Three EU regulations now decide what your engineering team must build, prove, and report: NIS2, DORA, and the Cyber Resilience Act. They share intent but differ in scope, deadlines, and who signs off. This hub maps how they connect and routes you to the deep guide for each.
Which EU cyber rules actually apply to your product and company?
Scope depends on what you are and what you sell. NIS2 targets operators in eighteen essential and important sectors. DORA binds financial entities and their ICT providers. The Cyber Resilience Act binds anyone placing a product with digital elements on the EU market. Most firms fall under at least one regime, and many fall under two.
- ▸NIS2 (Directive (EU) 2022/2555) covers essential and important entities, generally medium-sized and up (50-plus staff or 10 million euro-plus turnover), across energy, health, digital infrastructure, transport, and manufacturing.
- ▸DORA (Regulation (EU) 2022/2554) covers banks, insurers, payment and crypto-asset firms, and the ICT third parties that serve them.
- ▸CRA (Regulation (EU) 2024/2847) covers manufacturers, importers, and distributors of hardware and software with digital elements.
- ▸Map legal entities, products, and sectors to each regime first. Our The 2026 SME Cybersecurity Checklist for GDPR, NIS2 and DORA is a fast triage.
Where do NIS2, DORA and the CRA overlap?
All three demand the same engineering primitives: asset inventory, risk management, vulnerability handling, incident reporting on tight clocks, and supply-chain assurance. They differ mainly on who is regulated and on the deadline. Build the controls once, then map evidence to each regime instead of running three parallel programs.
- ▸Shared demands include MFA, encryption, logging, patch cadence, coordinated vulnerability disclosure, and tested business continuity.
- ▸Timing diverges: NIS2 uses a 24-hour, 72-hour, and one-month reporting sequence; the CRA uses 24-hour, 72-hour, and 14-day reporting for exploited vulnerabilities; DORA sets its own staged incident clock.
- ▸For how this lands in cloud architecture, see NIS2, DORA, and the Cyber Resilience Act: Cloud Compliance in 2026.
What does NIS2 ask engineering teams to build?
NIS2 Article 21 lists ten risk-management measures, including incident handling, business continuity, supply-chain security, vulnerability disclosure, cryptography, MFA, and access control. Article 23 sets a 24-hour early warning, a 72-hour notification, and a one-month final report. Management is personally accountable for adopting and overseeing the measures.
- ▸Turn the ten measures into backlog items with named owners and machine-verifiable evidence.
- ▸Operators with industrial systems carry extra weight: OT and ICS Security in 2026: Defending Industrial Operations Under NIS2.
- ▸Supply chain is a named obligation, not an afterthought: NIS2 Supply-Chain Security in 2026: Who Is in Scope, How to Vet Vendors, and How to Build Auditable Software.
- ▸Full breakdown: NIS2 in 2026: Turning the Directive into an Engineering Backlog.
What does DORA add for financial-sector stacks?
DORA layers five pillars on financial entities: ICT risk management, incident classification and reporting, digital operational resilience testing, ICT third-party risk with a register of information, and information sharing. Significant entities also face threat-led penetration testing. DORA has applied since 17 January 2025, so this is live obligation, not a future one.
- ▸Maintain a register of information for every ICT third-party dependency, including subcontractors supporting critical functions.
- ▸Significant entities run threat-led penetration testing, typically on a three-year cycle.
- ▸Deep dive: DORA in Practice: What Resilience Really Asks of Your Stack.
What does the Cyber Resilience Act require you to ship?
The CRA makes secure-by-default a legal condition for selling products with digital elements in the EU. You must ship with no known exploitable vulnerabilities, an SBOM, a coordinated disclosure policy, and security updates across a defined support period. Reporting duties start 11 September 2026; CE-marking obligations apply from 11 December 2027.
- ▸Generate an SBOM in a machine-readable format (SPDX or CycloneDX) covering at least top-level dependencies.
- ▸Complete conformity assessment, technical documentation, and CE marking before the 2027 deadline.
- ▸The near-term clock, explained: The Cyber Resilience Act Countdown: September 2026 Is the Real Deadline, plus our engineering checklist, The Cyber Resilience Act Countdown: What to Ship Before September 2026.
- ▸SBOM and provenance depth: The Software Supply Chain in 2026: SBOMs, Provenance, and the CRA Reckoning.
How do you turn three regimes into one engineering backlog?
Build a single control set, then map each control to the clauses it satisfies. Most requirements collapse into a short list: asset inventory, SBOM and provenance, patch SLAs, coordinated disclosure, tested backups, and incident runbooks tied to legal clocks. Automate the evidence so audits query systems, not people.
- ▸Make evidence a build artifact: ISO 27001 Evidence as Code: Building an ISMS Engineers Don't Hate.
- ▸Prove what you shipped end to end: Provenance You Can Prove: SLSA, Sigstore, and Policy-as-Code CI/CD.
- ▸One control often satisfies three clauses; tag evidence by regime rather than duplicating work.
How do GDPR, ISO 27001 and the EU AI Act fit alongside these?
They interlock rather than compete. GDPR governs personal data. ISO 27001 gives you the management system auditors recognize. The EU AI Act adds obligations for AI systems by risk tier. Passing an enterprise security review usually means demonstrating all of them coherently, not one regime at a time.
- ▸Personal data baseline: GDPR Compliance for SaaS Startups: A Practical 2026 Guide.
- ▸Shipping AI features lawfully: EU AI Act in 2026: The Obligations That Actually Apply Now, and How to Ship Compliant AI Features.
- ▸Penalties concentrate the mind: NIS2 reaches up to 10 million euro or 2 percent of global turnover for essential entities; the CRA reaches up to 15 million euro or 2.5 percent for essential-requirement breaches.
How TuniCyberLabs helps
We map your entities and products to NIS2, DORA, and the CRA, then convert the overlap into one prioritized backlog with owners, SBOM pipelines, disclosure policies, and reporting runbooks wired to the legal clocks. Our EU-North Africa delivery model keeps the work close to your regulators and cost-controlled, without scattering evidence across three disconnected programs.
Book a compliance-readiness review at /contact and leave with a backlog, not a binder.
