NIS2 & DORA answers
Short, sourced answers to the questions organisations most often ask about NIS2 and DORA. Each answer starts with a direct summary, followed by the detail and links to the official texts.
- Does NIS2 apply to my company?
The NIS2 test in three steps: sector (Annex I/II), size (medium or large) and the size-independent exceptions. Free scope check included.
- What are the fines under NIS2?
NIS2 Article 34 fine caps for essential and important entities, what triggers them, and why national law can go higher.
- NIS2 vs DORA: which one applies to my organisation?
Financial entities follow DORA as lex specialis; the 18 NIS2 sectors follow NIS2. A side-by-side comparison of scope, dates, reporting and fines.
- What is the NIS2 incident reporting deadline (24h, 72h, 1 month)?
NIS2 Article 23: early warning in 24 hours, incident notification in 72 hours, final report within one month. What each stage must contain.
- Who is liable under NIS2? (management liability)
NIS2 Article 20 makes management bodies approve and oversee cybersecurity measures, take training, and answer for infringements.
- Do I need NIS2 compliance if I'm a supplier to an essential entity?
Suppliers are not automatically in NIS2 scope, but Article 21(2)(d) supply-chain security means customers will pass requirements down to you.
- When did NIS2 apply, and has my country transposed it?
NIS2 transposition deadline was 17 October 2024; measures apply from 18 October 2024. Status notes for all 27 EU member states.
- How much does NIS2 compliance cost for an SME?
What drives NIS2 compliance cost for SMEs, typical cost components, consultant ranges and transparent self-serve software pricing.
- What policies and measures does NIS2 Article 21 require?
The ten minimum cybersecurity risk-management measures of NIS2 Article 21(2), from risk policies to MFA — with a free checklist.
- What is the DORA register of information for ICT third-party providers?
DORA Article 28(3) requires financial entities to keep a register of all ICT third-party contractual arrangements. What it covers and who receives it.
Official sources
- NIS2 Directive (EU) 2022/2555 — EUR-Lex
- DORA Regulation (EU) 2022/2554 — EUR-Lex
- ENISA — EU Agency for Cybersecurity
Last reviewed: 2026-07-03