EU Regulatory Compliance Experts · The Hague, Netherlands
DACTS
Digital Acts Trust & Compliance B.V.
Navigating the Digital Regulatory Frontier — so your business doesn't have to.

DACTS helps European organisations navigate the evolving landscape of cyber, privacy, and GRC regulation — from NIS2 to GDPR to the EU AI Act — with senior expertise and measurable outcomes.

EU Regulatory Coverage

NIS2 GDPR EU AI Act DORA NIST CSF 2.0 ISO 27001 CIS Controls ENISA
20+
Years senior
consulting experience
4
Professional certifications
(CISA · CRISC · CDPSE · ISO 27001)
Trusted across
Financial Services
Technology & Telecoms
Energy & Utilities
Retail & FMCG
E-commerce & Digital

End-to-end compliance services

From initial gap assessment through to Board-ready governance reporting, we deliver structured, practitioner-led programmes across three core disciplines.

Cybersecurity

Threat-led security programme design, maturity assessment, and control implementation aligned to leading frameworks. From NIS2 technical measures to NIST CSF 2.0 maturity modelling.

NIS2 Article 21 NIST CSF 2.0 ISO 27001 Maturity Assessment Control Design

Privacy & Data Protection

Operational GDPR compliance, privacy-by-design embedding, DPIA delivery, and cross-border data transfer structuring. Practical, audit-ready programmes.

GDPR DPIA Privacy by Design ROPA Data Transfers

Governance, Risk & Compliance

Enterprise GRC framework design, risk appetite setting, and Audit Committee–ready reporting. Independent assurance and third-party risk management programmes.

Risk Frameworks Board Reporting TPRM Audit Support Policy Design

AI Governance

EU AI Act readiness assessment, risk classification, and governance programme design. Helping organisations build compliant, trustworthy AI systems from the ground up.

EU AI Act Risk Classification AI Governance ALTAI Conformity Assessment

Digital Resilience

DORA compliance programmes for financial entities, ICT risk management, incident reporting structures, and operational resilience testing frameworks.

DORA ICT Risk Incident Reporting Resilience Testing TLPT

Compliance Assurance

Independent control testing, gap analysis reporting, and pre-audit readiness reviews. Structured deliverables aligned to regulatory inspection expectations.

Gap Analysis Control Testing Pre-audit Readiness Remediation Roadmaps

The EU regulatory frameworks we deliver

Enforcement deadlines are here. We help organisations understand their obligations, close gaps, and demonstrate compliance with confidence.

NIS2 Enforcement: Q2 2026

NIS2 Directive

Network and Information Security Directive 2

Expanded scope covering Essential and Important Entities across 18 sectors. Mandates Article 21 technical and organisational security measures, incident reporting within 24/72 hours, and supply chain risk management.

Article 21 Controls Incident Reporting Supply Chain Board Accountability
GDPR In force since 2018

GDPR

General Data Protection Regulation

The foundational EU privacy regulation. Ongoing compliance, evolving enforcement, and cross-border complexity require sustained operational programmes rather than one-time projects.

Data Subject Rights DPIA International Transfers Data Minimisation
EU AI Act Phased from 2025

EU AI Act

Regulation on Artificial Intelligence

A risk-based framework classifying AI systems from prohibited to minimal risk. High-risk systems face conformity assessments, transparency obligations, and human oversight requirements.

Risk Classification Conformity Assessment Transparency Fundamental Rights Impact
DORA Applicable from Jan 2025

DORA

Digital Operational Resilience Act

Uniform ICT risk management requirements for financial entities and their critical third-party providers. Five pillars: ICT risk, incident management, resilience testing, third-party risk, and information sharing.

ICT Risk Management TLPT TPRM Incident Classification

A structured approach to lasting compliance

01

Scoping & current state

We begin with a focused scoping exercise to establish regulatory applicability, define the programme perimeter, and understand your current maturity baseline — quickly, without wasted effort.

02

Gap analysis & risk assessment

Structured control interviews, documentation review, and technical assessment produce a prioritised gap register mapped directly to regulatory obligations and your organisation's risk appetite.

03

Maturity modelling

We translate gaps into a quantified maturity model — providing current-state and target-state scores, effort estimates, and a prioritised remediation roadmap with clear ownership.

04

Programme delivery

Hands-on delivery of remediation: policy development, control design, process embedding, and technology guidance. We work alongside your team, not around them.

05

Governance reporting

Board and Audit Committee–ready reporting, RAG dashboards, and evidence packs that demonstrate compliance posture to regulators, auditors, and senior stakeholders.

Professional certifications

CISA — Certified Information Systems Auditor
CRISC — Certified in Risk & Information Systems Control
CDPSE — Certified Data Privacy Solutions Engineer
ISO 27001 Lead Implementer

Industry experience

Financial Services Technology Telecommunications Energy Retail FMCG E-commerce Manufacturing

Senior expertise. Practical outcomes.

