NIS2 and DORA: What Enterprises Actually Have to Do
Both regimes push accountability onto management bodies and demand evidence, not policy documents.
Both NIS2 and DORA share a design philosophy that separates them from earlier regimes: accountability sits with the management body, and compliance is demonstrated with evidence rather than documentation. A policy stating that backups are tested is not compliance; test records are.
Which applies to you
NIS2 covers essential and important entities across sectors including energy, transport, health, water, digital infrastructure, public administration, manufacturing of critical products, and digital providers — a substantially wider scope than its predecessor, catching many organisations for the first time. DORA applies to financial entities and, importantly, to critical ICT third-party providers serving them.
Many groups fall under both, in which case build one control set and map it to each regime rather than running parallel programmes.
The common obligations
| Obligation | What evidence looks like |
|---|---|
| Governance and management accountability | Board approval records, training completion, documented oversight |
| Risk management framework | Risk register with owners, treatment decisions, review cadence |
| Incident detection and handling | Detection coverage, incident log, timeline evidence |
| Business continuity and crisis management | Recovery objectives, tested restore results, exercise reports |
| Supply chain and ICT third-party risk | Register of providers, contractual terms, concentration analysis |
| Resilience testing | Test plans, results, remediation tracking |
| Cryptography and access control | Policy plus configuration evidence and access review records |
Incident reporting is the operational shock
The 24-hour early warning changes how an incident is run. Within one day, while facts are still uncertain, someone must decide whether the incident is significant and file the initial notification.
Prepare for that specifically: define significance criteria in advance against the regulatory thresholds, name the person authorised to determine it and their deputy, pre-draft notification templates, register with the relevant authority's portal before you need it, and rehearse the 24-hour decision in your next tabletop exercise. Most reporting failures are decision-latency failures, not technical ones.
Third-party oversight is where DORA bites hardest
DORA requires a register of ICT third-party arrangements with defined contractual content — service descriptions, data locations, access and audit rights, exit strategies, and provisions for supporting your resilience obligations. Contracts signed years ago will frequently not meet this, so triage by criticality and renegotiate the critical ones first.
Concentration risk must be assessed explicitly. Document what happens if a critical provider becomes unavailable for an extended period, and ensure the answer is more substantial than a statement of intent to migrate.
Testing must be evidenced, and for some, advanced
Both regimes expect regular resilience testing with tracked remediation. DORA additionally introduces threat-led penetration testing for significant financial entities, which requires scoping against real threat intelligence and covering live production systems — a materially different exercise from a scoped application test.
How to run the programme
Do a single control mapping exercise: list requirements from each applicable regime, map to existing controls, identify gaps, assign owners and dates. Then invest in evidence automation — coverage reports, access reviews, and test results generated on a schedule rather than assembled manually before an audit. Organisations that automate evidence spend a fraction of the effort at assessment time and, more usefully, know their actual control state continuously.
Frequently asked questions
How do NIS2 and DORA differ?
NIS2 is a broad cross-sector cybersecurity directive; DORA is a financial-services regulation focused on digital operational resilience with detailed ICT third-party and testing requirements.
What are the reporting timelines?
Under NIS2: early warning within 24 hours, notification within 72 hours, final report within one month. DORA sets comparable staged reporting for major ICT incidents.
Are directors personally accountable?
Management bodies must approve and oversee risk measures and undertake training, and authorities can hold them personally responsible, including prohibition from managerial functions in serious cases.
Where should we start?
Scope applicability, map requirements against existing controls, then fix incident reporting readiness and third-party contract gaps — those carry the shortest timelines.