Regulatory Intelligence · 2026

DORA, NIS2 & DESC ISR:
What applies to your organisation in 2026

Three of the most impactful cybersecurity and operational resilience regulations of 2026 — DORA for financial sector ICT, NIS2 for critical infrastructure and digital services, and DESC ISR for Dubai/UAE operations. Most organisations don't know if they're directly or indirectly subject to all three.

EU Regulation · Financial Sector

Digital Operational Resilience Act (DORA)

EU Regulation 2022/2554 · In force: 17 January 2025

~22,000

EU financial entities in scope

2%

Max fine (financial entities)

of global annual turnover

4 hrs

ICT incident first alert

for significant incidents

3 yrs

TLPT testing cycle

for significant entities

What is DORA?

DORA is the EU's landmark regulation requiring financial entities and their critical ICT service providers to implement operational resilience frameworks. Unlike previous guidance, DORA is directly applicable law — not a directive — meaning it takes effect in all EU member states without national transposition.

DORA is particularly significant because it creates indirect obligations for any SaaS, cloud, or managed service provider that serves EU banks, payment institutions, investment firms, or insurance companies — regardless of where the provider is incorporated.

Who DORA applies to

Directly in scope

  • Banks and credit institutions
  • Payment and e-money institutions
  • Investment firms and fund managers
  • Insurance and reinsurance undertakings
  • Crypto-asset service providers (CASPs)
  • Crowdfunding and peer-to-peer platforms
  • Central securities depositories
  • Trade repositories

Indirectly in scope (ICT third parties)

  • SaaS platforms serving EU banks
  • Cloud providers (AWS, Azure, GCP and alternatives) used by financial entities
  • Core banking software vendors
  • Fintech data and analytics providers
  • Managed security service providers (MSSPs)
  • Business process outsourcing (BPO) providers
  • Payment gateway and processing vendors
  • Critical ICT providers designated by ESAs

DORA's 5 pillars

1

ICT Risk Management

Formal framework for identifying, classifying, and managing ICT risks. Requires risk appetite statement, threat intelligence integration, and board-level accountability.

2

ICT-Related Incident Reporting

Major incidents must be reported to the competent authority: initial notification within 4 hours, intermediate within 72 hours, final within 1 month. Significant cyber threats must also be voluntarily notified.

3

Digital Operational Resilience Testing

Annual basic testing (vulnerability assessments, scenario testing) for all in-scope entities. Significant entities must conduct Threat-Led Penetration Testing (TLPT) every 3 years using authorised red teamers.

4

ICT Third-Party Risk Management

Comprehensive due diligence, contractual requirements, and ongoing monitoring of ICT suppliers. Contracts must include audit rights, incident notification obligations, exit strategies, and concentration risk disclosures.

5

Information and Intelligence Sharing

Voluntary sharing of cyber threat intelligence between financial entities through trusted platforms. Facilitates sector-wide situational awareness.

DORA — Frequently Asked Questions

Does DORA apply to my company if we're based outside the EU?
Yes — DORA has extraterritorial reach for ICT third-party service providers. If you provide ICT services to EU-regulated financial entities, you are subject to DORA's ICT third-party provisions regardless of where your company is incorporated. EU supervisory authorities can also designate non-EU ICT providers as "critical" and directly oversee them.
What is the difference between DORA and NIS2 for financial entities?
Both apply to financial entities, but DORA takes precedence under the lex specialis principle. DORA's more specific requirements on ICT resilience, TLPT testing, and third-party risk management override equivalent NIS2 provisions for financial sector entities. However, financial sector ICT providers must still comply with NIS2 for their own classification as digital service providers.
What is Threat-Led Penetration Testing (TLPT) under DORA?
TLPT is mandatory red-team testing based on real threat intelligence, required for significant financial entities every 3 years. It covers production systems and must be conducted by certified TLPT providers. DORA's TLPT framework is aligned with TIBER-EU. The scope must include critical or important functions and at least three internal target threat intelligence providers.
How does DORA affect SaaS companies serving banks?
SaaS vendors serving EU financial institutions are classified as ICT third-party service providers under DORA. Your customers will contractually require: mandatory incident notification within 4 hours, audit rights and regulatory access, business continuity documentation, exit strategy provisions, and concentration risk disclosures. Non-DORA-aligned vendors risk losing financial-sector contracts in 2025.
What are the DORA penalties for non-compliance?
For financial entities: fines up to 2% of global annual turnover. For individual management: fines up to €1M. For critical ICT third-party service providers designated by ESAs: periodic penalty payments of 1% of average daily worldwide turnover until compliant. Member state competent authorities also retain the power to temporarily prohibit products or services.

