{"id":73439,"date":"2026-05-12T14:58:05","date_gmt":"2026-05-12T12:58:05","guid":{"rendered":"https:\/\/www.schneider.im\/?p=73439"},"modified":"2026-05-12T14:58:05","modified_gmt":"2026-05-12T12:58:05","slug":"broadcom-vmware-vcf-meet-nis2-dora-and-data-sovereignty-requirements","status":"publish","type":"post","link":"https:\/\/www.schneider.im\/lu\/broadcom-vmware-vcf-meet-nis2-dora-and-data-sovereignty-requirements\/","title":{"rendered":"Broadcom VMware VCF: Meet NIS2, DORA, and Data Sovereignty Requirements"},"content":{"rendered":"<p>European regulators have\u00a0<strong>raised the bar<\/strong>\u00a0on cybersecurity and operational resilience. Organizations across the EU are now expected to\u00a0<strong>prove<\/strong>\u00a0that their IT environments are\u00a0<strong>secure, recoverable, and under their own legal control<\/strong>.\u00a0Complying with regulations such as the Digital Operational Resilience Act (DORA) has become an increasingly painstaking process. There are unclear definitions and demanding adherence requirements. Software that helps organizations meet these obligations has never been more critical.<\/p>\n<p><strong>VMware Cloud Foundation (VCF) <\/strong>is the software that powers a company\u2019s\u00a0<strong>private datacenter<\/strong>. It provides the technical foundations that\u00a0<strong>IT professionals,<\/strong> <strong>compliance officers, auditors, and boards<\/strong>\u00a0need to\u00a0demonstrate\u00a0adherence to the\u00a0<strong>NIS2 Directive<\/strong>, <strong>DORA<\/strong> and\u00a0<strong>EU data sovereignty<\/strong>\u00a0expectations.<\/p>\n<p>This article explains, how\u00a0<strong>VCF <\/strong>helps EU organizations meet these obligations\u00a0<strong>without sacrificing modern capabilities<\/strong> such as AI, automation, and cloud-style operations.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-73440\" src=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-LinkedIn-VCF-regulatory.jpg\" alt=\"\" width=\"1080\" height=\"710\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-LinkedIn-VCF-regulatory.jpg 1080w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-LinkedIn-VCF-regulatory-500x329.jpg 500w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-LinkedIn-VCF-regulatory-800x526.jpg 800w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-LinkedIn-VCF-regulatory-150x99.jpg 150w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-LinkedIn-VCF-regulatory-768x505.jpg 768w\" sizes=\"(max-width: 1080px) 100vw, 1080px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Why EU regulatory compliance matters now<\/h2>\n<p>The regulatory landscape in Europe has\u00a0<strong>changed faster in the last two years<\/strong>\u00a0than in the\u00a0previous\u00a0decade. Several rules now apply\u00a0<strong>in parallel<\/strong>\u00a0and reinforce each other:<\/p>\n<ul>\n<li><strong>NIS2 Directive.<\/strong>\u00a0The\u00a0<strong>EU cybersecurity\u00a0law<\/strong>\u00a0that\u00a0requires\u00a0<strong>critical and important organizations<\/strong>\u00a0to prove strong security, manage supply-chain risk, and\u00a0<strong>report serious incidents within 24 hours<\/strong>. Boards are now\u00a0<strong>personally accountable<\/strong>\u00a0for cybersecurity oversight.<\/li>\n<\/ul>\n<ul>\n<li><strong>DORA (Digital Operational Resilience Act).<\/strong>\u00a0In force across the EU since\u00a0<strong>January 17, 2025<\/strong>, DORA requires\u00a0<strong>financial entities<\/strong>\u00a0(banks, insurers, investment firms, and many of their IT suppliers) to prove they can\u00a0<strong>withstand, respond to, and recover from Information and Communications Technology (ICT) incidents<\/strong>, including major cyberattacks.<\/li>\n<\/ul>\n<ul>\n<li><strong>EU Data Act and sovereignty expectations.<\/strong>\u00a0Customers, regulators, and partners increasingly require that\u00a0<strong>sensitive data\u00a0stays\u00a0under EU legal\u00a0control<\/strong>\u00a0and that organizations are\u00a0<strong>not locked into a single non-EU provider<\/strong>.<\/li>\n<\/ul>\n<ul>\n<li><strong>Audit pressure is constant.<\/strong>\u00a0Internal auditors, external auditors, and supervisory authorities now expect\u00a0<strong>documented evidence<\/strong>. This should cover <strong>access, encryption, segmentation, recovery testing, and incident response<\/strong>.