惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
S
SegmentFault 最新的问题
V
Visual Studio Blog
J
Java Code Geeks
宝玉的分享
宝玉的分享
美团技术团队
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
有赞技术团队
有赞技术团队
量子位
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
博客园 - 叶小钗
月光博客
月光博客
P
Proofpoint News Feed
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
博客园_首页
腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
NIS2 vs DORA: Which EU Regulation Applies to Your SaaS Pr...
Narendrasahoo · 2026-06-23 · via DEV Community

If you build SaaS products and serve European customers, two major EU regulations are demanding your attention right now NIS2 and DORA. But which one actually applies to you? And what happens if both do?

This guide cuts through the legal jargon and gives developers and technical teams a clear, practical breakdown of what each regulation requires, who it covers, and exactly what you need to do next.

What Is NIS2 — And Why Should SaaS Teams Care?

The Network and Information Security Directive 2 (NIS2) officially Directive EU 2022/2555 replaced the original NIS1 Directive in October 2024. It is the EU's broadest cybersecurity law to date, covering 18 critical sectors including energy, healthcare, transport, digital infrastructure, and critically for tech companies cloud computing services and managed service providers.

NIS2 defines two tiers of covered organizations:

  • Essential Entities — Organizations in high-criticality sectors like energy, banking, healthcare, and digital infrastructure.
  • Important Entities — Organizations in sectors like food production, waste management, and ICT service management.

Size threshold: Companies with more than 50 employees OR revenue exceeding €10 million in these sectors are directly in scope. Smaller companies may be indirectly affected if they serve essential or important entities.

What NIS2 Requires From You

If NIS2 applies to your SaaS product, here is what you must implement:

  • Risk management measures — regular risk assessments, vulnerability management, and documented security policies
  • Supply chain security — auditing vendors and third-party SaaS tools used within your organization
  • Incident reporting — a three-stage process: early warning within 24 hours, full notification within 72 hours, and a final report within 30 days
  • Executive accountability — senior management must approve cybersecurity measures and can face personal liability for failures
  • Business continuity planning — documented disaster recovery and crisis management procedures
  • Asset inventory — a complete map of all information systems, including shadow IT and SaaS applications

Penalties for non-compliance: Up to €10 million or 2% of global annual turnover for essential entities, and €7 million or 1.4% of turnover for important entities whichever is higher.

What Is DORA And How Is It Different?

The Digital Operational Resilience Act (DORA) Regulation EU 2022/2554 has been fully applicable since January 17, 2025. Unlike NIS2, DORA is a regulation, not a directive. This means it applies directly and uniformly across every EU member state with zero national variation.

DORA is laser-focused on the financial sector and its ICT supply chain. It covers roughly 22,000 financial entities, including:

  • Banks and credit institutions
  • Insurance companies and reinsurers
  • Investment firms and asset managers
  • Payment institutions and e-money institutions
  • Crypto-asset service providers (CASPs)
  • Trading venues and central counterparties

Crucially for SaaS teams: If your product serves any of these financial entities, DORA reaches you indirectly through contractual requirements your customers will push down to you.

What DORA Requires

DORA's requirements are stricter and more prescriptive than NIS2:

  • ICT Risk Management Framework — a formal, board-approved framework covering identification, protection, detection, response, and recovery
  • Incident Reporting — major ICT incidents must be reported within 4 hours of classification, followed by updates at 24 and 72 hours
  • Digital Operational Resilience Testing — including mandatory Threat-Led Penetration Testing (TLPT) for significant entities
  • Third-Party Risk Management — a formal Register of Information (ROI) documenting all critical ICT vendors, with contractual security clauses
  • ICT Concentration Risk — managing over-dependence on a single cloud or ICT provider
  • Information Sharing — participating in threat intelligence sharing with other financial entities

Penalties: Up to 2% of global annual turnover, with potential daily penalties for continued non-compliance.

In 2026, DORA enforcement has fully shifted from guidance to active supervision. National regulators including BaFin (Germany), AFM/DNB (Netherlands), and ACPR/AMF (France) are actively conducting supervisory reviews and audits.

