Cybersecurity

EU Cyber Compliance for Engineers: NIS2, DORA and the Cyber Resilience Act

TuniCyberLabs Team
5 min read

NIS2, DORA and the Cyber Resilience Act now decide what EU engineering teams must build, prove and report. This hub maps how the three regimes overlap, who is in scope, and links to the deep guide for each.

Three EU regulations now decide what your engineering team must build, prove, and report: NIS2, DORA, and the Cyber Resilience Act. They share intent but differ in scope, deadlines, and who signs off. This hub maps how they connect and routes you to the deep guide for each.

Which EU cyber rules actually apply to your product and company?

Scope depends on what you are and what you sell. NIS2 targets operators in eighteen essential and important sectors. DORA binds financial entities and their ICT providers. The Cyber Resilience Act binds anyone placing a product with digital elements on the EU market. Most firms fall under at least one regime, and many fall under two.

  • NIS2 (Directive (EU) 2022/2555) covers essential and important entities, generally medium-sized and up (50-plus staff or 10 million euro-plus turnover), across energy, health, digital infrastructure, transport, and manufacturing.
  • DORA (Regulation (EU) 2022/2554) covers banks, insurers, payment and crypto-asset firms, and the ICT third parties that serve them.
  • CRA (Regulation (EU) 2024/2847) covers manufacturers, importers, and distributors of hardware and software with digital elements.
  • Map legal entities, products, and sectors to each regime first. Our The 2026 SME Cybersecurity Checklist for GDPR, NIS2 and DORA is a fast triage.

Where do NIS2, DORA and the CRA overlap?

All three demand the same engineering primitives: asset inventory, risk management, vulnerability handling, incident reporting on tight clocks, and supply-chain assurance. They differ mainly on who is regulated and on the deadline. Build the controls once, then map evidence to each regime instead of running three parallel programs.

  • Shared demands include MFA, encryption, logging, patch cadence, coordinated vulnerability disclosure, and tested business continuity.
  • Timing diverges: NIS2 uses a 24-hour, 72-hour, and one-month reporting sequence; the CRA uses 24-hour, 72-hour, and 14-day reporting for exploited vulnerabilities; DORA sets its own staged incident clock.
  • For how this lands in cloud architecture, see NIS2, DORA, and the Cyber Resilience Act: Cloud Compliance in 2026.

What does NIS2 ask engineering teams to build?

NIS2 Article 21 lists ten risk-management measures, including incident handling, business continuity, supply-chain security, vulnerability disclosure, cryptography, MFA, and access control. Article 23 sets a 24-hour early warning, a 72-hour notification, and a one-month final report. Management is personally accountable for adopting and overseeing the measures.

What does DORA add for financial-sector stacks?

DORA layers five pillars on financial entities: ICT risk management, incident classification and reporting, digital operational resilience testing, ICT third-party risk with a register of information, and information sharing. Significant entities also face threat-led penetration testing. DORA has applied since 17 January 2025, so this is live obligation, not a future one.

  • Maintain a register of information for every ICT third-party dependency, including subcontractors supporting critical functions.
  • Significant entities run threat-led penetration testing, typically on a three-year cycle.
  • Deep dive: DORA in Practice: What Resilience Really Asks of Your Stack.

What does the Cyber Resilience Act require you to ship?

The CRA makes secure-by-default a legal condition for selling products with digital elements in the EU. You must ship with no known exploitable vulnerabilities, an SBOM, a coordinated disclosure policy, and security updates across a defined support period. Reporting duties start 11 September 2026; CE-marking obligations apply from 11 December 2027.

How do you turn three regimes into one engineering backlog?

Build a single control set, then map each control to the clauses it satisfies. Most requirements collapse into a short list: asset inventory, SBOM and provenance, patch SLAs, coordinated disclosure, tested backups, and incident runbooks tied to legal clocks. Automate the evidence so audits query systems, not people.

How do GDPR, ISO 27001 and the EU AI Act fit alongside these?

They interlock rather than compete. GDPR governs personal data. ISO 27001 gives you the management system auditors recognize. The EU AI Act adds obligations for AI systems by risk tier. Passing an enterprise security review usually means demonstrating all of them coherently, not one regime at a time.

How TuniCyberLabs helps

We map your entities and products to NIS2, DORA, and the CRA, then convert the overlap into one prioritized backlog with owners, SBOM pipelines, disclosure policies, and reporting runbooks wired to the legal clocks. Our EU-North Africa delivery model keeps the work close to your regulators and cost-controlled, without scattering evidence across three disconnected programs.

Book a compliance-readiness review at /contact and leave with a backlog, not a binder.

TAGS
NIS2DORACyber Resilience ActEU compliancesupply chain securityincident reportingengineering backlogcybersecurity

Frequently Asked Questions

Do NIS2, DORA and the CRA apply to the same companies?

+

Not identically. NIS2 covers essential and important entities in eighteen sectors, DORA covers financial firms and their ICT providers, and the CRA covers anyone selling products with digital elements in the EU. Many organizations fall under two of the three, so scope should be mapped per legal entity and product rather than assumed.

When do these EU cyber rules take effect?

+

NIS2 had a national transposition deadline of 17 October 2024. DORA has applied since 17 January 2025. The Cyber Resilience Act entered into force in December 2024, with reporting duties from 11 September 2026 and CE-marking obligations from 11 December 2027. Some are already live and enforceable today.

Can one control set satisfy all three regimes?

+

Largely, yes. Asset inventory, SBOM and provenance, patch SLAs, coordinated vulnerability disclosure, tested backups, and incident runbooks satisfy overlapping clauses across NIS2, DORA and the CRA. The efficient approach is to build controls once, automate the evidence, and tag each artifact by the regime and clause it supports rather than running three separate programs.

What are the penalties for non-compliance?

+

They are material. NIS2 allows fines up to 10 million euro or 2 percent of global annual turnover for essential entities. The CRA allows up to 15 million euro or 2.5 percent of worldwide turnover for breaches of the essential requirements. DORA penalties are set by national competent authorities and can include periodic penalty payments.

How does GDPR relate to NIS2 and DORA?

+

GDPR governs personal data protection and breach notification, while NIS2 and DORA govern operational security and resilience. They overlap on incident handling and reporting but have separate authorities and clocks. A single security incident involving personal data can trigger obligations under all three at once, so reporting runbooks should account for each timeline.

Where should a small engineering team start?

+

Start by mapping which regimes apply, then build the shared primitives first: an asset and dependency inventory, an SBOM pipeline, a coordinated disclosure channel, tested backups, and an incident runbook wired to legal deadlines. This shared backlog satisfies most of NIS2, DORA and the CRA before you tackle regime-specific details.

Need help with
this topic
?

Our team specializes in the technologies and strategies discussed in this article. Let’s talk about how we can help your business.

Get in Touch