DORA, NIS2 & DESC ISR:
What applies to your organisation in 2026
Three of the most impactful cybersecurity and operational resilience regulations of 2026 — DORA for financial sector ICT, NIS2 for critical infrastructure and digital services, and DESC ISR for Dubai/UAE operations. Most organisations don't know if they're directly or indirectly subject to all three.
Digital Operational Resilience Act (DORA)
EU Regulation 2022/2554 · In force: 17 January 2025
~22,000
EU financial entities in scope
2%
Max fine (financial entities)
of global annual turnover
4 hrs
ICT incident first alert
for significant incidents
3 yrs
TLPT testing cycle
for significant entities
What is DORA?
DORA is the EU's landmark regulation requiring financial entities and their critical ICT service providers to implement operational resilience frameworks. Unlike previous guidance, DORA is directly applicable law — not a directive — meaning it takes effect in all EU member states without national transposition.
DORA is particularly significant because it creates indirect obligations for any SaaS, cloud, or managed service provider that serves EU banks, payment institutions, investment firms, or insurance companies — regardless of where the provider is incorporated.
Who DORA applies to
Directly in scope
- Banks and credit institutions
- Payment and e-money institutions
- Investment firms and fund managers
- Insurance and reinsurance undertakings
- Crypto-asset service providers (CASPs)
- Crowdfunding and peer-to-peer platforms
- Central securities depositories
- Trade repositories
Indirectly in scope (ICT third parties)
- SaaS platforms serving EU banks
- Cloud providers (AWS, Azure, GCP and alternatives) used by financial entities
- Core banking software vendors
- Fintech data and analytics providers
- Managed security service providers (MSSPs)
- Business process outsourcing (BPO) providers
- Payment gateway and processing vendors
- Critical ICT providers designated by ESAs
DORA's 5 pillars
ICT Risk Management
Formal framework for identifying, classifying, and managing ICT risks. Requires risk appetite statement, threat intelligence integration, and board-level accountability.
ICT-Related Incident Reporting
Major incidents must be reported to the competent authority: initial notification within 4 hours, intermediate within 72 hours, final within 1 month. Significant cyber threats must also be voluntarily notified.
Digital Operational Resilience Testing
Annual basic testing (vulnerability assessments, scenario testing) for all in-scope entities. Significant entities must conduct Threat-Led Penetration Testing (TLPT) every 3 years using authorised red teamers.
ICT Third-Party Risk Management
Comprehensive due diligence, contractual requirements, and ongoing monitoring of ICT suppliers. Contracts must include audit rights, incident notification obligations, exit strategies, and concentration risk disclosures.
Information and Intelligence Sharing
Voluntary sharing of cyber threat intelligence between financial entities through trusted platforms. Facilitates sector-wide situational awareness.
DORA — Frequently Asked Questions
Does DORA apply to my company if we're based outside the EU?
What is the difference between DORA and NIS2 for financial entities?
What is Threat-Led Penetration Testing (TLPT) under DORA?
How does DORA affect SaaS companies serving banks?
What are the DORA penalties for non-compliance?
Not sure if DORA applies to your organisation?
Our compliance team scopes applicability in a 30-minute call — no charge.
NIS2 Directive
EU Directive 2022/2555 · Transposition deadline: 17 October 2024 · Replaces NIS1 (2016)
18
Sectors covered
€10M
Max fine (essential entities)
or 2% global turnover
24 hrs
Early warning deadline
after incident awareness
72 hrs
Incident notification
full notification
What is NIS2?
NIS2 is the EU's broadest cybersecurity directive — it significantly expands the scope of the original NIS Directive (2016) to cover more sectors, impose stricter requirements, and introduce personal liability for senior management. Member states must transpose NIS2 into national law, but the core obligations are harmonised across the EU.
Unlike DORA (which is financial-sector specific), NIS2 covers 18 sectors and explicitly includes cloud computing services, managed service providers, and digital infrastructure. This means many B2B technology companies that weren't subject to NIS1 are now within scope.
