Skip to main content

What NIS 2-Affected Companies Can Learn from DORA

How the financial industry's regulatory experience helps with NIS 2 implementation

Robin Schmeisser

Robin Schmeisser

Created on 25. August 2026

Zwei Personen arbeiten an DORA und NIS-2

With national implementing laws in Germany and Austria, NIS 2 is taking shape for thousands of companies. Many organizations are currently wondering what new cybersecurity, risk management, and governance requirements they will face and how to implement them.
For guidance, it’s worth looking to the financial sector. Since early 2025, the Digital Operational Resilience Act (DORA) has required financial companies to have specific digital operational resilience measures in place. Both DORA and NIS 2 aim to strengthen the resilience of critical and important organizations against cyber threats, IT outages, and risks along digital supply chains.
Over the past few years, banks, insurance companies, and other financial institutions have gained valuable practical experience in implementation: from identifying critical IT service providers and documenting processes to preparing for audits by regulatory authorities. Experience shows that the greatest challenges often lie not in technical security measures but in transparency, accountability, and organizational implementation. For companies subject to NIS 2, this provides valuable insights and areas for action.


1. The supply chain takes center stage

For a long time, cybersecurity measures focused primarily on protecting a company’s internal systems and processes. However, experience from the financial sector shows that risks increasingly arise outside a company’s boundaries. According to the Austrian Financial Market Authority (FMA)1, more than 50 percent of the security incidents reported since the Digital Operational Resilience Act (DORA) took effect originated with an IT service provider.
This development explains why new EU regulations, such as DORA and NIS 2, place a significantly greater emphasis on managing supplier and supply chain risks than previous regulations did. The lesson for NIS 2-compliant companies is clear: their security strategy must extend beyond their own boundaries. Resilience requires a holistic view of the entire digital value chain.


2. Transparency regarding critical dependencies

As part of the DORA implementation, many financial institutions had to closely examine their dependence on IT service providers. It became clear that many business processes depend on a small number of providers for which there were often no exit strategies or plans2. DORA has brought transparency to the potential impact of a critical service provider's failure or change.
Although NIS 2 does not require exit plans like DORA does, an important lesson can be drawn from this. Organizations should identify critical dependencies early on and explore possible alternatives. Those who understand their supply chain can better assess risks and respond more quickly in the event of a crisis.


3. The underestimated challenge of IT service provider management

According to financial firms, the greatest challenge during implementation was managing the risks associated with their IT service providers.3 DORA mandates comprehensive documentation and reporting obligations, risk assessments, due diligence, and obtaining information from suppliers, including security certifications and sub-service providers. It also requires ensuring this information is up to date and adapting existing contractual agreements.
These tasks proved to be more complex and time-consuming than originally expected, particularly with larger cloud and software providers. On-site audits by regulatory authorities revealed incomplete inventories, inadequate functions and processes, unclear responsibilities, and poor data quality. Additionally, IT service providers were often not properly integrated into processes, and many necessary contractual adjustments were missing.2
Experience from the financial sector clearly shows that managing IT service providers involves much more than just supplier management. Rather, it is an ongoing governance task requiring robust processes and up-to-date data. Companies subject to NIS 2 should not underestimate the effort required, either. Early, centralized collection of relevant service provider information and establishment of structured third-party management processes can prevent future implementation hurdles. AI-powered contract management helps to efficiently review contracts for regulatory risks and quickly implement necessary adjustments.


4. No compliance without verifiability

Simply defining processes is not enough to ensure reliable compliance. While most financial institutions had established procedures for managing their suppliers, the challenge was demonstrating the execution of each process step during an on-site audit.
This applied to risk analyses, criticality assessments, approval processes, regular monitoring and review activities, and reassessing existing service provider relationships, for example. Often, the necessary information was scattered across email correspondence, spreadsheets, and various specialized applications, making complete traceability of decisions and process steps difficult to ensure.
Therefore, to prepare for NIS 2, it is essential for organizations to design transparent and traceable governance, risk, and control processes from the outset. Digital, workflow-based processes are particularly helpful in this regard because they automatically manage all steps, clearly assign responsibilities, and document activities in an audit-proof manner. Complete audit trails and electronic workflow signatures allow one to verify at any time who conducted assessments, made decisions, or granted approvals and when.


5. NIS 2 is not an IT project

Both NIS 2 and DORA explicitly address the management's responsibility and also require an organization-wide approach to cyber risks. DORA has already demonstrated that establishing digital resilience requires a truly cross-functional effort involving numerous business units: Outsourcing, IT, supplier management, risk management, compliance, business units, and senior management must work closely together to effectively meet the requirements.
However, experience from the first year of DORA shows that, in practice, top management at many financial institutions was not sufficiently involved in the necessary processes. Consequently, necessary measures were often not approved or monitored.2
For successful implementation, organizations should view NIS 2 as a company-wide governance project. When all relevant stakeholders are involved from the beginning, responsibilities are clearly assigned and senior management is actively engaged, decisions can be made more quickly, measures can be consistently implemented, and regulatory requirements can be sustainably embedded within the company.


Conclusion

Cyber resilience stems not only from technical security measures, but also from clear responsibilities and defined processes for implementing and monitoring those measures. For organizations subject to NIS 2, the financial sector’s experience with DORA offers valuable guidance. Those that establish transparency early on; conduct risk-based assessments of IT service providers and existing contracts; systematically manage supply chain risks; establish robust governance structures; and document processes digitally and in an audit-proof manner will not only meet regulatory requirements more efficiently, but also strengthen their resilience to cyber risks in the long term.

 

Quellen: 
1)    KPMG Cybersecurity in Österreich 2026
2)    IT-Aufsicht im Finanzsektor: Das erste Jahr DORA - Bafin
3)    DORA – FMA-Aktivitäten - FMA Österreich