What is NIS2 and DORA?
NIS2 and DORA are two EU regulations that raise cybersecurity and digital resilience requirements. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations for essential and important entities across 18 critical sectors. DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) applies specifically to the financial sector and has been in force since 17 January 2025.
The two frameworks overlap but differ in scope and legal form:
- NIS2 is a directive, so each member state transposes it into national law (in Czechia, the new Cybersecurity Act). It covers sectors such as energy, transport, health, digital infrastructure, public administration and manufacturing.
- DORA is a regulation, so it applies directly and uniformly across the EU. It covers banks, insurers, investment firms, payment institutions and their critical ICT service providers.
Both require ICT risk management, incident reporting, supply chain and third-party risk control, and accountability at management level. For financial entities, DORA acts as the sector-specific rulebook that takes precedence over NIS2 where the two overlap.
For organisations in scope, the tools they use to run projects and store operational data become part of the compliance picture. Self-hosted or EU-hosted platforms such as Easy8 make it easier to keep control over data, access and audit trails.