Not sure if DORA applies to your organisation?

Our compliance team scopes applicability in a 30-minute call — no charge.

Book a scoping call
EU Directive · Critical Infrastructure & Digital Services

NIS2 Directive

EU Directive 2022/2555 · Transposition deadline: 17 October 2024 · Replaces NIS1 (2016)

18

Sectors covered

€10M

Max fine (essential entities)

or 2% global turnover

24 hrs

Early warning deadline

after incident awareness

72 hrs

Incident notification

full notification

What is NIS2?

NIS2 is the EU's broadest cybersecurity directive — it significantly expands the scope of the original NIS Directive (2016) to cover more sectors, impose stricter requirements, and introduce personal liability for senior management. Member states must transpose NIS2 into national law, but the core obligations are harmonised across the EU.

Unlike DORA (which is financial-sector specific), NIS2 covers 18 sectors and explicitly includes cloud computing services, managed service providers, and digital infrastructure. This means many B2B technology companies that weren't subject to NIS1 are now within scope.

Essential vs Important entities

DimensionEssential EntitiesImportant Entities
Size threshold250+ employees or €50M+ revenue50+ employees or €10M+ revenue
Max fine€10M or 2% global turnover€7M or 1.4% global turnover
SupervisionEx-ante (proactive, ongoing)Ex-post (reactive, after incident)
ExamplesEnergy operators, banks, hospitals, digital infra, public adminMSPs, postal services, food producers, manufacturers, research

18 sectors in scope

Annex I — Highly Critical (Essential)

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructure
  • Health (hospitals, labs, pharma manufacturing)
  • Drinking water and wastewater
  • Digital infrastructure (DNS, TLD, IXPs, cloud, data centres)
  • ICT service management (MSPs, MSSPs)
  • Public administration
  • Space

Annex II — Other Critical (Important)

  • Postal and courier services
  • Waste management
  • Chemical production and distribution
  • Food production and processing
  • Manufacturing (medical devices, electronics, machinery, motor vehicles)
  • Digital providers (marketplaces, search engines, social networks)
  • Research organisations

NIS2 key obligations (Article 21)

Risk management measures

Policies on risk analysis, information system security, incident handling, business continuity, supply chain security, acquisition and development, cybersecurity hygiene, and cryptography.

Incident reporting

24-hour early warning → 72-hour notification → 1-month final report. For significant incidents affecting service continuity or causing substantial damage.

Management liability

Governing bodies (Article 20) must approve cybersecurity risk measures, oversee implementation, and can be held personally liable for infringements. Management must undergo regular cybersecurity training.

Supply chain security

Entities must address risks in supplier relationships. ENISA conducts coordinated supply chain risk assessments for critical sectors. Contracts must include security requirements for vendors.

Cross-border cooperation

Mandatory reporting to national CSIRT. EU-level information sharing through the CyCLONe network for large-scale incidents. Coordinated vulnerability disclosure obligations.

NIS2 — Frequently Asked Questions

Is my company an essential or important entity under NIS2?
Essential entities are large organisations in critical sectors (energy, transport, banking, health, drinking water, digital infrastructure, public administration, space) with 250+ employees or €50M+ revenue. Important entities include medium-to-large organisations in additional sectors plus all MSPs and managed security service providers regardless of size. If you provide cloud services, DNS, or ICT management services in the EU, you are almost certainly in scope.
How does NIS2 affect managed service providers (MSPs)?
NIS2 explicitly names MSPs and MSSPs as "important entities" under ICT service management (Annex I). This means full NIS2 obligations apply — risk management framework, 24/72-hour incident reporting, supply chain security, and management training and liability. MSPs are also subject to ex-ante supervision in most member states, and their downstream customers may require NIS2 compliance evidence as a procurement condition.
Does NIS2 apply to companies outside the EU?
NIS2 applies to entities providing services in the EU. Non-EU digital service providers (cloud, online marketplaces, search engines, social networks) that offer services to EU users must designate an EU representative and comply with NIS2 if they meet size thresholds. MSPs and cloud providers serving EU critical infrastructure entities are also effectively subject to NIS2 requirements via supply chain obligations.
What are the NIS2 incident reporting timelines?
Within 24 hours: early warning to national CSIRT indicating whether the incident is suspected to be the result of unlawful or malicious acts. Within 72 hours: full incident notification including initial assessment of severity. Within 1 month: a final report including root cause analysis, implemented mitigation measures, and cross-border impact. For ongoing incidents, an intermediate progress report is due at 72 hours.
How does NIS2 differ from GDPR?
GDPR focuses on personal data protection — lawful processing, data subject rights, and breach notification for personal data incidents. NIS2 focuses on cybersecurity resilience — protecting network and information systems, with incident reporting triggered by service disruption or significant cyber threat, regardless of whether personal data is involved. Both can apply simultaneously, and a security incident that also involves personal data breach triggers obligations under both.

