NIS-2 and DORA: What They Mean for Enterprise Networks

NIS-2 and DORA are reshaping cybersecurity and operational resilience requirements across Europe. From risk management and incident reporting to access control, business continuity, and third-party risk, both frameworks are prompting organizations to take a closer look at how their IT environments are secured and managed.

At a Glance: NIS-2 and DORA

  • Definition: NIS-2 is an EU Directive that strengthens cybersecurity requirements across critical sectors, while DORA is an EU Regulation focused specifically on digital operational resilience in the financial sector.
  • Scope: NIS-2 covers 18 sectors, ranging from energy, transport, and healthcare to digital infrastructure, manufacturing, and public administration. DORA, by contrast, focuses specifically on the financial sector and applies to a broad range of financial entities, including banks, payment institutions, investment firms, insurers, and other regulated financial organizations.
  • Deadlines: As an EU Directive, NIS-2 is implemented through national legislation in each member state. DORA has applied directly across the EU since January 17, 2025.
  • Core obligations: Both frameworks strengthen requirements around cybersecurity risk management, incident reporting, business continuity, and operational resilience.
  • In Germany: The BSI is the competent authority for key aspects of NIS-2 implementation, while BaFin oversees DORA requirements for much of the financial sector. The BSI also provides tools to help organizations assess whether they fall within the scope of NIS-2.
  • Assessment Tools: The BSI provides an interactive self-assessment and decision tree to help organizations quickly confirm their regulatory status. 

With the rollout of NIS-2 and DORA (the Digital Operational Resilience Act), he European Union has significantly strengthened cybersecurity and operational resilience requirements for organizations across critical sectors. The impact extends beyond regulatory compliance: organizations need to assess how they manage cyber risk, protect critical systems, respond to incidents, maintain business continuity, and manage risks introduced by third parties. For IT and security teams, this means taking a closer look at existing processes and infrastructure — from network architecture and access controls to monitoring, incident response, and secure remote access.

Practical Tip: Check Your Status Early

Start by using the BSI’s NIS-2 Applicability Assessment to see if your business falls into one of the 18 covered sectors.

Understanding the Legal Framework:  Direct Rules vs. National Laws

Because NIS-2 is an EU Directive, member states translate it into domestic law individually. In Germany, for example, the implementation act took effect on December 6, 2025. However, adoption on the ground remains an ongoing process, and many businesses have lagged behind official registration deadlines. Many companies have not yet registered, even though the deadline has already passed.

DORA works differently: As an EU Regulation — much like the GDPR — it took effect automatically across all member states on January 17, 2025, without requiring separate national legislation. For the financial industry, compliance became mandatory overnight.

Network Security: Stop Intruders with Segmentation and Detailed Logs

Relying on a single perimeter fence around an open network is no longer viable. Both frameworks expect organizations to adopt micro-segmentation. By separating office workstations, operational technology (OT), and core databases, IT teams can contain an intrusion immediately. Even if a user account is compromised, the attacker cannot pivot freely across the entire enterprise.

At the same time, teams must ensure complete visibility into system activity. IT departments must record every relevant security event — whether it originates inside the office or comes through remote VPN tunnels. 

Incident Response: Clear Roles and Executive Accountability

When a breach happens, teams cannot afford confusion. Both regulations mandate written, battle-tested response plans detailing who triages alerts, who investigates the root cause, and how to quarantine affected systems in real time.

The design of your network and remote access tools directly influences how fast your team can react. In addition, organizations must maintain proven backup and recovery procedures to restore operations quickly.

Crucially, cybersecurity is now a boardroom responsibility. Senior leaders and executive boards must personally review and approve risk policies. Under NIS-2, leadership can face personal liability for material oversights.  If an incident does occur, thorough operational records are your best proof of due diligence.

Supply-Chain Risk: Securing External Dependencies

Internal controls alone are not enough. Third-party contractors, software vendors, and cloud providers can introduce dangerous blind spots, as recent high-profile supply chain incidents have shown.

Organizations must vet their suppliers carefully: What security baselines do vendors maintain? How quickly do they notify partners when an issue occurs? If a critical vendor suffers an outage, how will it disrupt your core business?

Conclusion: Turning Regulatory Requirements into Real-World Resilience

Adapting to NIS-2 and DORA starts with an honest look at your current posture: How severely would a sudden network outage affect your customers? What is the true business cost of a data breach? Where are your current blind spots in identity and access? 

Effective compliance is rarely achieved through isolated tools.  Instead, it relies on the smooth coordination of network segmentation, thorough logging, rapid incident handling, and third-party oversight. Centralized, secure VPN platforms provide a reliable foundation to help teams meet these requirements efficiently while keeping daily operations running smoothly.

 

Frequently Asked Questions

What penalties apply for noncompliance with NIS-2 or DORA?
Under the German implementation of NIS-2, fines for essential entities can reach up to €10 million or 2% of global annual turnover, whichever is higher. For important entities, penalties reach up to €7 million or 1.4%.  Under DORA, individual national regulators have the authority to impose administrative penalties and operational sanctions.

Are small and medium-sized businesses exempt from NIS-2?
NIS-2 generally exempts micro and small businesses that employ fewer than 50 people and report annual revenue under €10 million However, exceptions apply regardless of size to specialized providers that play critical digital roles, such as DNS providers, trust service partners, and public telecommunications networks.

How does an ISO 27001 certification relate to these frameworks?
While neither regulation explicitly requires ISO-27001 certification, maintaining a certified Information Security Management System (ISMS) satisfies many core requirements around documentation and risk assessment. However, organizations must still ensure they address framework-specific mandates, such as strict incident notification windows and specialized network controls.

Do financial institutions have to comply with both NIS-2 and DORA?
No. DORA serves as a specialized rule (lex specialis) for the financial sector and takes precedence over general NIS-2 provisions. Regulated financial entities follow DORA as their primary cybersecurity framework

Can an existing VPN help achieve compliance?
Yes. A centrally managed VPN that provides encrypted connections, granular role-based access, and detailed session logging directly fulfills several operational requirements. To achieve full compliance, it should be paired with broader measures like network segmentation, automated alerting, and documented incident-handling policies.