Skip to main content
GMI-TECHNOLOGIES: A GMI-INVESTMENTS Company
Back to news

NIS2 and DORA: how to tell if your company is covered (and by what)

NIS2 and DORA are often mentioned in the same breath, which wrongly suggests they cover the same ground. They're two distinct texts, with different applicability criteria, that can apply separately, together, or not at all depending on your sector and size. Here's how to work it out quickly, without waiting for a full compliance audit to find out.

NIS2: a scope widened by sector and by size

The NIS2 directive distinguishes two categories of entities, essential and important, based on sector of activity and headcount/revenue thresholds. It covers a broad sectoral scope: energy, transport, health, drinking water, digital infrastructure — but also, and this is what catches most organizations off guard, medical device manufacturing, food production, or certain B2B digital service providers. The right question isn't "am I a traditional critical operator?" but "does my sector appear in the text's annex, and do I clear the size thresholds?" The main obligations that follow: structured cyber risk management, incident notification within tight deadlines, and governance accountability made explicit — this is no longer just the CISO's problem.

DORA: a narrower scope, but one that extends beyond the financial sector itself

The Digital Operational Resilience Act (DORA) targets the financial sector, but not only financial institutions themselves: it also applies to their critical ICT third-party providers. This is the point most often missed — a technology SME supplying a digital service to banks or insurers can fall within DORA's scope without ever having had to think about it before, simply because one of its clients designates it a critical provider. DORA structures its obligations around five pillars: ICT risk management, incident management and reporting, digital operational resilience testing, third-party risk management, and information sharing across the sector.

The common case: both texts apply at once

An organization in the financial sector that clears the NIS2 thresholds through its activity and size, and that is itself subject to DORA because of its sector, has to work with two sets of obligations that partially overlap without being identical. Treating them separately, with two independent compliance plans, doubles the work and multiplies inconsistencies. The right approach is to map the shared requirements once (risk management, incident notification) and only handle separately what's genuinely specific to each text.

How to prioritize once the scope is clear

Faced with two ambitious texts, the most common mistake is trying to address everything at once on a tight timeline. Three steps allow you to prioritize without spreading too thin: map the major gaps first, often already known intuitively by technical teams; address the obligations with the nearest regulatory deadline first; then build a realistic multi-year plan for the rest. A documented, shared roadmap — even incomplete at the immediate deadline — beats a promise of full compliance that isn't achievable in the time given.

Our NIS2 & DORA: getting compliant seminar helps SMEs/mid-caps and financial sector players clarify their scope of applicability and prioritize their roadmap. AuditForge also covers prioritized treatment plan tracking for progressive compliance — get in touch for an initial assessment.