Skip to content
Security Notes

NIS2 and DORA in practice for EU companies

By Elias Lankinen11 min read

The morning the four-hour clock started

At 17:00 on a Tuesday, a payments processor serving several mid-sized European banks notices that transactions are timing out. By 17:20 the on-call engineer confirms it is not a fluke: a misconfigured update has taken down a core authorisation service. Under the rules that took effect across the European Union on 17 January 2025, the firm now has a very specific problem. It must decide whether this counts as a "major" incident, and if it does, it has four hours from that classification to file an initial notification with its regulator, and no more than 24 hours from the moment it first became aware of the disruption. The technical fix and the regulatory clock run in parallel, and both are being timed. That four-hour rule comes from the Digital Operational Resilience Act, or DORA, the EU regulation that now governs how banks, insurers, investment firms and roughly 22,000 other financial entities withstand and recover from technology failures. It is one half of a pair. The other, the NIS2 Directive, rewrites cybersecurity obligations for something like 160,000 organisations across energy, transport, health, water, digital infrastructure and more. Together they represent the most ambitious attempt any bloc has made to legislate cyber resilience into an entire economy. In practice, they have arrived at very different speeds, and the gap between what the texts say and what is actually happening on the ground is where the interesting story lives.

Source: Euro Pictures / Sarra Benyaich, via Wikimedia Commons
Source: Euro Pictures / Sarra Benyaich, via Wikimedia Commons

Two laws, one goal, opposite trajectories

Start with the most basic difference, because it explains almost everything else. DORA is a regulation. NIS2 is a directive. In EU law that distinction is not bureaucratic trivia. A regulation applies directly and identically in every member state the day it takes effect, no national law required. A directive sets an objective and a deadline, then leaves each of the 27 countries to write its own statute achieving that objective, transposing it into national law. The result is a study in contrasts. DORA entered into force on 16 January 2023, gave the sector a two-year runway, and applied uniformly from 17 January 2025 with no waiting on national parliaments. A bank in Dublin and a bank in Lisbon face the same text. NIS2 had a transposition deadline of 17 October 2024, and that deadline was, to put it plainly, missed by most of Europe. Only Belgium, Croatia, Italy and Lithuania had national laws in place on time. As of mid-2026, according to the ECSO transposition tracker and legal-firm monitoring, 23 of 27 member states had adopted transposing legislation, with the Netherlands among the last to get its Cyberbeveiligingswet into force in August 2026, nearly two years late. A handful, including Ireland, Spain and France, were still legislating. The European Commission has not been patient about this. It opened infringement proceedings against 23 member states in November 2024, escalated to formal "reasoned opinions" against 19 of them in May 2025, and by July 2026 had referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union. The practical consequence for a company is awkward. If you operate in several countries, your NIS2 obligations may already be law in one and still a draft bill in the next.

What the laws actually make you do

Both laws share a philosophy that marks a real departure from the previous decade of cybersecurity policy: resilience, not just prevention. The old assumption was that you build walls and try to keep attackers out. The new assumption is that disruption is inevitable, whether from a ransomware crew or a botched software update, and what regulators care about is whether you can keep functioning through it and recover fast. DORA organises this around five pillars. The first, ICT risk management, requires a documented framework owned by the board, not delegated to a corner of the IT department. The second, incident management, standardises how firms classify, log and report technology incidents. The third, digital operational resilience testing, mandates regular testing of systems. The fourth, ICT third-party risk management, governs the outsourcing relationships that now underpin almost every financial service. The fifth, information sharing, encourages firms to pool threat intelligence. The testing pillar deserves a closer look, because it is genuinely demanding. Beyond routine vulnerability scans, the largest and most systemically important firms must undergo threat-led penetration testing, known as TLPT: a controlled attack simulation modelled on the real tactics of real adversaries, built on the European Central Bank's earlier TIBER-EU framework. A red team of ethical hackers attempts to breach live production systems while a small "white team" inside the firm coordinates in secret, so that the defenders, the blue team, do not know they are being tested. This is expensive and slow. A full TLPT cycle runs from roughly 200,000 to over a million euros and takes six to twelve months. Around 8,447 EU financial entities are expected to be in scope, with first tests due by 17 January 2028. NIS2 covers a much broader universe of organisations with a lighter but still substantial set of duties: risk-management measures spanning supply-chain security, encryption, access control and business continuity, plus incident reporting and, crucially, direct accountability for senior management. The reasoning behind both is the same. If your systems support something a society depends on, whether that is a hospital, a power grid or a settlement system, the state now has a legitimate interest in how well you have prepared for the day they fail.

