Why This Matters for SMEs in 2026
Cybersecurity is no longer an optional "add-on" — it's a legal condition for survival. By 2026, the transition periods for many sectors have expired. Companies classified as "important" or "essential" entities under NIS2, or acting as service providers to banks (under DORA), face a Herculean task.
The focus has shifted: away from purely preventive measures (firewalls) and toward operational resilience. It's no longer just about whether an attack happens, but how quickly the organization survives and reports it.
NIS2: The Foundation of European Cybersecurity
The NIS2 Directive (Network and Information Systems Security) is the EU's response to the increased threat posed by state actors and cybercriminals. It massively expands the range of companies affected.
The two categories of NIS2:
- Essential entities: large companies in highly critical sectors (energy, transport, banking, healthcare).
- Important entities: providers in sectors such as waste management, food production, or the chemical industry.
SMEs are often indirectly affected: if a small supplier works for an energy company, it will be contractually required to comply with NIS2 standards to secure the supply chain.
DORA: The Specialized Fortress for the Financial Sector
The Digital Operational Resilience Act (DORA) is a regulation — meaning it applies directly, without national implementation detours. DORA assumes that an IT failure in the financial system can trigger a chain reaction that threatens the entire EU economy.
The five pillars of DORA:
- ICT risk management: a robust framework for identifying and mitigating risks.
- ICT incident reporting: classification and reporting of major incidents.
- Digital operational resilience testing: regular penetration testing (TLPT).
- Third-party risk: oversight of cloud providers and software vendors.
- Information sharing: promoting collaboration between financial institutions.
The Relationship Between NIS2 and DORA: Which One Prevails?
This is the most important question for compliance officers. The principle "lex specialis derogat legi generali" applies.
Since DORA is more specifically tailored to the financial sector, its rules take precedence over NIS2. Financial institutions must therefore primarily comply with DORA. But be careful: in areas DORA doesn't explicitly cover (e.g., certain physical infrastructure security aspects), NIS2 can still apply as a supplement.
The Reporting Cascade: Why Every Minute Counts
This is where the most significant differences in operational implementation become apparent.
| Feature | NIS2 | DORA |
|---|---|---|
| Early warning | Within 24 hours | Within 4 hours (for major incidents) |
| Incident report | Within 72 hours | By the end of the same business day (or the next day) |
| Final report | After 1 month | As soon as the root cause analysis is complete |
For SMEs, DORA's 4-hour deadline means manual processes are no longer sufficient. Automated monitoring tools are essential here.
Sanctions and Personal Liability
Both NIS2 and DORA are serious about accountability. The days when cybersecurity could simply be "handed off" to the IT department are over.
- Management liability: executives must approve cybersecurity measures and oversee their implementation. They can be held personally liable for failures.
- Fines: under NIS2, up to €10 million or 2% of global revenue. DORA provides for similarly severe fines, plus daily penalty payments for critical third-party providers.
Practical Guide to Implementation
To avoid getting lost in complexity, SMEs should follow this path:
- Scope analysis: am I an "essential entity" (NIS2) or an "ICT third-party provider" (DORA)?
- Gap analysis: compare your current state against ISO 27001 or NIST standards (a good foundation for both).
- Incident response plan: create playbooks that account for DORA's extremely short deadlines.
- Supply chain audit: review your own subcontractors — because their security is now your security.
Conclusion: Resilience as a Competitive Advantage
NIS2 and DORA are not just bureaucratic hurdles. They force companies to build digital resilience that's essential for survival in an age of AI-driven cyberattacks. Companies that integrate these requirements early not only protect themselves from fines but also secure the trust of their customers and partners.
FAQ
Does DORA also apply to small insurance intermediaries?
Does DORA also apply to small insurance intermediaries?
Yes, DORA is very broad in scope but provides proportionality rules for microenterprises.
Do I need to implement an ISMS for NIS2?
Do I need to implement an ISMS for NIS2?
De facto, yes. Even though the law doesn't mandate a specific system, an information security management system (ISMS) based on ISO 27001 is the safest path to compliance.
Can authorities shut down my business for DORA violations?
Can authorities shut down my business for DORA violations?
DORA enables supervisory authorities to impose far-reaching sanctions, up to and including the withdrawal of licenses or the prohibition of certain services.







