.avif)
NIS2 in the financial sector: how does it relate to DORA and ISO 27001?
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

What is NIS2 (Cybersecurity Act in the Netherlands)?
The NIS2 Directive (Network and Information Security Directive) focuses on cybersecurity for essential sectors across Europe. In the Netherlands, NIS2 has been implemented through the Cybersecurity Act (Cbw): this law comes into effect on August 15, 2026. Essential sectors include energy companies, healthcare, transport, and large IT service providers. With NIS2, the EU aims to ensure that these companies:
- Maintain robust digital security.
- Identify and address risks.
- Report major cyber incidents promptly.
The goal is simple: to protect critical infrastructure from cyberattacks and ensure that companies and countries collaborate more effectively to tackle digital threats. Companies acting as suppliers to these essential sectors must establish agreements with their major clients. They must be able to demonstrate that they operate securely, based on their specific risk profile.
Why NIS2 is relevant to the financial sector
Traditionally, financial institutions have already been subject to various strict frameworks such as PCI-DSS, EBA guidelines, the Wft, and the GDPR. With the arrival of NIS2, Europe is adding an extra layer to this.
Are you automatically subject to NIS2 as a financial organization?
Yes. The financial sector falls under the category of essential entities. This means:
- stricter security requirements
- stringent reporting obligations
- supervision by national authorities
- director liability
But… there is more: DORA.
What is DORA?
While NIS2 is a broad cybersecurity directive that applies to many sectors, DORA (Digital Operational Resilience Act) is focused entirely on the financial world:
- Banks
- Insurers
- Payment institutions
- Investment firms
- Pension funds
- Crypto asset service providers
- ICT Third-Party Service Providers (Critical Third Party Providers)
DORA is not a directive, but a regulation. This means it is directly binding, without national interpretation. DORA focuses on:
- ICT risk management
Example: a payment institution must annually assess which IT systems pose the most critical risk (e.g., the payment platform) and implement measures such as network segmentation, MFA, and stricter monitoring.
- Incident reporting
Example: a bank that discovers a phishing attack that could affect customers must report this to the regulator within a very short timeframe, including an impact analysis, actions taken, and follow-up measures.
- Penetration testing (TIBER-EU)
Example: an insurer must periodically conduct a TIBER-EU test in which ethical hackers simulate realistic attacks, such as breaching the customer portal or fraud via APIs.
- Supply chain management and dependencies
Example: a pension fund must have insight into which software vendors have access to sensitive data and the risks this entails, including exit strategies should a vendor fail.
- Oversight of ICT service providers
Example: a fintech company that relies on a cloud provider (such as AWS, Azure, or Google Cloud) must demonstrate what contractual agreements are in place, how performance is monitored, and what happens in the event of outages. Many components overlap with NIS2, but DORA goes deeper and is more stringent.
How do NIS2 and DORA relate to each other?
1. DORA takes precedence for financial institutions
For all financial firms, the rule is: DORA is your primary cybersecurity regulation. NIS2 is supplementary, but where there is overlap, the requirements of DORA take precedence.
2. NIS2 goes further in supply chain responsibility
DORA focuses primarily on your direct ICT vendors. NIS2 compels organizations to assess the entire supply chain, including smaller suppliers.
3. Incident reporting is similar, but timelines differ
- NIS2 → 24-hour notification, 72-hour reporting
- DORA → varies by incident type, often more detailed and with stricter documentation requirements
4. NIS2 is broader, DORA is deeper
You can think of it like this:
- NIS2 = broad security obligation for many sectors
- DORA = specialized, in-depth requirements for financial institutions
The role of ISO 27001: standard for both regulations
Now that you have two robust frameworks (NIS2 + DORA), you might be wondering as an organization: “How do I ensure I’m not doing double the work?”. That is exactly where ISO 27001 becomes relevant.
ISO 27001:
- provides structure through an information security management system (ISMS)
- is internationally recognized
- integrates seamlessly with risk-based cybersecurity
- helps demonstrably meet legal requirements
Many of the controls mandated or recommended by ISO 27001 correspond directly to requirements in both NIS2 and DORA. ISO 27001 supports, among other things:
- Risk management
- Policy & governance
- Incident management
- Access management
- Supplier management
- Logging & monitoring
- Continuity management
By choosing ISO 27001 as your framework, you establish a foundation that covers a large portion of the topics and requirements of NIS2 and DORA.
What do NIS2, ISO 27001, and DORA mean for you?
1. You must comply with DORA
DORA is mandatory for almost all financial institutions and many of the ICT service providers that support them.
2. NIS2 also applies, but it largely overlaps with DORA
Unlike in other sectors, you have no choice: both apply.
3. ISO 27001 is the smartest approach
ISO 27001 helps you implement DORA and NIS2 by:
- structuring processes
- securing measures
- simplifying audits
- improving accountability
4. Start with a DORA gap analysis
A solid approach:
- Start with DORA requirements as a foundation
- Check which additional NIS2 requirements apply
- Record everything in an ISMS based on ISO 27001
How do you get started with NIS2, DORA, and ISO 27001? (Step-by-step plan)
- Map out which parts of DORA and NIS2 apply to your organization
- Conduct a gap analysis
- Link all requirements to ISO 27001 controls
- Create a roadmap for, for example, 12–24 months
- Establish governance and roles
- Implement technical and organizational measures
- Document accountability: policies, risks, procedures, tests, and reports
Conclusion
DORA and NIS2 are mandatory, but ISO 27001 is the most practical way to become and remain compliant. It may seem like a lot, but by combining them smartly, you avoid duplicate work and build a future-proof information security management system. Want to know more? Contact us below for a no-obligation consultation!
.avif)
.avif)


