Source: Norbert Nagel, via Wikimedia Commons
Source: Norbert Nagel, via Wikimedia Commons

Who is caught, and the trap of being caught twice

Here is the most common misconception worth dismantling early: that DORA and NIS2 are alternatives, and a company falls under one or the other. Many organisations fall under both, and untangling which rule governs which activity is a real compliance exercise, not an academic one. NIS2 sorts organisations into two tiers. Essential entities are the large operators in eleven high-criticality sectors listed in Annex I, energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space. Important entities are medium and large firms in seven further sectors in Annex II, including postal services, waste management, chemicals, food, manufacturing and digital providers. The size thresholds matter: broadly, 250-plus employees or over 50 million euros in turnover pushes you toward "essential," while 50-plus employees or over 10 million euros makes you at least "important." Some organisations, such as DNS providers, top-level-domain registries and public telecoms, are in scope regardless of size, because knocking them out has outsized consequences. ENISA, the EU cybersecurity agency, estimates the net now captures around 160,000 entities, up from perhaps 10,000 to 15,000 under the original 2016 NIS Directive. Now the overlap. A bank is simultaneously a "credit institution" under DORA and, as part of the banking sector, an "essential entity" under NIS2. Which set of ICT rules does it follow? DORA answers this itself. Article 4 makes DORA lex specialis, the specialist law that prevails over the general one, in Latin, lex specialis derogat legi generali. Where the two overlap on ICT risk management and ICT incident reporting, DORA's more specific requirements displace NIS2's. But, and this is the trap, the carve-out is narrow. It covers ICT risk and ICT incident reporting, not everything. A financial firm is not simply exempt from NIS2. On matters DORA does not address, NIS2 may still bite, and the same firm may deal with financial supervisors on DORA questions and a separate national cybersecurity authority on residual NIS2 ones. Reading "DORA replaces NIS2 for banks" as blanket exemption is exactly the error that leaves a gap in a compliance programme.

The clocks are not the same clock

Both regimes require fast incident reporting, and both use a staged model, but the details differ enough to matter when the alarm actually sounds. Under NIS2's Article 23, a significant incident triggers a three-step sequence: an early warning within 24 hours, flagging whether the incident looks malicious or could spread across borders; a fuller notification within 72 hours with an initial assessment and mitigations taken; and a final report within one month covering root cause and remediation. Only "significant" incidents, those causing severe operational disruption or considerable damage, trigger the duty at all. DORA is tighter at the front. For a major ICT-related incident, the initial notification is due "as early as possible" within four hours of classifying the incident as major, and in any case no later than 24 hours from first becoming aware of it. Then comes an intermediate report within 72 hours, and a final report within one month of that. The subtlety that catches firms out is that the four-hour clock runs from the internal decision that an incident is major, while the 24-hour outer limit runs from detection. A firm that drags its feet on classification to buy time is not protected: the 24-hour ceiling still applies. In effect, DORA forces the triage decision to happen fast and be documented, because the timestamp on that decision is itself now a compliance artefact.

DORA's most radical move: putting Big Tech under direct supervision

For decades, the relationship between a bank and its cloud provider was a private contract. If a European lender ran its systems on Amazon Web Services, that was the bank's outsourcing decision and the bank's risk to manage. The regulator supervised the bank, not the cloud. DORA breaks that. It recognises that when thousands of financial firms all depend on the same handful of infrastructure providers, the provider itself becomes a point of systemic fragility, a concentration risk that no single bank can manage away by writing a better contract. So DORA created an oversight framework for critical ICT third-party providers, or CTPPs, and on 18 November 2025 the three European Supervisory Authorities, the EBA, EIOPA and ESMA, published the first list: 19 companies. The names on it are the ones you would expect: Amazon Web Services, Microsoft, Google Cloud, Oracle, SAP and Deutsche Telekom among them, alongside IT-services and financial-data firms. The designation was not arbitrary. The ESAs built it from the "Registers of Information" that every financial entity now has to maintain, cataloguing exactly which providers support which functions, then ran a criticality assessment with national authorities. The consequences for a designated provider are unlike anything cloud giants have faced from financial regulators before. Each CTPP must appoint a legal entity, ideally an EU subsidiary with real resources, as a coordination point with its lead overseer. The ESAs can assess its risk management, examine its incident-reporting and subcontracting practices, and issue recommendations. And the provider must pay annual oversight fees to fund the supervision of itself. A trillion-dollar American technology company is now, for part of its European business, a supervised entity of EU financial authorities. The list will be refreshed annually, so the perimeter will move.

