NIS2 and DORA: European Cyber Security Compliance and Turkish Companies
NIS2 places EU cyber security obligations on critical sectors and DORA on the financial sector. A comparison table, how they bind Turkish companies through the supply chain, ISO 27001 overlap and resilience testing with KAOS.
Quick answer: NIS2 and DORA are two regulations the European Union introduced to increase cyber security resilience. NIS2 places risk management, incident reporting and supply chain security obligations on organizations in critical and important sectors such as energy, health, transport and digital infrastructure. DORA specifically requires digital operational resilience, third party risk management and resilience testing for the financial sector. Although these regulations do not directly cover Turkish companies, Turkish companies that serve customers in Europe, sit in the supply chain of an EU organization or operate in the EU market can be bound by these obligations through contracts. So companies that export and work with the EU need to plan NIS2 and DORA compliance early.
Europe now ties cyber security not to good intentions but to legal obligation. NIS2 and DORA are two cornerstones of this approach. This article explains who the two regulations cover, their core requirements and what they mean for Turkish companies.
What is NIS2
NIS2 is the updated version of the European Union's network and information systems security directive. It widens the scope and tightens the obligations compared to the previous one. Its core elements:
- Expanding scope. Sectors such as energy, health, transport, water, digital infrastructure, public administration and important manufacturing are in scope.
- Risk management obligation. Organizations must prove their technical and organizational security measures.
- Incident reporting. Serious incidents must be reported to the authority within defined times.
- Management responsibility. Senior management is held directly responsible for cyber security.
- Supply chain security. The security of suppliers must also be assessed, see our supply chain security article for detail.
What is DORA
DORA (Digital Operational Resilience Act) is a regulation specific to the financial sector. It covers banks, insurance companies, payment institutions and the technology providers that serve them. Its core elements:
- Operational resilience. The organization must prove it can maintain service during a serious disruption.
- Third party risk management. Critical ICT suppliers must be strictly monitored.
- Resilience testing. Regular penetration testing and threat led testing are mandatory.
- Incident management and reporting. Incidents must be classified and reported to the authority.
NIS2 and DORA comparison
| Dimension | NIS2 | DORA |
|---|---|---|
| Scope | Multi sector critical infrastructure | Financial sector only |
| Focus | General cyber security management | Digital operational resilience |
| Testing | Risk based measures | Mandatory resilience and penetration testing |
| Supplier | Supply chain security | Critical ICT supplier oversight |
The two regulations complement each other. A financial organization must work in line with both DORA and, if in scope, the logic of NIS2.
Why Turkish companies should care
NIS2 and DORA are not directly Turkish legislation, but they indirectly bind Turkish companies:
- Supply chain pressure. If you serve an EU organization, that organization can require NIS2 and DORA compliant security practice from you through a contract.
- Market access. Meeting these expectations is a competitive advantage for operating in the EU market.
- Compliance overlap. ISO 27001 and KVKK compliance overlaps with a large part of the NIS2 and DORA requirements. If you already have a foundation, the compliance burden is reduced.
- Business continuity. DORA's resilience logic is directly related to business continuity and disaster recovery planning.
NIS2 and DORA readiness with DSET
DSET brings its ISO 27001, KVKK and GDPR compliance experience to NIS2 and DORA readiness. It assesses your current security posture against the requirements of these regulations, identifies gaps and provides a prioritized road map. It runs the mandatory resilience and penetration tests at scale with the local AI engine KAOS and documents every finding with a working proof. So you can concretely demonstrate compliance to your EU customers and business partners.
Frequently asked questions
Do NIS2 and DORA directly bind Turkish companies? The direct legal obligation is on organizations in Europe. But if you are in the supply chain of an EU customer, you can be subject to these requirements through a contract. So it turns into a practical requirement for exporting companies.
I have ISO 27001, how much extra work is needed for NIS2 and DORA? ISO 27001 is a strong foundation and overlaps with a large part of the requirements. In addition, a gap analysis and completion are needed in areas such as incident reporting times, third party risk management and mandatory resilience testing.
Does DORA cover only banks? No. Besides banks, DORA also covers insurance, payment institutions and technology providers that give them critical ICT services. If you are a technology company serving the financial sector, it concerns you too.
Sources
- European Union, NIS2 Directive: https://eur-lex.europa.eu
- European Union, DORA Regulation: https://eur-lex.europa.eu
To get readiness and resilience testing services to demonstrate NIS2 and DORA compliance to your customers and partners in Europe, contact DSET. We provide compliance consulting and penetration testing from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.