<\/li>\n<\/ul>\n<ul>\n<li><strong>High Penalties.<\/strong>\u00a0NIS2 and DORA both carry\u00a0<strong>significant administrative fines<\/strong>, and NIS2 allows action against\u00a0<strong>individual senior managers<\/strong>\u00a0for non-compliance.<\/li>\n<\/ul>\n<p>Under these conditions, the way an organization\u00a0<strong>designs and runs its private datacenter<\/strong>\u00a0becomes a\u00a0<strong>central compliance question<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>How VCF supports EU regulatory requirements<\/h2>\n<h3>1) Sovereign control over data and encryption keys<\/h3>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-73460\" src=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-data.webp\" alt=\"\" width=\"1024\" height=\"559\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-data.webp 1024w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-data-500x273.webp 500w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-data-800x437.webp 800w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-data-150x82.webp 150w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-data-768x419.webp 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p><strong>VCF 9.1<\/strong>\u00a0runs in\u00a0<strong>your own datacenter<\/strong>, under your own legal entity, on hardware you control. This is the\u00a0<strong>strongest possible posture<\/strong>\u00a0for\u00a0<strong>data sovereignty<\/strong>\u00a0as it keeps data under the legal control of a specific country or region.<\/p>\n<p>VCF 9.1 includes\u00a0<strong>native encryption<\/strong>\u00a0for stored data, virtual machines, and backups. The\u00a0<strong>encryption keys<\/strong>\u00a0are managed by a\u00a0<strong>KMS (Key Management Server)<\/strong>\u00a0which is the system that\u00a0<strong>stores and controls the keys<\/strong>\u00a0used to lock and unlock data.<\/p>\n<p><strong>How it helps you with regulators:<\/strong><\/p>\n<ul>\n<li><strong>Keys stay in Europe:<\/strong>\u00a0Encryption keys can be held in a\u00a0<strong>KMS on EU soil<\/strong>, so no non-EU operator can technically read your data.<\/li>\n<\/ul>\n<ul>\n<li><strong>Clear data location:<\/strong>\u00a0Customer records, financial data, and other sensitive content\u00a0<strong>never leave the perimeter you control<\/strong>.<\/li>\n<\/ul>\n<ul>\n<li><strong>No hidden lock-in:<\/strong>\u00a0Workloads can be moved between datacenters or to a\u00a0<strong>sovereign cloud partner<\/strong>\u00a0without rebuilding applications.<\/li>\n<\/ul>\n<p><strong>This brings you\u00a0demonstrable sovereignty<\/strong>\u00a0for\u00a0<strong>NIS2, DORA, and EU Data Act<\/strong>\u00a0conversations.<\/p>\n<p>&nbsp;<\/p>\n<h3>2) Network security and micro-segmentation (NIS2)<\/h3>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-73456\" src=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-NIS2.webp\" alt=\"\" width=\"780\" height=\"410\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-NIS2.webp 780w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-NIS2-500x263.webp 500w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-NIS2-150x79.webp 150w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-VCF-NIS2-768x404.webp 768w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/><\/p>\n<p><strong>NIS2<\/strong>\u00a0expects organizations to\u00a0<strong>limit how far an attacker can move<\/strong>\u00a0once inside the network. VCF 9.1 ships with the tools to do exactly that.<\/p>\n<p><strong>NSX<\/strong>\u00a0is VMware&#8217;s <strong>built-in network and\u00a0firewall<\/strong>\u00a0inside the\u00a0datacenter.\u00a0It controls\u00a0<strong>which virtual computers are allowed to talk to each other<\/strong>.\u00a0<strong>vDefend<\/strong>\u00a0adds a\u00a0<strong>threat-protection layer<\/strong>\u00a0on top of NSX that\u00a0<strong>watches for suspicious behavior<\/strong>\u00a0between virtual computers and blocks it automatically.<\/p>\n<p><strong>Why it matters for regulators:<\/strong><\/p>\n<ul>\n<li><strong>Micro-segmentation by default:<\/strong>\u00a0<strong>Micro-segmentation<\/strong>\u00a0means splitting the internal network into\u00a0<strong>small zones<\/strong>, so an attacker who lands in one zone\u00a0<strong>cannot move freely<\/strong>\u00a0across the rest of the environment.