Skip to content
Built for directly regulated entities

NIS2, DORA & CRA compliance for regulated entities and data centre operators

Three cyber regimes. One obligation map.

NIS2 cybersecurity duties, DORA operational resilience, CRA product security — banks, insurers, essential and important entities, manufacturers of connected products, and data centre operators increasingly carry duties under more than one at once. ComplyOne maps your obligation scope across all three and tracks the deadlines that follow.

Just 5 quick questions — no credit card required.

Product preview
ComplyOne product screenshot: Global dashboard all enabledComplyOne product screenshot: Global dashboard detailsComplyOne product screenshot: Module dials workingComplyOne product screenshot: Regulation compliance

Why regulated entities can't manage NIS2, DORA and the CRA as separate projects

NIS2 (in force since January 2023, national transposition due by 17 October 2024) put cybersecurity risk management, supply-chain security and incident reporting on a statutory footing for essential and important entities across 18 sectors. DORA layers financial-sector-specific ICT risk management, third-party oversight and resilience testing on top for banks, insurers, investment firms and payment institutions — DORA is lex specialis where it overlaps NIS2, but does not remove every NIS2 duty. The Cyber Resilience Act adds product-security obligations for manufacturers of anything with a digital element, with its own separate incident-reporting clock. A data centre operator, a bank running its own software, or a manufacturer selling connected products can face duties under two or three of these at once — treating them as separate compliance projects means the same evidence gets produced three times, on three different clocks, and gaps between them go unnoticed.

What's included in Cyber Entity

The regulations that matter most for banks, insurers, nis2 essential/important entities, cra manufacturers, data centre operators — covered, mapped to your business, and tracked over time.

NIS2

Cybersecurity risk-management measures, governance accountability and incident reporting for essential and important entities across 18 sectors. Scope test: 50+ employees qualifies on its own; under that, in scope only if both annual turnover AND balance sheet total exceed EUR 10M. Initial incident notification within 24 hours of becoming aware, full notification within 72 hours.

DORA

Digital Operational Resilience Act — ICT risk-management framework, register of ICT third-party providers, resilience testing, and incident reporting for banks, insurers, investment firms, payment institutions and similar financial entities. Initial notification within 4 hours from classification of the incident as major (24-hour outer cap from becoming aware (outer cap if classification itself is delayed)). Penalties for the entity itself are set nationally, not by a single EU-wide cap — they vary significantly by member state.

Cyber Resilience Act

Essential cybersecurity requirements, conformity assessment and CE marking for manufacturers of products with digital elements. Reporting obligations (Art. 14) begin 11 September 2026, applying to products already on the market. Full application of the remaining requirements from 11 December 2027. Early-warning notification within 24 hours, full notification within 72 hours, both from becoming aware.

Data centre facility obligations

Data centre operators additionally carry energy-efficiency and sustainability-reporting duties (EED/EnEfG) alongside their NIS2 cybersecurity duty as digital-infrastructure providers — tracked as facility metrics (PUE, WUE, ERF, REF) rather than folded into the NIS2/DORA/CRA obligation scope above, since the regulatory basis is distinct.

How Cyber Entity works

1

Onboard in minutes

Quick signup, then 5 questions about your business — sector, locations, data flows. No credit card required.

2

Get your compliance map

See exactly which regulations apply to your business, where the gaps are, and what severity each carries.

3

Act on it

A prioritised task list, document templates, and an evidence pack organised for audit — guided through to a defensible compliance baseline.

Daily regulatory horizon scanning

ComplyOne scans EU regulatory sources every day — directives, implementing acts, regulator guidance, enforcement notices. When something changes that affects your obligation map, you get a structured alert: what changed, why it applies to you, and what you need to do. No more discovering enforcement deadlines from a news headline.

How to approach banks, insurers, nis2 essential/important entities, cra manufacturers, data centre operators compliance

1

Establish which regimes actually apply to your entity

A bank is a DORA financial entity and may separately be NIS2-scoped as digital infrastructure. A manufacturer of connected industrial equipment is CRA-scoped and may be NIS2-scoped as 'important' under the manufacturing sector test. A data centre operator is NIS2-scoped as digital infrastructure and carries separate facility-level obligations. Confirm scope under each regime individually before assuming overlap or exclusion.

