Reference
DORA, NIS2 and MiCA: what is actually required, and by whom
Three EU regimes get named together constantly and are rarely explained properly. These guides set out what each one obliges you to do, who has to do it, who checks, and where every member state currently stands. Written for people who are not lawyers.
Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.
Regulation (EU) 2022/2554
DORA
Digital Operational Resilience Act
One binding set of ICT resilience rules across roughly twenty categories of EU financial entity: governance the board owns, an incident clock measured in hours, resilience testing, and a Register of Information covering every ICT contract.
Read the DORA guideDirective (EU) 2022/2555
NIS2
Network and Information Security Directive
A directive, so what binds you is your member state's law and not the directive text. Ten minimum security measures, a three-stage reporting clock, personal liability for management โ and 27 national timetables that do not line up.
Read the NIS2 guideRegulation (EU) 2023/1114
MiCA
Markets in Crypto-Assets Regulation
A single EU authorisation regime for crypto, split across issuers of ordinary tokens, asset-referenced tokens and e-money tokens, plus crypto-asset service providers. Every transitional window closed on 1 July 2026.
Read the MiCA guideThe three side by side
| Regime | Legal form | Status | Who it applies to |
|---|---|---|---|
| DORA | Regulation โ directly applicable in all 27 states | Applies since 17 January 2025 | EU financial entities and their ICT providers |
| NIS2 | Directive โ binds you through national law | Transposition deadline was 17 October 2024 | 18 sectors, essential and important entities |
| MiCA | Regulation โ directly applicable in all 27 states | Fully applicable since 30 December 2024 | Crypto-asset issuers and service providers serving EU clients |
Three regimes, one demand
Strip out the sector language and the three converge. Each one pushes accountability onto the management body by name rather than onto a function. Each one runs on filing cadences to a named supervisor with clocks measured in hours rather than quarters. And each one shifts the burden of proof: the question a supervisor asks is not whether you have a policy but whether you can produce cited, dated, verifiable evidence that the control operated.
That is the part organisations consistently underestimate. Writing the policy is a project with an end date. Producing evidence that survives examination, repeatedly, on someone else's schedule, is an operating requirement that does not stop.
Common questions
What is the difference between DORA, NIS2 and MiCA?
DORA (Regulation (EU) 2022/2554) sets ICT operational resilience rules for EU financial entities and their ICT suppliers. NIS2 (Directive (EU) 2022/2555) sets cybersecurity requirements across eighteen sectors, through each member state's own implementing law. MiCA (Regulation (EU) 2023/1114) is an authorisation and conduct regime for crypto-asset issuers and service providers. DORA and MiCA are regulations and apply directly; NIS2 is a directive and only binds you through national law.
Which of the three needs national transposition?
Only NIS2. DORA and MiCA are regulations, so they apply directly and identically across all 27 member states. NIS2 is a directive, which is why its national laws arrived years apart and why three member states โ France, Ireland and Spain โ still have no law in force.
Do these three overlap for a bank?
Yes, and the overlap is resolved in your favour. DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice. MiCA, in the other direction, routes crypto-asset service providers into DORA for ICT resilience.
What do all three have in common?
Each pushes accountability onto the management body by name rather than onto a function. Each runs on filing cadences to a named supervisor with clocks measured in hours rather than quarters. And each shifts the burden of proof: the question a supervisor asks is not whether you have a policy but whether you can produce cited, dated, verifiable evidence that the control operated.
Producing the evidence is the part that does not stop
ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score โ cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.
Sources and status
These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.
Spotted something out of date? [email protected].