We are a specialist boutique — not a generalist firm. Every engagement is led by a certified senior consultant with deep regulatory knowledge and hands-on delivery experience.

20+

Years of experience

Over two decades of senior consulting delivery across European financial services, technology, energy, and retail sectors. Deep practitioner knowledge, not theoretical frameworks.

4

Active certifications

CISA, CRISC, CDPSE, and ISO 27001 Lead Implementer — maintained and current, ensuring regulatory advice is grounded in recognised professional standards.

EU

Netherlands-based, EU-focused

Based in The Hague with deep familiarity of the Dutch regulatory environment and the broader EU regulatory landscape. Local presence, European reach.

Regulator-ready deliverables

Every deliverable is structured to withstand regulatory inspection — gap registers, maturity models, evidence packs, and Board reports that auditors and supervisors expect to see.

Embedded, not advisory-only

We work inside your programme, not outside it. Control owner interviews, policy drafting, and cross-team coordination — hands-on delivery alongside your people.

Ongoing relationship

Compliance is not a point-in-time exercise. We structure engagements to build internal capability and support continuous improvement beyond the initial programme.

Meet the Founder

VG
Vikas Gupta
Founder & Managing Director
CISA
CRISC
CDPSE
ISO 27001 Lead Implementer
BE Electronics & Communication
20+
Years of consulting & delivery experience
13+
Years at Accenture serving global clients
4
Active professional certifications
13+ years at Accenture — Senior Manager, Cyber & Risk Practice

Vikas Gupta is a senior cybersecurity, risk, and compliance leader with over two decades of end-to-end consulting and programme delivery experience. Throughout his career he has worked embedded within some of Europe's and the world's most complex organisations — navigating regulatory change, building security governance frameworks, and translating technical risk into language that resonates at Board and ExCo level.

Vikas spent more than 13 years at Accenture, one of the world's leading professional services firms, where he advised Fortune 500 clients and large European enterprises on cybersecurity strategy, IT risk, data privacy, and compliance transformation. Working across Accenture's global delivery model, he led cross-functional, multi-geography teams — coordinating between technology, legal, compliance, and business stakeholders to deliver programmes that were both technically rigorous and operationally practical.

His consulting career spans financial services, telecommunications, energy, retail, and e-commerce sectors across Europe, Asia, and beyond. He has led assessments and implementations across the full GRC lifecycle — from initial risk appetite definition through control design, independent assurance, and regulatory reporting. He brings particular depth in NIS2, GDPR, NIST CSF 2.0, ISO 27001, and EU AI Act readiness programmes.

Vikas founded DACTS Trust & Compliance B.V. to bring enterprise-grade expertise to organisations of all sizes — combining the rigour and methodology of large-firm consulting with the agility, accountability, and senior attention that only a specialist boutique can deliver.

Senior consulting delivery at Accenture across Europe, Asia, and global client engagements
Led cross-functional, multi-geography teams in complex programme environments
Deep expertise in NIS2, GDPR, EU AI Act, DORA, NIST CSF 2.0, and ISO 27001
Served Board, ExCo, Audit Committee, and regulatory audiences across sectors
Sector coverage: financial services, telecoms, energy, retail, e-commerce, technology
Based in The Hague — deep familiarity with Dutch and EU regulatory environment

Our Advisory Board

DACTS draws on a network of senior practitioners and industry leaders who provide strategic guidance, domain expertise, and sector-specific insight to enhance our consulting programmes.

VG
Vikas Gupta
Founder & Managing Director
20+ years of senior cybersecurity, risk and compliance consulting. 13+ years at Accenture advising global clients. CISA, CRISC, CDPSE, ISO 27001 Lead Implementer. Based in The Hague.
CISA CRISC CDPSE ISO 27001 LI NIS2 NIST CSF
Advisor Name
Advisory Board Member
Add advisor profile here — name, background, area of expertise, and previous roles or affiliations.
Advisor Name
Advisory Board Member
Add advisor profile here — name, background, area of expertise, and previous roles or affiliations.
Advisor Name
Advisory Board Member
Add advisor profile here — name, background, area of expertise, and previous roles or affiliations.
Advisor Name
Advisory Board Member
Add advisor profile here — name, background, area of expertise, and previous roles or affiliations.
Advisor Name
Advisory Board Member
Add advisor profile here — name, background, area of expertise, and previous roles or affiliations.

Ready to strengthen your compliance posture?

Whether you have an imminent regulatory deadline or are building a long-term compliance programme, we'd welcome a conversation about how DACTS can help.

The Hague, Netherlands
info@dacts.nl
KvK: 42043063
DACTS Trust & Compliance B.V.