DORA, NIS2, and the End of ‘We’re Not in Scope’

Updated on: Sep 25, 2026 5 Minute Read

DORA and NIS2 obligations extend far beyond EU-headquartered organizations and entities directly named in the regulations. Any vendor selling services within the EU or operating as a third-party supplier to EU-regulated firms is directly impacted through contractual flow-down.

Passeca, a Hyperproof MSSP partner, helps organizations navigate the complexity of DORA and NIS2 through incident response, security awareness, vCISO services, and specialized compliance support. Sergiy Lapin, CEO of Passeca Germany, shared the daily realities his team sees as organizations navigate DORA and NIS2 requirements.

Workload increase translates to commercial risk

Sergiy and his team often encounter organizations where a single compliance lead manages the entire program. That lead may be mid-cycle on SOC 2® audit prep when a key customer submits a DORA compliance questionnaire with a strict 30-day deadline. With no extra headcount available, the bottleneck immediately threatens revenue.

“In this case, manual workload becomes a commercial risk,” Sergiy said. “It’s not an abstract compliance gap — it’s a real deadline, tied to a real customer relationship, that the business risks failing to meet simply because one person is stretched across too many frameworks at once.”

Fragmented ownership across business units compounds this workload. Vendor lists sit in procurement spreadsheets, security questionnaires sit in compliance tools, and a lack of cross-departmental coordination leads to duplicated effort and audit burnout.

‘We’re not in scope’ doesn’t work anymore

The scope question used to be simple: Is our company directly named in the regulation? That framing is obsolete. Contractual flow-down from NIS2- and DORA-covered entities — including banks, hospitals, and energy providers — pulls vendors into the regulatory sphere regardless of where they are headquartered.

“If you sell to a bank, a hospital, or an energy provider, you are now part of their third-party risk surface,” Sergiy explained. “We see those clauses landing in supplier contracts in countries where regulatory transposition isn’t even finalized. ‘We are not in scope’ was the 2024 answer. In 2026, the right answer is: ‘Our customers are in scope, so we need to be ready.’” 

The DORA & NIS2 Mindset Shift

Legacy Compliance MindsetThe DORA & NIS2 Reality
“Is our company directly named in the regulation?”“Are our key customers subject to DORA or NIS2 compliance?”
Point-in-time, annual security questionnairesContinuous contractual flow-down and mandatory risk tracking
Siloed vendor lists managed in isolated spreadsheetsCentralized Register of Information mapped directly to critical functions

Incident reporting mandates expose plan gaps 

NIS2 requires early warning notification within 24 hours of an incident, a formal notification within 72 hours, and a final root-cause analysis within 1 month. DORA mandates a similarly aggressive reporting window. 

Sergiy’s team consistently sees the same operational gap during client engagements: “The incident response runbook was written for internal escalations — not for regulatory-facing notification under a legal deadline.” 

Organizations assume their existing incident response plan is sufficient, only to discover critical gaps the first time the clock starts ticking against a regulatory deadline.

Board responsibility grows as board scrutiny pivots

Under DORA, management bodies must formally approve cybersecurity measures and undergo mandatory security training. Personal accountability has replaced passive delegation.

 “The board can’t say, ‘We hired a CISO, we delegated.’ That defense is gone,” said Sergiy.

Board scrutiny has pivoted from passive oversight to active risk management. “The board used to ask, ‘Are we compliant?’ Now they ask, ‘Are we resilient?’ Compliance is binary; you have or don’t have a certificate. Resilience is a posture that encompasses how fast an organization can recover and how confident an organization is in engaging with regulators.” 

This shift challenges CISOs who were historically trained to report on control completion percentages rather than business resilience. 

Three practical steps to manage DORA and NIS2 impact

Step 1: Identify your assets (The three W’s)

To help organizations build a defensible foundation, Sergiy stresses three core questions to open every engagement:

  • What is the asset?
  • Where is the asset?
  • Who owns the asset?

Sergiy’s team often encounter organizations without an understanding of their assets. Asset protection is impossible without an asset inventory. Only when a complete inventory exists can teams effectively layer on controls and frameworks. 

Step 2: Don’t start from scratch for your Register of Information

DORA requires a living Register of Information covering all ICT third-party relationships mapped to critical business functions. Many mid-market organizations lack this view because vendor data remains split across procurement and compliance silos.

Sergiy advises against starting with a blank spreadsheet. Instead, start with the organization’s contract repository. Pull all active contracts involving data processing or system access to create the seed list. Next, layer in criticality: Which vendors, if they failed for 4 hours, would stop your organization from serving customers?

Teams adopting this contract-first approach reach 80% coverage in 2 weeks versus 2 quarters compared to those starting with empty templates.

Step 3: Shift reporting from ‘Are we compliant?’ to ‘Are we resilient?’

To guide board conversations effectively, Passeca coaches GRC leaders to implement three reporting shifts:

  • Stop reporting control completion percentages. Boards do not need to know that 247 of 251 controls are green. Lead with the exceptions, and explain what those open gaps represent.
  • Translate metrics into business language. Statement A: “Twelve critical third parties have no tested exit plan.” Statement B: “Our TPRM completion rate is 85%.” Statement A provides immediate, actionable business clarity.
  • Bring scenarios, not snapshots. Frame board discussions around operational reality: “If our top critical vendor fails on Monday, what happens by Tuesday?” Scenario planning positions leadership to make strategic decisions rather than audit spreadsheet rows.

Scale your DORA and NIS2 compliance with Hyperproof

Passeca leverages Hyperproof to streamline client obligations under DORA, NIS2, and overlapping global frameworks. By utilizing Hierarchical Scopes to model complex organizational structures and Hyperproof TPRM to automate third-party risk assessments and document reviews, lean GRC teams can eliminate spreadsheet chaos and build continuous operational resilience.

Request a demo to see how Hyperproof can help your team automate vendor risk management and simplify multi-framework compliance. 

Ready to see Hyperproof in action?

G2Crowd Leader Enterprise
G2Crowd Leader Mid-Market
G2Crowd High Performer Enteprise
G2Crowd Momentum Leader
G2Crowd Users Love Us