← Tutte le news
ARTICOLO
8 giugno 2026

NIS2 & DORA: what EU businesses need to know in 2026

The NIS2 Directive and DORA regulation impose new obligations on EU businesses. Here is what you need to do and how Altovar can help.

As of 2025, the NIS2 Directive and DORA (Digital Operational Resilience Act) are in full effect. Together, these regulations impose significant obligations on a broad range of EU businesses — from critical infrastructure operators to financial institutions and their IT service providers.

What NIS2 requires

NIS2 expands the scope of the original NIS Directive to include more sectors and introduces stricter security requirements: risk management, incident reporting, supply chain security, and board-level accountability for cybersecurity.

What DORA requires

DORA is specific to the financial sector. It mandates operational resilience testing, ICT risk management, incident classification and reporting, and strict oversight of third-party IT providers.

How Altovar helps

Our Auris Comply module provides the audit trail, access control, and incident logging required by both directives. Our EU-sovereign infrastructure ensures that data residency requirements are met by design.