<\/li>\n<\/ul>\n<ul>\n<li><strong>Visibility into east-west traffic:<\/strong>\u00a0<strong>East-west traffic<\/strong>\u00a0is the traffic that flows\u00a0<strong>between servers inside the\u00a0datacenter<\/strong>. This is where most attackers hide. VCF 9.1 makes it\u00a0<strong>visible and\u00a0policed<\/strong>.<\/li>\n<\/ul>\n<ul>\n<li><strong>Network Detection and Response (NDR):<\/strong>\u00a0With VCF, you get a security capability that\u00a0<strong>watches network traffic for attack patterns<\/strong>\u00a0and flags them in near real time. That is exactly the kind of evidence NIS2 supervisors look for.<\/li>\n<\/ul>\n<p>The result is a<strong> defensible security architecture<\/strong>\u00a0that maps directly to\u00a0<strong>NIS2 risk-management requirements<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h3>3) Operational resilience and ransomware recovery (DORA)<\/h3>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-73448\" src=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-DORA.png\" alt=\"\" width=\"901\" height=\"364\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-DORA.png 901w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-DORA-500x202.png 500w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-DORA-800x323.png 800w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-DORA-150x61.png 150w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-DORA-768x310.png 768w\" sizes=\"(max-width: 901px) 100vw, 901px\" \/><\/p>\n<p><strong>DORA<\/strong>\u00a0states clearly that <strong>you must be able to recover<\/strong>. Recovery\u00a0has to\u00a0be\u00a0<strong>planned, documented, and tested<\/strong>.<\/p>\n<p>VCF 9.1 includes\u00a0<strong>VMware Live Recovery<\/strong>, a\u00a0<strong>built-in disaster\u00a0recovery\u00a0and ransomware recovery capability<\/strong>. It supports a\u00a0<strong>stretched cluster<\/strong>\u00a0(one logical datacenter spread across\u00a0<strong>two physical sites<\/strong>) so workloads keep running even if\u00a0a whole site\u00a0goes down.<\/p>\n<p><strong>How it helps you with regulators:<\/strong><\/p>\n<ul>\n<li><strong>Defined RTO and RPO:<\/strong>\u00a0<strong>RTO (Recovery Time Objective)<\/strong>\u00a0is how\u00a0<strong>fast<\/strong>\u00a0a service must be\u00a0backed\u00a0up.\u00a0<strong>RPO (Recovery Point Objective)<\/strong>\u00a0is how much\u00a0<strong>data loss<\/strong>\u00a0is acceptable. VCF 9.1 makes both\u00a0<strong>measurable and provable.<\/strong><\/li>\n<\/ul>\n<ul>\n<li><strong>Tested recovery workflows:<\/strong>\u00a0Recovery plans can be\u00a0<strong>rehearsed regularly<\/strong>\u00a0with isolated test runs that do not disrupt production. <strong>DORA explicitly demands <\/strong>those recovery plans.<\/li>\n<\/ul>\n<ul>\n<li><strong>Ransomware-aware restore: <\/strong>Backups can be\u00a0<strong>scanned and\u00a0validated<\/strong>\u00a0before restoring, so encrypted or infected data is not brought back into production.<\/li>\n<\/ul>\n<ul>\n<li><strong>Two-site continuity:<\/strong>\u00a0A stretched cluster gives\u00a0<strong>continuous availability<\/strong>\u00a0even during a full site outage.<\/li>\n<\/ul>\n<p><strong>Especially for DORA<\/strong>, these capabilities give you<strong> operational resilience<\/strong>\u00a0without you having to use a third-party recovery stack.<\/p>\n<p>&nbsp;<\/p>\n<h3>4) Auditability, logging, and evidence<\/h3>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-73444\" src=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-logging.png\" alt=\"\" width=\"1378\" height=\"732\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-logging.png 1378w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-logging-500x266.png 500w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-logging-800x425.png 800w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-logging-150x80.png 150w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-logging-768x408.png 768w\" sizes=\"(max-width: 1378px) 100vw, 1378px\" \/><\/p>\n<p>Both\u00a0<strong>NIS2 and DORA<\/strong>\u00a0require organizations to produce\u00a0<strong>evidence<\/strong>\u00a0on demand: who did what, when, on which system, and what was the security state at the time of an incident.