDPR for SaaS
Roles
Key Obligations
| Area | Obligation | Status |
|---|
| ROPA | Documentation of all processing activities | Required |
| DPA | Agreements with cloud providers | Required |
| DSAR | Workflow for data subject rights | Required |
| Breach | 72h notification | Required |
| Privacy Policy | Clear, complete | Required |
| Cookie consent | GDPR-compliant banner | Required |
Multi-tenancy Specifics
Checklist for SaaS
Weeks 1-2 (Audit & Scope)
Months 1-3 (Planning)
Months 3-6 (Implementation)
Months 6-12 (Certification)
Typical Costs
| Item | Estimate |
|---|
| ISMS setup (CISO consultant) | EUR 20-40k |
| ISO 27001 certification | EUR 30-50k |
| Legal review (DPA, policies) | EUR 10-20k |
| Penetration testing | EUR 5-15k/year |
| Compliance tooling | EUR 5-15k/year |
| Total Y1 | EUR 70-140k |
Resources