EU NIS-2 Directive Calls Firms to Apply DORA Cyber‑Resilience Lessons
The European Union’s NIS-2 directive tightens cybersecurity, risk‑management and supply‑chain obligations for thousands of companies across many sectors, expanding far beyond the finance‑only focus of the Digital Operational Resilience Act (DORA). DORA, which has been mandatory for financial firms since early 2025, revealed that more than half of reported security incidents originated with third‑party ICT providers, according to the Austrian Financial Market Authority. The experience shows that risks now lie largely outside an organisation’s own boundaries.
NIS‑2 therefore places greater emphasis on managing third‑party and supply‑chain risks, demanding transparency, evidence‑ability and robust organisational implementation. Industry experts such as Robin Schmeisser, CEO of Fabasoft Contracts, stress that "security cannot end at the corporate border" and that firms must adopt a holistic view of their digital value chain, identify critical dependencies early, and consider alternative providers where necessary. The directive aims to ensure that companies can demonstrate complete risk mitigation and resilience in any audit or crisis scenario.