Essential vs Important entities
| Dimension | Essential Entities | Important Entities |
|---|---|---|
| Size threshold | 250+ employees or €50M+ revenue | 50+ employees or €10M+ revenue |
| Max fine | €10M or 2% global turnover | €7M or 1.4% global turnover |
| Supervision | Ex-ante (proactive, ongoing) | Ex-post (reactive, after incident) |
| Examples | Energy operators, banks, hospitals, digital infra, public admin | MSPs, postal services, food producers, manufacturers, research |
18 sectors in scope
Annex I — Highly Critical (Essential)
- •Energy (electricity, oil, gas, hydrogen)
- •Transport (air, rail, water, road)
- •Banking and financial market infrastructure
- •Health (hospitals, labs, pharma manufacturing)
- •Drinking water and wastewater
- •Digital infrastructure (DNS, TLD, IXPs, cloud, data centres)
- •ICT service management (MSPs, MSSPs)
- •Public administration
- •Space
Annex II — Other Critical (Important)
- •Postal and courier services
- •Waste management
- •Chemical production and distribution
- •Food production and processing
- •Manufacturing (medical devices, electronics, machinery, motor vehicles)
- •Digital providers (marketplaces, search engines, social networks)
- •Research organisations
NIS2 key obligations (Article 21)
Risk management measures
Policies on risk analysis, information system security, incident handling, business continuity, supply chain security, acquisition and development, cybersecurity hygiene, and cryptography.
Incident reporting
24-hour early warning → 72-hour notification → 1-month final report. For significant incidents affecting service continuity or causing substantial damage.
Management liability
Governing bodies (Article 20) must approve cybersecurity risk measures, oversee implementation, and can be held personally liable for infringements. Management must undergo regular cybersecurity training.
Supply chain security
Entities must address risks in supplier relationships. ENISA conducts coordinated supply chain risk assessments for critical sectors. Contracts must include security requirements for vendors.
Cross-border cooperation
Mandatory reporting to national CSIRT. EU-level information sharing through the CyCLONe network for large-scale incidents. Coordinated vulnerability disclosure obligations.
NIS2 — Frequently Asked Questions
Is my company an essential or important entity under NIS2?
How does NIS2 affect managed service providers (MSPs)?
Does NIS2 apply to companies outside the EU?
What are the NIS2 incident reporting timelines?
How does NIS2 differ from GDPR?
Not sure if NIS2 applies to your organisation?
Our compliance team scopes applicability in a 30-minute call — no charge.
DESC Information Security Regulation (ISR)
Dubai Electronic Security Center (DESC) · ISR v3.0 · Jurisdiction: Emirate of Dubai
2014
DESC established
Dubai government mandate
10
ISR domains
governance to continuity
6+
Standards maintained
ISR, IoT, ICS, Cloud, SOC, DC
2026
Dubai Cyber Strategy
target maturity year
What is DESC?
The Dubai Electronic Security Center (DESC) is the cybersecurity regulatory authority for the Emirate of Dubai. DESC maintains the Information Security Regulation (ISR), a comprehensive framework covering governance, operations, cloud, OT/ICS, SOC services, and digital infrastructure security for Dubai government entities and their supply chains.
While DESC ISR is directly mandatory only for Dubai government and semi-government entities, its reach extends significantly into the private sector through procurement requirements. Any company providing IT, cloud, security, or managed services to Dubai government entities must increasingly demonstrate DESC ISR compliance or alignment.
DESC regulatory portfolio
Information Security Regulation (ISR v3.0)
Core standardCore framework: 10 domains covering governance, asset management, HR security, physical security, access control, operations, incident management, and compliance.
Cloud Security Standard
CloudRequirements for cloud service providers serving Dubai government entities. Covers data sovereignty, shared responsibility, and multi-cloud governance.
IoT Security Standard
IoTSecurity requirements for IoT devices and platforms deployed in Dubai government contexts, including smart city infrastructure.
ICS / OT Security Standard
OT / ICSCybersecurity requirements for industrial control systems and operational technology in government-aligned critical infrastructure.
SOC Security Standard
SOCRequirements for Security Operations Centers providing services to Dubai government — incident detection, response, and reporting standards.
Data Centre Security Standard
Data CentrePhysical and logical security requirements for data centres processing Dubai government data — including Tier classification, access controls, and resilience.
