Why DORA Doesn’t Cover All Banking — and Where NIS2 Applies Instead
DORA doesn’t cover all banking. Sub-threshold AIFMs, MiFID II-exempt firms and post-office giro institutions remain under NIS2. Map the exact boundary for your entity.
DORA doesn’t cover all banking. Sub-threshold AIFMs, MiFID II-exempt firms and post-office giro institutions remain under NIS2. Map the exact boundary for your entity.
NIS2 classifies central and regional government entities as essential. Covers 10 Article 21 obligations, what’s excluded, and procurement requirements.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation. In February 2021, an…
42,000 Polish organisations now covered by NIS2. Identify your competent authority, CSIRT reporting contact, and meet the October 3, 2026 registration deadline.
Which NIS2 authority supervises your Spanish operations — INCIBE-CERT or CCN-CERT? ENS overlap, draft law status, €10M penalties, and action steps.
Your EU NIS2 programme likely has gaps for France: ANSSI’s ReCyF has 20 objectives and ISO 27001 covers only 2. Here’s what to fix before registration opens.
Germany’s NIS2 via BSIG 2.0: BSI registration, KRITIS scope, personal management liability, and ICT component prohibition. Step-by-step guide for multinationals.
Italy NIS2 is live. ACN notified entities in April 2025 — learn registration steps, CSIRT reporting rules, and the October 2026 compliance deadline.
Most networks don’t meet CIR Annex 6.7 and 6.8 — here’s the 4-zone segmentation model that satisfies NIS2 network security requirements.
CIR Annex 6 §6.6 and §6.10 impose separate patch management and vulnerability handling obligations. Includes CVSS-tiered patch SLA table, OT compensating controls framework, and CVD procedure requirements for NIS2 compliance.