Cybersecurity

DORA and NIS2: What US Companies Need to Know and Do Before the Deadlines

Rajesh Nair, Managing Director. . Republished: . 12 min read

In short

Two European rules are now in force and a large number of companies headquartered in the United States are inside their scope. If you serve European financial institutions, supply technology services to European entities, or run European operations, the obligations may already apply to you whether or not anybody has told you.

Two major EU cybersecurity regulations are now in force, DORA (Digital Operational Resilience Act) and NIS2 (Network and Information Security Directive 2), and a significant number of US-headquartered companies are in scope. If your company serves EU financial institutions, provides IT services to EU entities, or has European operations, you may have compliance obligations you are not yet addressing. The stakes are significant: DORA non-compliance carries penalties up to €10 million or 5% of global annual turnover. NIS2 carries penalties up to €10 million or 2% of global annual revenue.

DORA: Digital Operational Resilience Act

What Is DORA?

DORA is an EU regulation that went into force on January 17, 2025. It establishes a comprehensive framework for digital operational resilience in the EU financial sector, covering banks, insurance companies, investment firms, payment processors, and critically, the ICT service providers (IT companies) that serve them.

Who Is In Scope?

DORA has two categories of in-scope entities:

Financial entities (direct obligation):

ICT third-party service providers (indirect obligation via contracts):

If you provide IT services, cloud infrastructure, software, or managed services to a bank, insurer, or investment firm with EU operations, you are likely in scope for DORA, even if you are headquartered in the United States.

DORA's Five Pillars

PillarKey Requirements
ICT Risk ManagementComprehensive ICT risk framework. Risk appetite statement. Classification and protection of information assets
ICT Incident ReportingClassify incidents by materiality. Report major incidents to regulator within 4 hours (initial) and 72 hours (intermediate). Root cause report within 1 month
Digital Operational Resilience TestingAnnual threat-led penetration testing (TLPT) for significant institutions. Vulnerability assessments. Scenario-based testing
ICT Third-Party Risk ManagementDue diligence on all ICT vendors. Contractual requirements for resilience. Exit strategies. Register of critical third parties
Information SharingVoluntary threat intelligence sharing within the EU financial community

What DORA Means for US ICT Providers

If your EU financial institution clients are asking you to sign DORA-compliant contract addenda, this is your signal that you are in scope. DORA requires financial entities to include specific provisions in contracts with ICT providers:

NIS2: Network and Information Security Directive 2

What Is NIS2?

NIS2 is an EU directive that updated the original 2016 NIS Directive. Member states were required to transpose NIS2 into national law by October 17, 2024. NIS2 significantly expanded the scope of cybersecurity obligations beyond the original directive, adding new sectors and new requirements.

Who Is In Scope?

NIS2 applies to organizations that:

  1. Operate in an in-scope sector (see below)
  2. Operate in the EU (have an establishment in an EU member state, OR provide services to EU customers from outside the EU in certain sectors)
  3. Meet the size thresholds: medium enterprise (50+ employees or €10M+ revenue) or large enterprise (250+ employees or €50M+ revenue)

In-scope sectors:

For US companies: If you are a cloud provider, managed service provider, or data center operator serving EU customers, you are likely in scope. If you are a manufacturer with EU production facilities, you are likely in scope. The "country of establishment" rule means NIS2 applies to the EU entity, even if the parent is headquartered in the US.

NIS2 Requirements

NIS2 requires in-scope entities to implement "appropriate and proportionate technical and organisational measures" in 10 areas:

  1. Risk analysis and information security policies
  2. Incident handling (detection, response, recovery)
  3. Business continuity (backup management, disaster recovery, crisis management)
  4. Supply chain security (ICT supplier relationships and security)
  5. Security in network and information systems acquisition, development, and maintenance
  6. Policies and procedures to assess cybersecurity risk management measures effectiveness
  7. Basic cyber hygiene practices and cybersecurity training
  8. Cryptography and encryption policies
  9. Human resources security, access control, and asset management
  10. Multi-factor authentication and continuous authentication solutions

Incident Reporting Under NIS2

NIS2 requires a three-stage reporting process for significant incidents:

DORA vs NIS2: Key Differences

FactorDORANIS2
Regulation typeEU Regulation (directly applicable)EU Directive (transposed into national law)
Primary sectorsFinancial sector only16 sectors across economy
US company applicabilityUS ICT providers serving EU financial entitiesUS companies with EU establishments in scope sectors
Enforcement dateJanuary 17, 2025 (in force)October 17, 2024 (transposition deadline)
Maximum penalty€10M or 5% global turnover€10M or 2% global revenue
Testing requirementsMandatory TLPT for major institutionsEncouraged, not mandated

The 90-Day DORA/NIS2 Compliance Roadmap for US Companies

Days 1 to 30: Scoping and Gap Assessment

Days 31 to 60: Policy and Control Development

Days 61 to 90: Testing and Documentation

Defense contractors reading this for NIS2 exposure should also check CMMC 2.0, a separate and stricter US requirement that runs alongside it.

TechCloudPro's cybersecurity compliance consulting practice helps US companies assess DORA and NIS2 applicability, conduct gap assessments, and build compliance programs that satisfy EU regulatory requirements. We have worked with technology companies, financial services firms, and manufacturers to navigate EU cybersecurity regulation. Schedule a DORA/NIS2 scoping call to determine your obligations and build a compliance plan.

About the author

Rajesh Nair, Managing Director

Rajesh divides his time between several business interests, ranging from solar powered sustainable products and corporate gifting to organic food production, technology and logistics. He brings that operating background to TechCloudPro, where he is responsible for keeping delivery running across geographies.

Related reading

Talk to the team that wrote this

If any of this matches what you are dealing with, a short conversation will get you further than another article.

Book a consultationCybersecurity at TechCloudPro