< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

6 clusters · 15 sources · 58 days · First seen · Last updated

Categories: TECHNOLOGY · BUSINESS · POLITICS

EU DORA & NIS‑2 compliance challenges

Entities: Claude Mythos · European Union · Digital Operational Resilience Act · Anthropic

Overview

In late May 2026 the EU adopted the Network and Information Security Directive 2 (NIS‑2) and the Digital Operational Resilience Act (DORA). NIS‑2 expands cyber‑risk duties to roughly 160,000 entities in 18 critical sectors, while DORA, mandatory for financial firms since early 2025, imposes continuous risk‑management, resilience testing and board‑level accountability. By the end of June Portugal had transposed NIS‑2 into national law, launching an electronic self‑identification and incident‑notification platform and creating new roles such as Cybersecurity Responsible and Permanent Point of Contact. The strict DORA enforcement has sparked rapid growth in third‑party risk‑management (TPRM) solutions. Vendors like OneTrust, UpGuard, Vanta and Bitsight now offer automated questionnaires, real‑time cyber‑ratings, continuous monitoring and native xBRL‑CSV export to satisfy Article 28’s supply‑chain mapping and reporting obligations. A July 2026 analysis found that 96 % of European financial‑services firms remain non‑compliant, with regulators shifting from policy intent to demonstrable results—requiring measurable recovery objectives, backup immutability, periodic testing and realistic simulations. Parallel findings from the Austrian Financial Market Authority show that more than half of reported incidents stem from third‑party ICT providers, underscoring the supply‑chain focus of both DORA and the newly‑tightened NIS‑2. Experts stress a holistic view of the digital value chain to meet upcoming milestones in the AI Act, Cyber Resilience Act, PSD3, Digital Euro and other EU rules, warning that fragmented compliance could erode efficiency. In July 2026 the EU further tightened DORA by obligating financial institutions, insurers, investment firms and their ICT service providers to protect cryptographic keys throughout their lifecycle and to adopt strong authentication within a unified ICT risk‑management framework. Non‑compliance can lead to fines of up to 2 % of global annual turnover or €5 million for critical third‑party providers.

Timeline

  1. 6 days ago

    [TECHNOLOGY] 3 sources
    EU DORA Regulation Tightens Cryptographic Key Protection Amid AI-Driven Cyber Threats

    EU DORA now forces financial firms to protect cryptographic keys and use strong authentication, with penalties up to 2 % turnover. Combined with GDPR and NIS2, AI tools like Claude Mythos heighten cyber‑risk, p

  2. 10 days ago

    [TECHNOLOGY] 2 sources
    EU NIS-2 Directive Calls Firms to Apply DORA Cyber‑Resilience Lessons

    EU NIS-2 expands cybersecurity rules beyond finance, urging firms to adopt DORA‑derived lessons on third‑party risk, supply‑chain transparency, and holistic digital resilience.

  3. 26 days ago

    [BUSINESS] 3 sources
    EU financial firms lag on DORA compliance amid sweeping regulatory overhaul

    EU financial firms are largely non‑compliant with DORA, while a new study flags over 70 upcoming regulations urging integrated governance across the sector.

  4. about 1 month ago

    [BUSINESS] 2 sources
    EU DORA compliance drives demand for specialized TPRM software

    DORA enforcement in 2026 mandates financial firms to use dedicated TPRM tools for N‑party mapping, continuous threat monitoring and xBRL‑CSV reporting, with platforms like OneTrust, UpGuard, Vanta and Bitsight.

  5. about 1 month ago

    [TECHNOLOGY] 2 sources
    EU NIS2 Directive Expands to 160,000 Entities, Portugal Launches New Cybersecurity Regulation

    The EU NIS2 Directive now applies to about 160,000 firms, imposing board‑level cyber risk duties and hefty fines; Portugal has issued a national regulation and electronic platform to enforce compliance.

  6. 2 months ago

    [POLITICS] 3 sources
    EU introduces NIS-2 and DORA rules to tighten digital security and financial resilience

    The EU's NIS-2 directive and DORA regulation impose stricter security, risk‑management and incident‑reporting duties on critical sectors and financial firms, extending compliance to many businesses.

Sources

agendadigitale.eu · apdc.pt · bitmat.it · cybersecurity-magazine.com · dbsc.de · encryptionconsulting.com · it-daily.net · mijndocent.nl · mit-blog.de · peliqan.io · silicon.de · smo-handbuch.de · sortir.fr · trend-rays.com · versicherungsbote.de