2

Map where DORA displaces NIS2, and where it doesn't

DORA is lex specialis for financial entities' ICT risk management, incident reporting, resilience testing and third-party provisions — those specific NIS2 provisions are displaced for a DORA-covered entity. Displacement is per-provision, not whole-module: a DORA entity is not simply 'outside NIS2' for every purpose, and some member states may still expect national registration. Get this mapping right before building a merged control set, not after.

3

Build the incident-reporting clock matrix once

NIS2, DORA and the CRA each run their own incident-reporting clock, on different trigger events, to different authorities. An entity in scope for more than one needs a single matrix mapping which clock starts when, rather than tracking each regime's deadlines in isolation and discovering a missed window after the fact.

4

Stand up resilience testing against DORA's actual requirement

DORA requires proportionate ICT resilience testing, with more demanding threat-led penetration testing for entities DORA itself designates as significant. Confirm which tier applies to you specifically rather than defaulting to the most demanding regime out of caution or the lightest out of cost — both are wrong in different directions.

5

Keep product-security (CRA) and operational-security (NIS2/DORA) evidence separate

CRA obligations attach to a manufactured product; NIS2 and DORA obligations attach to how the entity itself operates. A manufacturer that is also NIS2-scoped needs both evidence trails, and they answer different questions for different auditors — do not merge them into one undifferentiated 'security' file.

Swiss-hosted

All data hosted in Switzerland — outside US data-access frameworks.

9 EU regulations

GDPR, AI Act, NIS2, DORA, FADP, UK GDPR, Data Act, CSRD, AMLR — one platform.

Daily horizon scanning

Regulatory changes alerted, mapped to your obligations, every day.

Frequently asked questions

We're a bank — do we need to worry about NIS2 at all if DORA already applies to us?+

Partly. DORA is lex specialis and displaces NIS2's ICT risk-management, incident-reporting, resilience-testing and third-party provisions for a covered financial entity — but displacement is per-provision, not a blanket exemption from NIS2 as a whole, and Chapter VII supervision considerations can still apply alongside your DORA obligations. Treat the two together as one mapped obligation set, not as 'DORA replaces NIS2'.

Our company makes hardware with embedded software — are we CRA or NIS2, or both?+

Likely CRA as a manufacturer of a product with digital elements, regardless of size. Whether you're also NIS2-scoped depends on your sector and the size test independently — manufacturing is one of NIS2's covered sectors, so a manufacturer at or above the size thresholds can be in scope for both, each with its own obligation set and its own incident clock.

As a data centre operator, is our cybersecurity duty separate from our energy-reporting duty?+

Yes, and they're tracked separately for exactly that reason. NIS2 scopes data centres in as digital infrastructure, which is a cybersecurity duty. Energy-efficiency and sustainability reporting (EED/EnEfG) is a distinct legal basis with its own thresholds and metrics (PUE, WUE, ERF, REF) — the two run in parallel, not as one combined obligation.

How many different incident-reporting clocks could we actually be running at once?+

Up to three, if you're in scope for all of NIS2, DORA and the CRA: NIS2's 24/72-hour early-warning/notification pair, DORA's 4-hour initial notification (24-hour outer cap), and the CRA's 24/72-hour pair for products. Each runs on its own trigger and reports to its own authority — they don't merge into a single window.

How quickly can we get started?+

The compliance check takes about 5 minutes and produces your applicable-regulations map across NIS2, DORA and the CRA immediately. From there, ComplyOne tracks your obligation scope per regime, the incident-reporting deadline reference for each, data centre facility metrics where applicable, and resilience-testing management.

See where you stand — in 60 seconds

Free compliance check, just 5 quick questions. No credit card required — get your obligation map and gap report.

Related guides

Practical guidance for banks, insurers, nis2 essential/important entities, cra manufacturers, data centre operators.