Skip to content
Back to the guide

Compliance

NIS2 and DORA: who is affected and what to do

Two European frameworks that turn cybersecurity from a recommendation into an obligation with management liability.

4 min read

NIS2 is the EU directive on the security of network and information systems, which widened the circle of companies with security obligations. DORA is the regulation on digital operational resilience for the financial sector. Both apply in the EU and affect Ukrainian companies that provide services to European customers.

NIS2: who falls under it

  • Medium and large companies in energy, transport, healthcare, digital infrastructure, manufacturing, food, research and other sectors.
  • Suppliers of these companies through contractual requirements.
  • Management is personally responsible for approving the measures.

DORA: who falls under it

  • Banks, insurers, payment institutions, crypto providers, investment firms.
  • Their ICT service providers, including cloud and software vendors.

What both require

  • Risk management and documented policies.
  • Incident reporting within tight deadlines (NIS2: first notification within 24 hours).
  • Regular testing, under DORA including threat-led pentesting for large institutions.
  • Supplier and supply chain control.

Where to start

A gap analysis: where you are now relative to the requirements. Then a 6 to 12 month plan with priorities, policies that are actually followed, and a first pentest as evidence.

Articles