Reference

DORA, NIS2 and MiCA: what is actually required, and by whom

Three EU regimes get named together constantly and are rarely explained properly. These guides set out what each one obliges you to do, who has to do it, who checks, and where every member state currently stands. Written for people who are not lawyers.

Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.

The three side by side

DORA, NIS2 and MiCA compared, as at 2 August 2026
RegimeLegal formStatusWho it applies to
DORARegulation โ€” directly applicable in all 27 statesApplies since 17 January 2025EU financial entities and their ICT providers
NIS2Directive โ€” binds you through national lawTransposition deadline was 17 October 202418 sectors, essential and important entities
MiCARegulation โ€” directly applicable in all 27 statesFully applicable since 30 December 2024Crypto-asset issuers and service providers serving EU clients

Three regimes, one demand

Strip out the sector language and the three converge. Each one pushes accountability onto the management body by name rather than onto a function. Each one runs on filing cadences to a named supervisor with clocks measured in hours rather than quarters. And each one shifts the burden of proof: the question a supervisor asks is not whether you have a policy but whether you can produce cited, dated, verifiable evidence that the control operated.

That is the part organisations consistently underestimate. Writing the policy is a project with an end date. Producing evidence that survives examination, repeatedly, on someone else's schedule, is an operating requirement that does not stop.

Common questions

What is the difference between DORA, NIS2 and MiCA?

DORA (Regulation (EU) 2022/2554) sets ICT operational resilience rules for EU financial entities and their ICT suppliers. NIS2 (Directive (EU) 2022/2555) sets cybersecurity requirements across eighteen sectors, through each member state's own implementing law. MiCA (Regulation (EU) 2023/1114) is an authorisation and conduct regime for crypto-asset issuers and service providers. DORA and MiCA are regulations and apply directly; NIS2 is a directive and only binds you through national law.

Which of the three needs national transposition?

Only NIS2. DORA and MiCA are regulations, so they apply directly and identically across all 27 member states. NIS2 is a directive, which is why its national laws arrived years apart and why three member states โ€” France, Ireland and Spain โ€” still have no law in force.

Do these three overlap for a bank?

Yes, and the overlap is resolved in your favour. DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice. MiCA, in the other direction, routes crypto-asset service providers into DORA for ICT resilience.

What do all three have in common?

Each pushes accountability onto the management body by name rather than onto a function. Each runs on filing cadences to a named supervisor with clocks measured in hours rather than quarters. And each shifts the burden of proof: the question a supervisor asks is not whether you have a policy but whether you can produce cited, dated, verifiable evidence that the control operated.

Producing the evidence is the part that does not stop

ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score โ€” cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.

Sources and status

These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.

Spotted something out of date? [email protected].