DESC ISR — 10 domains
Information Security Governance
Asset Management
Human Resources Security
Physical & Environmental Security
Communications & Operations
Access Control
IS Acquisition & Development
Incident Management
Business Continuity
Compliance
DESC ISR vs ISO 27001
| Dimension | DESC ISR | ISO 27001:2022 |
|---|---|---|
| Jurisdiction | Emirate of Dubai / UAE | International (170+ countries) |
| Authority | Dubai Electronic Security Center | ISO / IEC |
| Mandatory for | Dubai govt + supply chain | Voluntary (procurement-driven) |
| Certification | DESC ISR certification scheme | ISO 27001 certificate (accredited CB) |
| Cloud coverage | Dedicated Cloud Security Standard | Annex A controls + ISO 27017 |
| OT/ICS | Dedicated ICS/OT Security Standard | Requires ISO 27001 + IEC 62443 |
| SOC services | Dedicated SOC Security Standard | No dedicated SOC standard |
| Alignment | Aligned with ISO 27001 framework | Global benchmark |
DESC ISR — Frequently Asked Questions
Does DESC ISR apply to private companies in Dubai?
How does DESC ISR relate to ISO 27001?
What is the DESC ISR certification process?
Does DESC apply to cloud service providers operating in or serving Dubai?
How does DESC fit into Dubai's 2023–2026 Cyber Security Strategy?
Not sure if DESC ISR applies to your organisation?
Our compliance team scopes applicability in a 30-minute call — no charge.
DORA · NIS2 · DESC ISR — Framework Comparison
Key differences and overlaps across the three frameworks — plus how they relate to ISO 27001.
| Dimension | DORA | NIS2 | DESC ISR | ISO 27001 |
|---|---|---|---|---|
| Type | EU Regulation | EU Directive | UAE Regulation | International Standard |
| Authority | ESAs (EBA, ESMA, EIOPA) | National authorities / ENISA | Dubai Electronic Security Center | ISO / IEC |
| Geography | EU + third-party ICT | EU (+ digital services) | Emirate of Dubai / UAE | Global (voluntary) |
| Primary scope | Financial sector + ICT providers | 18 sectors, MSPs, cloud, OT | Dubai govt + supply chain | All organisations |
| In force / deadline | Jan 17, 2025 | Oct 17, 2024 (transposition) | Ongoing (ISR v3.0) | Current: 2022 edition |
| Incident reporting | 4h / 72h / 1 month | 24h / 72h / 1 month | Per ISR incident procedure | Per ISMS procedure |
| Max fine | 2% global turnover | €10M or 2% (essential) | Regulatory sanctions | No fines (private standard) |
| Management liability | Yes — fines up to €1M | Yes — Article 20 | Yes — governance domain | No formal liability |
| Third-party / supply chain | Core pillar (contractual reqs) | Article 21(d) obligation | Procurement requirement | Annex A controls |
| OT / ICS | Limited (fintech OT) | Energy, transport, water OT | Dedicated ICS standard | Requires + IEC 62443 |
| AI governance | Limited (ICT risk framing) | Emerging (ICT risk) | Evolving | Requires + ISO 42001 |
| Overlaps with | NIS2, ISO 27001, NIST CSF | DORA, ISO 27001, IEC 62443 | ISO 27001, NIST CSF | All — foundation layer |
Framework relationships & overlaps
SG2 helps you navigate DORA, NIS2, and DESC ISR
From applicability scoping to evidence collection, gap assessment, control implementation, and audit readiness — SG2 provides end-to-end compliance advisory across all three frameworks.
DORA Advisory
- ICT risk framework design
- TLPT scoping and execution
- Third-party contract review
- Incident reporting runbooks
- Regulatory gap assessment
NIS2 Advisory
- Entity classification (essential/important)
- Article 21 control mapping
- Supply chain security programme
- Management awareness training
- National CSIRT reporting setup
DESC ISR Advisory
- ISR v3.0 gap assessment
- 10-domain control implementation
- DESC Cloud Security alignment
- DESC certification readiness
- OT / SOC standards support
Get a free 30-minute compliance scoping call
Tell us about your organisation and we'll confirm which of DORA, NIS2, and DESC ISR apply — and what your fastest path to compliance looks like.
Message received
We'll review your details and get back to you within one business day.