<\/p>\n<p>VCF 9.1 includes\u00a0<strong>Aria Operations<\/strong>\u00a0and\u00a0<strong>Aria Operations for Logs<\/strong>. They are the\u00a0<strong>monitoring dashboard<\/strong>\u00a0and the\u00a0<strong>central log archive<\/strong>\u00a0for the platform.\u00a0Together they show\u00a0<strong>how healthy each system is<\/strong>\u00a0and\u00a0<strong>what happened on it<\/strong>.<\/p>\n<p><strong>How this helps you with complying with EU regulations:<\/strong><\/p>\n<ul>\n<li><strong>Centralized, tamper-resistant logs:<\/strong>\u00a0Security, configuration, and access\u00a0logs\u00a0land in a\u00a0<strong>single archive<\/strong>\u00a0that can be\u00a0retained\u00a0for the legally required period.<\/li>\n<\/ul>\n<ul>\n<li><strong>Incident timelines on demand:<\/strong>\u00a0When supervisors ask\u00a0<strong>what happened during a breach<\/strong>, the answer is\u00a0<strong>reconstructable\u00a0from\u00a0real evidence<\/strong>.<\/li>\n<\/ul>\n<ul>\n<li><strong>Compliance reporting:<\/strong>\u00a0Built-in dashboards map directly to\u00a0<strong>common control frameworks<\/strong>. This reduces the manual effort to prepare an audit.<\/li>\n<\/ul>\n<p>This results in<strong> faster audits, cleaner reports, and less last-minute spreadsheet work<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h3>5) Identity, access, and least-privilege governance<\/h3>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-73452\" src=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-access-control.png\" alt=\"\" width=\"1072\" height=\"430\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-access-control.png 1072w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-access-control-500x201.png 500w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-access-control-800x321.png 800w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-access-control-150x60.png 150w, https:\/\/www.schneider.im\/media\/2026\/05\/SCHNEIDER-IT-MANAGEMENT-2026-05-12-Update-Vmware-access-control-768x308.png 768w\" sizes=\"(max-width: 1072px) 100vw, 1072px\" \/><\/p>\n<p>Regulators consistently focus on one question:\u00a0<strong>who can do what, and how do you prove it?<\/strong>\u00a0VCF 9.1 supports a\u00a0<strong>least-privilege model<\/strong>\u00a0across the platform.<\/p>\n<p><strong>How the least-privilege model helps you with regulations:<\/strong><\/p>\n<ul>\n<li><strong>Role-Based Access Control (RBAC):<\/strong>\u00a0Defines\u00a0<strong>who is allowed to do what<\/strong>\u00a0on the platform, so administrators only get the rights they actually need.<\/li>\n<\/ul>\n<ul>\n<li><strong>Strong authentication:<\/strong>\u00a0VCF integrates with\u00a0<strong>enterprise identity providers<\/strong>\u00a0and supports\u00a0<strong>multi-factor authentication (MFA)<\/strong>\u00a0on management access. This is a baseline expectation under NIS2.<\/li>\n<\/ul>\n<ul>\n<li><strong>Separation of duties:<\/strong>\u00a0Security, operations, and audit roles can be\u00a0<strong>cleanly separated<\/strong>, which is essential for\u00a0<strong>DORA-regulated entities<\/strong>.<\/li>\n<\/ul>\n<ul>\n<li><strong>Privileged access logging:<\/strong>\u00a0Every administrative action is\u00a0<strong>logged and attributable<\/strong>\u00a0to an individual, instead of a shared account.<\/li>\n<\/ul>\n<p>With the least-privilege model you benefit from<strong> fewer security gaps, defensible access governance<\/strong>, and have much <strong>smoother audit conversations<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>SCHNEIDER IT MANAGEMENT\u2019s role for regulated organizations<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-71876 size-full\" src=\"https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577.webp\" alt=\"\" width=\"2908\" height=\"1939\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577.webp 2908w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577-500x333.webp 500w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577-800x533.webp 800w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577-150x100.webp 150w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577-768x512.webp 768w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577-1536x1024.webp 1536w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF8577-2048x1366.webp 2048w\" sizes=\"(max-width: 2908px) 100vw, 2908px\" \/><\/p>\n<p><strong>Broadcom VMware offboarded more than 90 percent (%) of former partners<\/strong> and shifted to a small, highly specialized partner model.