HomeFrameworksEuropean Union
Country guide · European Union

Cyber resilience compliance in the European Union

Two EU instruments now set the cybersecurity and operational resilience baseline for most regulated organisations in the Union: the NIS2 Directive, which binds essential and important entities across critical sectors through 27 national laws, and the Digital Operational Resilience Act, which binds the financial sector directly and has applied since 17 January 2025. Both make the management body answerable, both run an incident-reporting clock measured in hours, and both reach into the supply chain. This page sets out what applies, to whom and from when, from the instruments themselves.

At a glance
  • Frameworks listed3
  • Issuing bodies3
  • Framework pages3
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
European UnionChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in European Union

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

Which cyber resilience rules apply in the European Union?

NIS2 covers medium-sized and larger organisations in the high-criticality sectors of its Annex I (energy, transport, banking, financial market infrastructures, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space) and the other critical sectors of Annex II (postal and courier, waste management, chemicals, food, manufacturing, digital providers and research), plus some entities whatever their size. DORA covers twenty types of financial entity, from banks, payment and e-money institutions to insurers, investment firms, trading venues and crypto-asset service providers, and reaches their ICT third-party service providers through contracts and, for the critical ones, through EU-level oversight.

A group can sit under both: an energy company with a payments subsidiary, or a banking group with an ICT services arm. GRCLens runs NIS2 and DORA on one control model with ISO/IEC 27001 and the rest of the library, so a control evidenced once counts wherever it applies.

What does NIS2 require?

Article 20 requires the management body to approve the cybersecurity risk-management measures, oversee their implementation and answer for failures; its members must follow training. Article 21 sets ten measures on an all-hazards basis: risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition, development and maintenance including vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, HR security with access control and asset management, and multi-factor authentication with secured communications. For digital-infrastructure, ICT-service and digital-provider entities, Commission Implementing Regulation (EU) 2024/2690 sets the technical and methodological detail of each measure and the thresholds that make an incident significant; ENISA's technical implementation guidance of June 2025 adds examples of evidence and mappings to ISO/IEC 27001 and NIST CSF 2.0.

Article 23 runs the reporting clock for a significant incident: an early warning to the CSIRT or competent authority within 24 hours of becoming aware of it, an incident notification within 72 hours and a final report within one month of the notification. Essential entities are supervised ex ante and ex post, and Member States must allow maximum fines of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher; important entities are supervised ex post, with maximum fines of at least EUR 7 million or 1.4%.

How has NIS2 been transposed across the Member States?

NIS2 is a directive, so it binds through national law, and the Member States moved at different speeds. The Commission sent letters of formal notice on 28 November 2024 to every Member State except Belgium, Croatia, Italy and Lithuania, reasoned opinions to 19 Member States on 7 May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice. The Dutch Cyberbeveiligingswet entered into force on 15 August 2026; the Irish, Spanish and French laws were still pending in October 2026.

The national laws differ in the details an entity deals with day to day: the competent authority and CSIRT, how and by when to register, and the route an incident notification takes. Germany's NIS2 implementation act has applied since 6 December 2025 with the BSI as authority, Italy's Legislative Decree 138/2024 since 16 October 2024 with ACN, and Poland's amended national cybersecurity system act since 3 April 2026, with registration due by 3 October 2026. GRCLens carries all 27 transpositions as an overlay of 115 duties, each recording the law, its status and the date it was checked.

What does DORA require?

DORA rests on five pillars: ICT risk management (Articles 5 to 16), ICT-related incident management, classification and reporting (17 to 23), digital operational resilience testing (24 to 27), ICT third-party risk (28 to 44) and information sharing (45), with oversight of critical ICT third-party providers alongside. Level 2 acts supply the detail: RTS 2024/1774 on the ICT risk-management framework and the simplified framework of Article 16, RTS 2024/1772 on incident classification, RTS 2025/301 on report content and timing, RTS 2025/1190 on threat-led penetration testing (TLPT) and ITS 2024/2956 on the register of information.

A major ICT-related incident is notified within 4 hours of being classified as major and no later than 24 hours after the entity became aware of it, followed by an intermediate report within 72 hours of the initial notification and a final report within one month of the latest intermediate report. Systems supporting critical or important functions are tested at least yearly, and entities identified for TLPT run it at least every three years. Every ICT services contract must carry the baseline provisions of Article 30(2), with further provisions in Article 30(3) where a critical or important function is supported, and every arrangement is recorded in the register of information.

Penalties for financial entities are set by the Member States; DORA sets no EU-wide cap. Critical ICT third-party providers are overseen by a Lead Overseer (the EBA, EIOPA or ESMA), which can impose periodic penalty payments of up to 1% of average daily worldwide turnover. The ESAs designated the first 19 critical providers on 18 November 2025.

How GRCLens runs NIS2 and DORA together

Both are assessed per group or per legal entity: NIS2 as essential or important, with a Digital infrastructure profile where Implementing Regulation (EU) 2024/2690 applies; DORA by financial-entity type, with the full or simplified framework, TLPT identification and ICT-provider status as profiles. NIS2 carries 303 requirements in 14 domains, 160 of them critical; DORA 230 requirements in 11 domains, 97 of them critical. Entities roll up into a group view with a heat map across 15 risk areas, and each framework has four stakeholder dashboards: management body, CISO and risk, operations, and third party and procurement.

Eight EU cyber-resilience connectors (incident records, backup and restore, vulnerability and patch, identity and MFA, the ICT third-party register, resilience testing, training and log monitoring) validate the answers alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors, and flag any check that fails where the requirement was answered Implemented. Gaps flow into a multi-owner assurance register and a remediation and risk treatment plan, key risk indicators trace to the requirements they measure, Baseerah writes the executive summary on a self-hosted language model, and reports export as Word and PDF.

Questions

Cyber compliance in European Union: common questions

What are the incident reporting deadlines under NIS2 and DORA?

NIS2: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification. DORA: for a major ICT-related incident, an initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification and a final report within one month of the latest intermediate report.

Who supervises NIS2 compliance?

The competent authorities and CSIRTs named in each Member State's transposition law, for example the BSI in Germany, ACN in Italy and CNCS in Portugal. Essential entities are supervised ex ante and ex post; important entities ex post, when there is evidence or an indication of non-compliance. ENISA keeps the EU registry of digital-infrastructure, ICT-service and digital-provider entities and publishes technical guidance.

Who supervises DORA compliance?

Each financial entity's existing competent authority, the banking, payments, securities, insurance or pensions supervisor named in Article 46, with the ECB for significant credit institutions. Critical ICT third-party providers are overseen by a Lead Overseer, the EBA, EIOPA or ESMA; the ESAs designated the first 19 on 18 November 2025.

Is there an EU-wide fine for breaching NIS2 or DORA?

NIS2 sets a floor for the maximum: Member States must allow fines of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher, for essential entities, and EUR 7 million or 1.4% for important entities. DORA leaves penalties for financial entities to the Member States; its only EU-level figure is the periodic penalty payment of up to 1% of average daily worldwide turnover that a Lead Overseer can impose on a critical ICT third-party provider.

Has every Member State transposed NIS2?

Not as of October 2026. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026; the Dutch law entered into force on 15 August 2026, while the Irish, Spanish and French laws were still pending. DORA needs no transposition: it has applied directly in every Member State since 17 January 2025.

Run European Union's frameworks on one platform

See GRCLens with your own frameworks loaded. Need hands-on help? NIS2 and DORA readiness services from Security Solution Consultants.