The DORA regulation (Digital Operational Resilience Act) is a European regulation that sets uniform requirements for the security of networks and information systems of organizations operating in the financial sector and their suppliers of information technology and IT services, such as cloud platforms or data analysis services.
NIS2 is an updated version of the 2016 Network and Information Security Directive. NIS2 significantly expands the scope of the current legislation and presents a new solution to strengthen and secure European cyberspace. EU Member States are obliged to adapt this Directive into their legal system.
The scope of obligations to ensure information and cyber security will not change that much with the new law. What will be new, however, will be the number of regulated entities. Under the current cyber security law regime, obligations are imposed on several hundred larger firms and public bodies. The new law will affect thousands, if not tens of thousands, of organizations. Including a number of medium and smaller entities. Even in areas that have not yet been covered by any regulation directly related to information or cyber security, such as the food industry, waste management, the provision of certain IT services, transport, etc.