Not sure if NIS2 applies to your organisation?

Our compliance team scopes applicability in a 30-minute call — no charge.

Book a scoping call
UAE Regulation · Dubai / GCC

DESC Information Security Regulation (ISR)

Dubai Electronic Security Center (DESC) · ISR v3.0 · Jurisdiction: Emirate of Dubai

2014

DESC established

Dubai government mandate

10

ISR domains

governance to continuity

6+

Standards maintained

ISR, IoT, ICS, Cloud, SOC, DC

2026

Dubai Cyber Strategy

target maturity year

What is DESC?

The Dubai Electronic Security Center (DESC) is the cybersecurity regulatory authority for the Emirate of Dubai. DESC maintains the Information Security Regulation (ISR), a comprehensive framework covering governance, operations, cloud, OT/ICS, SOC services, and digital infrastructure security for Dubai government entities and their supply chains.

While DESC ISR is directly mandatory only for Dubai government and semi-government entities, its reach extends significantly into the private sector through procurement requirements. Any company providing IT, cloud, security, or managed services to Dubai government entities must increasingly demonstrate DESC ISR compliance or alignment.

DESC regulatory portfolio

Information Security Regulation (ISR v3.0)

Core standard

Core framework: 10 domains covering governance, asset management, HR security, physical security, access control, operations, incident management, and compliance.

Cloud Security Standard

Cloud

Requirements for cloud service providers serving Dubai government entities. Covers data sovereignty, shared responsibility, and multi-cloud governance.

IoT Security Standard

IoT

Security requirements for IoT devices and platforms deployed in Dubai government contexts, including smart city infrastructure.

ICS / OT Security Standard

OT / ICS

Cybersecurity requirements for industrial control systems and operational technology in government-aligned critical infrastructure.

SOC Security Standard

SOC

Requirements for Security Operations Centers providing services to Dubai government — incident detection, response, and reporting standards.

Data Centre Security Standard

Data Centre

Physical and logical security requirements for data centres processing Dubai government data — including Tier classification, access controls, and resilience.

DESC ISR — 10 domains

01

Information Security Governance

02

Asset Management

03

Human Resources Security

04

Physical & Environmental Security

05

Communications & Operations

06

Access Control

07

IS Acquisition & Development

08

Incident Management

09

Business Continuity

10

Compliance

DESC ISR vs ISO 27001

DimensionDESC ISRISO 27001:2022
JurisdictionEmirate of Dubai / UAEInternational (170+ countries)
AuthorityDubai Electronic Security CenterISO / IEC
Mandatory forDubai govt + supply chainVoluntary (procurement-driven)
CertificationDESC ISR certification schemeISO 27001 certificate (accredited CB)
Cloud coverageDedicated Cloud Security StandardAnnex A controls + ISO 27017
OT/ICSDedicated ICS/OT Security StandardRequires ISO 27001 + IEC 62443
SOC servicesDedicated SOC Security StandardNo dedicated SOC standard
AlignmentAligned with ISO 27001 frameworkGlobal benchmark

DESC ISR — Frequently Asked Questions

Does DESC ISR apply to private companies in Dubai?
Directly, DESC ISR is mandatory for Dubai government entities and semi-government organisations. However, private companies — particularly cloud providers, MSPs, SOC operators, and ICT vendors — are increasingly required to demonstrate DESC ISR compliance as a condition of government procurement. Any supplier providing IT, security, or managed services to Dubai government entities should assess DESC ISR requirements proactively.
How does DESC ISR relate to ISO 27001?
DESC ISR is aligned with ISO 27001 and shares a similar domain structure. ISO 27001 certification provides a strong foundation but does not substitute for DESC ISR compliance, as DESC includes Dubai-specific controls, additional standards (Cloud, IoT, OT, SOC, Data Centre), and a separate DESC certification scheme. Organisations with ISO 27001 can expect significantly reduced effort in achieving DESC ISR compliance.
What is the DESC ISR certification process?
DESC ISR certification involves: (1) gap assessment against ISR domains, (2) implementation of required controls, (3) internal audit, (4) DESC-approved external assessment by an authorised auditor, (5) issuance of DESC ISR certificate. Certificates are periodically renewed. DESC maintains a list of approved assessment bodies. SG2 can guide organisations through the full certification journey.
Does DESC apply to cloud service providers operating in or serving Dubai?
Yes — cloud service providers serving Dubai government entities are subject to both the DESC ISR and the DESC Cloud Security Standard. This covers data sovereignty requirements (data residency in UAE or approved jurisdictions), shared responsibility model documentation, and cloud-specific security controls. Major cloud providers (AWS, Azure, GCP) have UAE regions that assist with residency requirements.
How does DESC fit into Dubai's 2023–2026 Cyber Security Strategy?
DESC is the implementing authority for the Dubai Cyber Security Strategy 2023–2026, which targets: enhanced cyber resilience for government entities, improved cyber threat intelligence sharing, expanded DESC certification coverage, and stronger supply chain security. The strategy accelerates DESC ISR adoption across the broader Dubai economy, increasing its relevance for private-sector entities in the GCC region.

