Discover the latest trends and essential tips in IT for everyone

The IT landscape of 2026 is being reshaped by the combined effects of new European regulations and a technical acceleration that affects both large corporations and SMEs. Two main axes will structure future choices: regulatory compliance, which has become an operational prerequisite, and the controlled integration of artificial intelligence into business processes.

Cyber Resilience Act: what the CE cyber marking changes for digital products

The regulation (EU) 2024/2847, known as the Cyber Resilience Act, imposes a binding timeline. Starting from September 11, 2026, any manufacturer of a product containing digital elements sold in the EU must report any actively exploited vulnerability or serious incident within 24 hours. The fine can reach 15 million euros or 2.5% of global revenue.

The next deadline, set for December 11, 2027, concerns market entry: home routers, connected cameras, and SaaS software will all need to meet cybersecurity requirements and carry a “cyber” CE marking. We recommend finding information on Digitale Naïve in IT now to gauge the extent of sector obligations.

Among the expected deliverables, the production of a SBOM (Software Bill of Materials) detailing all software dependencies, including open source, represents a significant undertaking for publishers who have never documented their component chain. DevSecOps teams must integrate this mapping into their CI/CD pipeline well before the deadline.

Man in open space office consulting IT advice on a tablet surrounded by notes and a laptop

AI Act and generative models: obligations already in force for companies

The timeline of the European AI Act is often misunderstood. Prohibited practices (cognitive manipulation, social scoring) have been effective since February 2, 2025. Obligations regarding basic generative AI models (GPAI, like GPT or Mistral) have been in effect since August 2, 2025.

High-risk obligations, however, are postponed to August 2, 2028. This delay creates a gray area: an SME deploying a customer service chatbot uses a GPAI model that is already regulated but may not be subject to “high-risk” constraints for another two years. We observe that this asymmetry leads some organizations to postpone any compliance efforts, effectively betting on an uncertain political timeline.

  • Document the source of the training data used by the integrated GPAI model, even via a third-party API
  • Establish a register of AI use cases within the organization, distinguishing risk levels
  • Plan for an internal compliance audit before the end of 2027 for systems likely to shift to “high-risk” category

The main difficulty remains the identification of AI components embedded in SaaS tools that the company uses without mastering the architecture. A CRM enhanced by generative AI may, depending on its use, fall under different obligations.

NIS 2 and DORA: cybersecurity becomes a business obligation for SMEs

NIS 2 significantly expands the scope of entities concerned compared to the previous directive. Sectors such as waste management, medical device manufacturing, or postal services are now included. For an industrial SME that has never had a CISO, the obligation to report incidents and manage supply chain risks represents a paradigm shift.

DORA, on the other hand, targets the financial sector with an approach to digital operational resilience. IT service providers supplying services to banks or insurers find themselves subject to strengthened contractual requirements.

The cascading effect is the point to watch. A cloud-hosted accounting software provider serving a regional mutual must prove its DORA compliance to its client. The IT subcontracting chain becomes a vector of direct legal responsibility.

Two young professionals collaborating on IT trends in a modern and relaxed coworking space

Digital maturity of French SMEs: real barriers and underestimated levers

The digitalization of SMEs remains very uneven. The most documented barriers are not technical but organizational: resistance to change from field teams, lack of a sponsor on the executive committee, and IT budgets perceived as a cost center rather than a management lever.

Companies that successfully transition share a common trait: they start with a specific use case, measurable in less than three months. Automating the processing of supplier invoices, for example, produces visible results quickly and creates a ripple effect on teams.

  • Appoint an internal digital referent, even part-time, to centralize field feedback
  • Favor SaaS tools with adoption support rather than long-to-deploy custom solutions
  • Integrate ongoing training in new digital practices into the skills development plan
  • Measure the effectiveness of each deployed tool based on a concrete business indicator (processing time, error rate, customer satisfaction)

Outsourcing IT management is gaining ground in organizations with fewer than 250 employees. Using a managed service provider allows for coverage of maintenance, supervision, and regulatory compliance without hiring a full IT team.

Energy transition and Green IT: a criterion for hardware and software selection

Reducing the energy footprint of the IT park is no longer a marketing argument. Responsible purchasing policies now incorporate the lifespan of materials, reparability, and the electrical consumption of equipment in operation.

On the software side, application eco-design reduces server resource consumption and extends the lifespan of client hardware. An optimized web application consumes less bandwidth, puts less strain on the processor, and runs on older machines, delaying the need for renewal.

The choice of a cloud host displaying documented PUE (Power Usage Effectiveness) and verifiable energy mix becomes a selection criterion on par with latency or price per gigabyte. Public tenders increasingly incorporate these requirements into their specifications.

The coming months will concentrate a rare density of regulations in IT. Cyber Resilience Act, AI Act, NIS 2, DORA: each text imposes concrete deliverables, precise deadlines, and heavy financial penalties. For SMEs as well as large accounts, regulatory compliance now conditions access to the market, not just risk management.

Discover the latest trends and essential tips in IT for everyone