| Regulation | Deadline | Scope |
|---|---|---|
| NIS2 | Registration + incident reporting: immediate. Duty-of-care: ~mid 2028 | Higher education institutions |
| EU AI Act | Aug 2, 2026 (possible delay to Dec 2, 2027) | Education AI (Annex III, Cat. 3) |
| Data Act | Sep 12, 2025 (in effect) | Data sharing, portability, interoperability |
Understanding how to cover the critical gaps. Not all capabilities need to run on SDP — SDA team has experience with additional platforms.
| Question | Gap(s) | With |
|---|---|---|
| How to enable PII-compliant storage? | GAP-01 | CEDA + SDP / SDA team |
| Encryption-at-rest options for storage backends? | GAP-02, GAP-10 | CEDA + SDP / SDA team |
| Is Kafka needed, or do batch-only patterns suffice? | GAP-02 | CEDA + SDA team |
| Which platform(s) for data lineage, catalog, orchestration? | GAP-04, 07, 08 | CEDA + SDA team |
| What is the operational load of each capability? | All | CEDA + SDA team |
Parallel to PoC — experimenting with implementations to assess operational load.
SDP provides: Solid infrastructure — K8s, GitLab, Harbor, MinIO, PostgreSQL, Kong, Grafana/Loki, SURFconext, SURFsecureID. ISO 27001. Covers NIS2 Art. 21(d)(e)(j) well.
SDP does not provide: 14 gaps identified across NIS2, EU AI Act, and Data Act. Five are CRITICAL — they block compliant operation entirely.
Most significant: GAP-01 — PII storage currently prohibited on SDP production. Must be resolved before PoC can proceed with real student data.
11 open-source capabilities needed. Not all need to run on SDP — SDA team has experience with additional platforms. Compliance tooling wraps around existing analytical functions — core Bronze/Silver/Gold pipeline logic unchanged. Functions remain locally executable without the full compliance stack.
2026 focus: Research how to cover critical gaps + experiment with implementations to assess operational load.