DORA
Digital Operational Resilience Act, Règlement (UE) 2022/2554
Règlement européen sur la résilience opérationnelle numérique du secteur financier. Applicable depuis le 17 janvier 2025, avec TLPT en 2026.
- Banking
- Finance & VC
Network and Information Security 2, Directive (EU) 2022/2555
EU cybersecurity directive in force since October 2024. Expands scope to SaaS, datacenters, transport, food industry.
NIS2 (directive 2022/2555) is the second European cybersecurity framework, replacing the 2016 NIS directive. It entered into application on 17 October 2024 and was transposed into French law by the law of 21 November 2024.
Goal: harmonize and strengthen the level of cybersecurity in the EU by imposing on entities identified as "essential" or "important" obligations on risk management, incident notification, and governance, with personal liability of executives in case of breach.
The French reference authority is ANSSI (National Information Systems Security Agency). It receives declarations and incident notifications, and conducts controls.
The scope is defined by Annexes I (essential entities) and II (important entities) of the directive. In summary:
Thresholds: ≥ 50 employees OR ≥ €10m revenue is enough to fall under "important entity". Beyond 250 employees or €50m revenue, you become "essential entity" with a stricter control regime.
Important: declaration to ANSSI is self-declarative. No notification is sent by the authority, it is up to the entity to identify itself and declare. Absence of declaration is itself an offense.
Applicable since 17 October 2024. Transposed into French law in November 2024. ANSSI self-declaration portal open; targeted controls from 2026.
Sanctions are both administrative and personal:
Article 21 of the directive lists 10 categories of minimum technical and organizational measures. In software translation:
Digital Operational Resilience Act, Règlement (UE) 2022/2554
Règlement européen sur la résilience opérationnelle numérique du secteur financier. Applicable depuis le 17 janvier 2025, avec TLPT en 2026.
Règlement (UE) 2024/1689 sur l'intelligence artificielle
Premier cadre horizontal mondial de régulation de l'IA. Obligations IA haut risque applicables le 2 août 2026.
Applicable depuis octobre 2024, la directive NIS2 commence à mordre en 2026. Les éditeurs SaaS classés « entité importante » font face à des exigences techniques nouvelles.
Quand NIS2 demande un logiciel sur-mesure, nous le livrons en quelques semaines, 3× moins cher qu'un éditeur historique.