<\/p>\n<p><strong>SCHNEIDER IT MANAGEMENT is one of only three (3) registered Broadcom partners in Luxembourg<\/strong>\u00a0following the\u00a0<strong>April 2,\u00a02026\u00a0partner consolidation<\/strong>, and we serve\u00a0<strong>regulated customers across Europe<\/strong>, including\u00a0<strong>financial services, public sector, and critical infrastructure<\/strong>.\u00a0We ensure that your Broadcom\u00a0<strong>VMware contracts deliver maximum regulatory coverage at minimum cost<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Summary<\/h2>\n<p>EU regulation has moved from\u00a0<strong>principle to enforcement<\/strong>.\u00a0<strong>NIS2, DORA, and EU data sovereignty<\/strong>\u00a0now shape how organizations design and\u00a0operate\u00a0their core IT.<\/p>\n<p><strong>VMware Cloud Foundation (VCF) 9.1<\/strong>\u00a0supports these requirements through:<\/p>\n<ul>\n<li><strong>Sovereign control<\/strong>\u00a0over data and encryption keys.<\/li>\n<\/ul>\n<ul>\n<li><strong>Micro-segmentation and east-west security<\/strong>\u00a0aligned to NIS2 expectations.<\/li>\n<\/ul>\n<ul>\n<li><strong>Tested operational resilience<\/strong>\u00a0and ransomware recovery for DORA.<\/li>\n<\/ul>\n<ul>\n<li><strong>Centralized logging and audit evidence<\/strong>\u00a0across the platform.<\/li>\n<\/ul>\n<ul>\n<li><strong>Least-privilege identity and access<\/strong>\u00a0governance.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Ready to make your VCF 9.1 estate regulatory-defensible?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-71768\" src=\"https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712.webp\" alt=\"\" width=\"3120\" height=\"2080\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712.webp 3120w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712-500x333.webp 500w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712-800x533.webp 800w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712-150x100.webp 150w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712-768x512.webp 768w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712-1536x1024.webp 1536w, https:\/\/www.schneider.im\/media\/2026\/03\/Office-People-DSCF7712-2048x1365.webp 2048w\" sizes=\"(max-width: 3120px) 100vw, 3120px\" \/><\/p>\n<p>As\u00a0leading\u00a0<strong>Broadcom partner<\/strong>, SCHNEIDER IT MANAGEMENT supports medium and large organizations in\u00a0<strong>licensing VMware environments<\/strong>\u00a0with a clear focus on\u00a0<strong>regulatory defensibility, security, and long-term value<\/strong>.\u00a0<a href=\"https:\/\/www.schneider.im\/contact\/\"><strong>Contact our Broadcom expert team today.<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>European regulators have\u00a0raised the bar\u00a0on cybersecurity and operational resilience. Organizations across the EU are now expected to\u00a0prove\u00a0that their IT environments are\u00a0secure, recoverable, and under their own legal control.\u00a0Complying with regulations such as the Digital Operational Resilience Act (DORA) has become an increasingly painstaking process. There are unclear definitions and demanding adherence requirements. Software that helps [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":47363,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[683],"tags":[],"class_list":["post-73439","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-broadcom"],"_links":{"self":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts\/73439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/comments?post=73439"}],"version-history":[{"count":1,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts\/73439\/revisions"}],"predecessor-version":[{"id":73464,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts\/73439\/revisions\/73464"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/media\/47363"}],"wp:attachment":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/media?parent=73439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/categories?post=73439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/tags?post=73439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}