Michael Aim
Founder & CEO
Three texts, the same teams
Europe built its cyber resilience in three pieces. NIS2 targets essential and important entities across eighteen critical sectors: a directive, hence national transposition, whose French version is so late that the Commission referred France to the Court of Justice on 9 July. DORA targets financial entities, banks, insurers, asset managers: a regulation, applicable as such since 17 January 2025, supervised in France by the ACPR. The CRA targets products: any hardware or software with digital elements placed on the European market, with a first binding deadline on 11 September 2026, the notification of actively exploited vulnerabilities, and the Commission has just published its first implementation guidance.
Seen from Brussels, three distinct scopes. Seen from inside a group, the same people: the CISO, the compliance team, the risk department, often the same providers. A bank that builds its own applications falls under DORA for its arrangement, under the CRA for its products, and its group may include NIS2 subsidiaries. The law even provides the articulation: for financial entities, DORA takes precedence over NIS2 as the sector-specific text. Provided you know precisely who, within the group, falls under what.
What the three texts require in common
Stripped of their own vocabulary, the three texts demand the same base. Named governance: management bodies are responsible, personally under NIS2 and DORA, for approving and overseeing the arrangement. Documented ICT risk management: identify assets, assess threats, treat gaps. An incident process: detect, qualify, notify, learn. And third-party control: the supply chain in NIS2, DORA's register of ICT providers, submitted to supervisors since April 2025, the component chain in the CRA.
The real differences lie in deadlines and counters. A major incident is notified to the national authority under NIS2 (early warning within 24 hours, notification within 72), to the financial supervisor under DORA with its own harmonised templates, and to ENISA under the CRA for an actively exploited product vulnerability, within 24 hours. Three forms, three clocks, one real incident.
The trap of three parallel projects
Silo treatment does its most concrete damage here. Three compliance projects build three diverging asset inventories, three risk maps on incompatible scales, and three notification procedures nobody can tell apart at 2 a.m. when the incident is real and all three clocks are running.
This is the unforgiving test: a significant incident at a financial player that also ships software can simultaneously trigger a DORA notification to the supervisor and a CRA notification to ENISA, while the group's subsidiaries wonder about their NIS2 obligations. Organisations that have rehearsed this scenario on a unified arrangement execute it; the others discover it the hard way.
One measured base, three regulatory views
The methodological answer is the one we described for regulatory stacking in general: separate the base, measured once, from the regulatory views, declined per text. A cyber-resilience maturity diagnostic assesses the common capabilities, governance, risks, incidents, third parties, testing, on a homogeneous scale; each criterion is mapped to the texts it serves, and the three compliances read as three projections of the same baseline.
This crossing makes the useful collisions visible: a unified incident process, with its qualification thresholds and its directory of counters, advances all three texts at once. A well-built third-party register serves DORA today and NIS2's supply chain tomorrow. And a common risk language, ISO 27005 for instance, keeps each text from reinventing its own severity scale.
Where to start before 11 September
The CRA's 11 September deadline is the right trigger, because it is near, binding and operational. Three moves in order: clarify who, within the group, falls under which text, entity by entity and product by product. Unify the notification process, one internal procedure, three exit counters, named and reachable owners. Then measure the base's maturity and convert the gaps into a dated action plan, prioritising what serves all three texts at once.
The calendar will not stop there: the CRA's main obligations arrive in December 2027, the French Resilience law will eventually pass, DORA keeps raising the bar on testing. Organisations steering this trio from a single diagnostic will absorb each new step. The others will restart a project at every deadline.