Three EU laws now touch the secure access layer directly, each from a different angle: DORA governs financial-sector ICT third-party risk, NIS2 sets cybersecurity baselines across critical sectors, and the Cyber Resilience Act (CRA) regulates the security of the software itself. Together, they mean that “our VPN vendor is reputable” is no longer a sufficient answer in a vendor risk review.