Teeth: liability that reaches the boardroom

Cybersecurity rules have historically been easy to nod along to and quietly underfund. NIS2 was written to make that harder, and it did so by aiming past the company at the people who run it. The financial penalties are calibrated to hurt. Essential entities face fines up to 10 million euros or 2% of global annual turnover, whichever is higher. Important entities face up to 7 million euros or 1.4%. Those percentages are deliberately GDPR-scale: large enough that a board cannot treat the fine as a cost of doing business. The sharper instrument is personal. Under Article 20, management bodies must approve and oversee the cybersecurity risk-management measures, and they can be held personally liable for failures. National transpositions can go as far as temporarily banning individuals from holding management roles in an entity that has breached its obligations. Combined with duties for senior managers to undergo cybersecurity training, the design is explicit: this is a governance obligation that lands on named executives, not a technical box for the IT team to tick. Enforcement is no longer hypothetical. Germany's cybersecurity agency, the BSI, issued formal notices to 47 entities in late 2025, an early signal that authorities in the countries that transposed on time intend to use their powers rather than let the regime settle in as paperwork.

What to watch

The uncomfortable truth as of late 2026 is that Europe has legislated a common standard and produced an uneven reality. DORA, being a regulation, is genuinely uniform, and its novelty, direct oversight of the cloud oligopoly, is only now being tested as the ESAs begin actual engagement with those 19 providers. Whether a regulator built to supervise banks can meaningfully hold Microsoft to account, and what happens the first time it tries, is the open question that will define the framework's credibility. NIS2, being a directive, is fragmenting even as it spreads. The Court of Justice referrals hanging over Ireland, Spain and France mean the map will keep changing into 2027, and companies operating across those borders are managing not one law but a moving patchwork of national versions of it. A useful thing to track is the first cross-border enforcement case, the moment a firm gets sanctioned in one country for a failure that touches another, because that is when the theory of a "single" European cyber-resilience regime meets the fact of 27 different statutes. The deeper shift, though, is the one worth sitting with. Both laws encode an assumption that the previous generation of rules resisted: that a serious incident is not an if but a when, and that the measure of a well-run organisation is no longer whether it was breached but how fast it noticed, how honestly it reported, and how quickly it came back. That is a harder thing to audit than a firewall. It is also, finally, the right question.


Sources

  1. Official Journal of the European Union, Regulation (EU) 2022/2554 (Digital Operational Resilience Act), 2022.
  2. Official Journal of the European Union, Directive (EU) 2022/2555 (NIS2 Directive), 2022.
  3. European Banking Authority / ESAs, European Supervisory Authorities designate critical ICT third-party providers under DORA, 2025.
  4. EIOPA, European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act, 2025.
  5. Morgan Lewis, DORA: EU Regulators Announce List of Critical ICT Third-Party Providers, 2025.
  6. Wavestone, NIS2 Directive: transposition status and what companies must do, 2025-2026.
  7. ECSO, NIS2 Directive Transposition Tracker, 2026.
  8. Bird & Bird, European Cybersecurity Regulatory Update: NIS2 and Beyond, 2025.
  9. Mayer Brown, Cybersecurity in the Financial Sector: EU's Digital Operational Resilience Act Takes Effect, 2025.
  10. activeMind.legal, NIS2 vs. DORA: differences and common misconceptions, 2025.
  11. ISMS.online, NIS2 Reporting Timeline: the 24-72-30 hour deadlines, 2025.
  12. financialregulations.eu, DORA Incident Reporting: 4h, 72h and 1-Month Deadlines, 2026.
  13. Kyte Global, Penetration Testing and TLPT Guide: DORA Compliance for Financial Institutions, 2025.
  14. Kiteworks, How to Determine If Your Organization Falls Under NIS2 Compliance Requirements, 2025.
  15. Orizon, NIS2 Penalties: Fines Up to 10 Million EUR Explained, 2025.
  16. Glocert International, NIS2 Penalties, Enforcement and Supervision: What Happens in Practice, 2025.