NIS2 vs DORA: Side-by-Side Comparison

Feature NIS2 DORA
Type Directive (national transposition) Regulation (directly applicable EU-wide)
In force October 2024 January 2025
Sectors covered 18 sectors (broad) Financial sector only
Who it targets Essential & important entities Financial entities + critical ICT suppliers
Incident reporting 24h early warning / 72h full report 4h initial / 24h / 72h
Penetration testing General testing requirement Mandatory TLPT for significant entities
Third-party risk Supply chain risk management Formal Register of Information (ROI)
Fines Up to €10M or 2% turnover Up to 2% turnover + daily penalties
Executive liability Yes Yes

The Critical Rule: When Both Apply, DORA Wins

Here is the legal rule that every compliance team must know:

Article 4 of NIS2 explicitly states that DORA takes precedence (in legal terms: DORA is lex specialis) wherever the two regulations address the same matter for financial entities. This means:

  • If you are a financial entity (bank, insurer, payment institution, etc.) DORA applies, full stop. NIS2 defers to DORA for overlapping requirements.
  • If you are a SaaS company serving financial entities you are subject to NIS2 directly, and DORA contractually through your customers.
  • Full DORA compliance will satisfy most equivalent NIS2 obligations, but NIS2 may add narrow additional requirements around national CSIRT coordination and certain physical security elements.

Which Regulation Applies to Your SaaS Product? A Decision Framework

Ask yourself these three questions in order:

Question 1: Are you a financial entity as defined by DORA? Banks, insurers, payment institutions, investment firms, crypto-asset service providers if you are any of these, DORA applies directly. NIS2 defers to DORA for overlapping areas.

Question 2: Do you serve financial entities as an ICT provider? If yes, you are not directly in DORA scope, but your customers will contractually impose DORA requirements on you. You may also fall under NIS2 as an ICT service provider depending on your size and sector.

Question 3: Do you operate in any of NIS2's 18 sectors, or provide cloud/digital services? If yes, NIS2 applies to you directly. This catches most SaaS companies serving healthcare, energy, public administration, and digital infrastructure clients.

The uncomfortable reality for many mid-sized SaaS companies: You may end up implementing NIS2 controls for your overall operation and DORA-aligned controls specifically for your financial sector customers. Deliberate planning is essential.

Practical Steps for SaaS Teams Starting Compliance Today

Whether NIS2, DORA, or both apply to you, here is where to focus first:

1. Build your asset inventory. Both regulations assume you know exactly what systems you run, who owns them, and how critical they are. Without this, everything else is theoretical.

2. Set up incident classification and reporting workflows. DORA's 4-hour initial reporting deadline is aggressive. Build pre-approved notification templates, define escalation paths, and run tabletop exercises before an incident occurs not during one.

3. Map your third-party dependencies. Know your critical vendors, have contracts with security clauses on file, and document your exit strategy if a vendor fails. For DORA, maintain the Register of Information in the format specified by the European Supervisory Authorities (ESAs).

4. Get leadership formally involved. Both NIS2 and DORA attach personal accountability to senior management. Security must become a board-level conversation not just an engineering team concern.

5. Use ISO 27001 as your compliance foundation. ISO 27001 is the single best starting point for both DORA and NIS2. Achieving ISO 27001 certification significantly reduces incremental effort for both regulations and demonstrates verifiable controls to regulators and customers alike.

How VISTA InfoSec Can Help

Navigating overlapping EU regulations is complex especially when your SaaS product serves customers across multiple sectors and geographies. At VISTA InfoSec, our compliance experts specialize in helping SaaS companies, fintechs, and digital service providers map their NIS2 and DORA obligations, build gap assessment frameworks, and achieve certification-ready postures efficiently.

With 20+ years of experience across PCI DSS, ISO 27001, SOC 2, GDPR, and EU digital resilience frameworks, we bring the cross-regulation expertise your team needs without the overhead of building it in-house.

Book a free compliance consultation with VISTA InfoSec

Key Takeaways

  • NIS2 is a broad EU cybersecurity directive covering 18 sectors, including cloud and SaaS providers. It requires risk management, supply chain security, 72-hour incident reporting, and executive accountability.
  • DORA is a stricter, directly applicable regulation targeting the financial sector and its ICT suppliers with a demanding 4-hour incident report requirement and mandatory penetration testing.
  • Where they overlap, DORA takes precedence for financial entities (the lex specialis principle).
  • Most SaaS companies are touched by at least one of these regulations — and many will need to satisfy elements of both.
  • Start with an asset inventory, incident response workflow, and ISO 27001 as your compliance foundation.

The enforcement window is no longer ahead of you. It is now. The sooner your team understands its obligations, the less painful and expensive the path to compliance will be.