Two dates worth knowing: NIS2 became applicable across the EU in October 2024. DORA became applicable in January 2025. Both are already law, already enforceable, in the countries you or your customers operate in — not "coming soon," not "proposed." If you're a founder who filed those away as "something to look at eventually," eventually already arrived.
I say this as someone who filed them away too. My background is product, not compliance, and when I started digging into this properly, my first reaction was the same one I suspect you're having right now: wait, is this actually my problem? So let's start there, honestly, instead of pretending every startup reading this is automatically in scope.
(Standard caveat, and I mean it: this is an explainer, not legal advice. If you're genuinely unsure whether NIS2 or DORA applies to you, that's a conversation for a lawyer who knows your specific structure — not a blog post.)
What NIS2 actually is
NIS2 — the EU's Network and Information Security Directive, second version — is cybersecurity regulation aimed at making sure organizations that matter to European digital and economic infrastructure actually manage cyber risk properly, instead of treating security as optional.
It applies to two tiers of organizations ("essential" and "important" entities) across a fairly wide list of sectors: energy, transport, banking, health, digital infrastructure, managed service providers, cloud computing, data centres, public administration, and several others, generally scoped by sector plus company size.
The obligations, at a high level, cover things like:
- risk analysis and information security policies
- incident handling and reporting
- business continuity and crisis management
- supply chain security
- vulnerability handling
- basic cyber hygiene and staff training
- access control and asset management
If none of that rings a bell for your company specifically, you might genuinely be out of scope — NIS2 is not "every company in Europe." But two things are worth checking rather than assuming: whether your sector is covered, and whether one of your customers is a regulated entity who is now obligated to push security requirements down onto their vendors, including you.
What DORA actually is
DORA — the Digital Operational Resilience Act — is narrower and sharper. It's specifically about financial entities (banks, insurers, investment firms, payment providers, and more) and, critically, about the ICT third-party providers those financial entities rely on.
That second part is the one founders miss. If your startup sells software, infrastructure, or any ICT service into the financial sector, DORA doesn't just apply to your customer — it changes what your customer is now required to demand from you contractually. Third-party risk management, incident reporting obligations, operational resilience testing expectations — these start showing up in procurement and vendor-security conversations even if your own company was never directly "in scope" in the regulatory sense.
The assumption that breaks
If your mental model of EU compliance was shaped by GDPR, there's a specific assumption worth examining, because NIS2 and DORA both break it.
GDPR's operating logic was largely: have the right policies, have a lawful basis, respond correctly if something goes wrong. It's substantially about documentation and process discipline.
NIS2 and DORA lean harder toward demonstrated, operating technical and organizational controls — not just "do you have an incident response policy" but "does your incident handling actually work, is it tested, can you show it." DORA in particular expects operational resilience testing, not just planning documents describing what you'd do in theory.
This is exactly the gap we wrote about last week — the difference between a control that exists on paper and a control that's actually, continuously true. NIS2 and DORA are regulatory frameworks that are increasingly written with that distinction in mind, even if the enforcement reality is still catching up to the letter of the law in places.
Why "we'll deal with it before the audit" doesn't work here
With something like SOC 2, there's a clean mental model: you prepare, an auditor shows up on a known date, you pass or you don't. NIS2 and DORA don't quite work that way.
There isn't a single universal "NIS2 audit day" you can cram for. Enforcement happens through national supervisory authorities, incident reporting obligations that trigger on your timeline (not a scheduled one), and — probably the most common way this actually bites a startup — through your enterprise customers' own compliance obligations getting pushed down onto you as contractual requirements, security questionnaires, and vendor risk assessments that show up whenever their procurement or legal team decides to run one.
In other words: the "audit" isn't a fixed date, it's whenever an obligated customer, a supervisory authority, or an incident forces the question. Which means the honest answer to "are we compliant" needs to be true most of the time, not just true on the one day a year someone checks.
So — does this actually apply to you?
A rough (genuinely rough — see the caveat above) set of questions worth asking yourself:
- Are you selling to financial services customers, or ICT-adjacent services to them? DORA's third-party reach is broader than most founders expect.
- Are you, or is a major customer, in one of NIS2's covered sectors — energy, health, transport, digital infrastructure, MSP/MSSP, cloud, and the rest of the list?
- Has an enterprise customer's security or procurement team started asking questions that sound like this? That's often the real-world trigger, regardless of the formal regulatory scoping.
- Do you have EU operations, EU customers, or EU regulatory exposure at all, even if headquartered elsewhere?
If two or more of those land close to home, it's worth a real conversation — with a lawyer for the legal scoping question, and with your own engineering team for the more useful practical question: if someone asked us to prove this right now, could we?
That second question is the one most companies genuinely can't answer confidently. Not because they're non-compliant, necessarily — often because nobody has looked recently enough to know either way. Which, if last week's post landed, should sound familiar: a control you haven't checked lately isn't the same thing as a control you know is true.