Not sure if DESC ISR applies to your organisation?

Our compliance team scopes applicability in a 30-minute call — no charge.

Book a scoping call

DORA · NIS2 · DESC ISR — Framework Comparison

Key differences and overlaps across the three frameworks — plus how they relate to ISO 27001.

DimensionDORANIS2DESC ISRISO 27001
TypeEU RegulationEU DirectiveUAE RegulationInternational Standard
AuthorityESAs (EBA, ESMA, EIOPA)National authorities / ENISADubai Electronic Security CenterISO / IEC
GeographyEU + third-party ICTEU (+ digital services)Emirate of Dubai / UAEGlobal (voluntary)
Primary scopeFinancial sector + ICT providers18 sectors, MSPs, cloud, OTDubai govt + supply chainAll organisations
In force / deadlineJan 17, 2025Oct 17, 2024 (transposition)Ongoing (ISR v3.0)Current: 2022 edition
Incident reporting4h / 72h / 1 month24h / 72h / 1 monthPer ISR incident procedurePer ISMS procedure
Max fine2% global turnover€10M or 2% (essential)Regulatory sanctionsNo fines (private standard)
Management liabilityYes — fines up to €1MYes — Article 20Yes — governance domainNo formal liability
Third-party / supply chainCore pillar (contractual reqs)Article 21(d) obligationProcurement requirementAnnex A controls
OT / ICSLimited (fintech OT)Energy, transport, water OTDedicated ICS standardRequires + IEC 62443
AI governanceLimited (ICT risk framing)Emerging (ICT risk)EvolvingRequires + ISO 42001
Overlaps withNIS2, ISO 27001, NIST CSFDORA, ISO 27001, IEC 62443ISO 27001, NIST CSFAll — foundation layer

Framework relationships & overlaps

DORA ↔ NIS2— DORA takes precedence for financial entities (lex specialis). Financial sector ICT providers must comply with both.
NIS2 ↔ IEC 62443— NIS2 applies to OT-heavy sectors (energy, manufacturing, water). IEC 62443 provides the technical controls layer for OT environments.
DORA ↔ NIST CSF— DORA's 5 pillars map closely to NIST CSF functions. US-headquartered financial institutions often use NIST CSF as the internal framework to meet DORA requirements.
DESC ISR ↔ ISO 27001— DESC ISR is structurally aligned with ISO 27001. ISO 27001 certification reduces DESC ISR implementation effort significantly.
GDPR ↔ ISO 27701— ISO 27701 is the privacy extension to ISO 27001 — it provides a structured path to demonstrate GDPR and DPDP compliance accountability.
NIS2 ↔ DORA ↔ ISO 27001— ISO 27001 is the common foundation layer for both DORA and NIS2 compliance. Achieving ISO 27001 first significantly reduces the incremental effort for both regulations.
SG2 Compliance Advisory

SG2 helps you navigate DORA, NIS2, and DESC ISR

From applicability scoping to evidence collection, gap assessment, control implementation, and audit readiness — SG2 provides end-to-end compliance advisory across all three frameworks.

DORA Advisory

  • ICT risk framework design
  • TLPT scoping and execution
  • Third-party contract review
  • Incident reporting runbooks
  • Regulatory gap assessment
Learn more →

NIS2 Advisory

  • Entity classification (essential/important)
  • Article 21 control mapping
  • Supply chain security programme
  • Management awareness training
  • National CSIRT reporting setup
Learn more →

DESC ISR Advisory

  • ISR v3.0 gap assessment
  • 10-domain control implementation
  • DESC Cloud Security alignment
  • DESC certification readiness
  • OT / SOC standards support
Learn more →

Get a free 30-minute compliance scoping call

Tell us about your organisation and we'll confirm which of DORA, NIS2, and DESC ISR apply — and what your fastest path to compliance looks like.

No spam. We respond within one business day.