Back to Blog
Regulation 19 August 2026 · 6 min read

DORA and NIS2 in Plain English, What It Actually Means If You Supply Into Regulated Sectors

You do not have to be a bank or an energy company for these regulations to reach you. If a regulated organisation depends on your business, its obligations become your obligations too.

Every few months we get a version of the same phone call. A manufacturing SME, or an IT support firm, or a small logistics provider, has just been sent a security questionnaire by one of their bigger customers. It asks about incident response plans, third party risk registers, and business continuity testing. The question we get asked back is always the same. We are not a financial institution and we are not critical infrastructure, so why is this landing on our desk.

The honest answer is that DORA and NIS2 were both built around a simple idea. A regulated organisation is only as resilient as the suppliers it depends on. Rather than trying to regulate every supplier directly, both frameworks instead require the regulated organisation to push resilience requirements down through its supply chain. If you supply software, IT services, hosting, logistics, or almost anything else to a bank, an insurer, an energy provider, a hospital trust, or increasingly a large enough business in a regulated sector, some version of their obligation is now flowing to you contractually, even though the regulation itself was never written with your business in mind.

DORA, in one paragraph

The Digital Operational Resilience Act applies directly to EU financial entities, banks, insurers, investment firms, and the like, and to the critical ICT third parties that serve them. It requires those financial entities to manage ICT risk formally, test their systems against realistic disruption scenarios, report major incidents on a strict timeline, and maintain a full register of their ICT third party providers. That last point is where suppliers get pulled in. A financial entity subject to DORA is required to assess and monitor the risk each of its suppliers presents, which in practice means contract clauses covering security controls, audit rights, incident notification, and exit planning. If your customer is a UK or EU financial services business, expect these clauses to start appearing in contract renewals even though DORA itself is an EU regulation.

NIS2, in one paragraph

The Networks and Information Systems Directive, in its second iteration, widens the net further. It covers essential and important entities across energy, transport, health, water, digital infrastructure, and several other sectors, and it explicitly makes supply chain security part of what those entities must manage. An organisation in scope has to assess the cyber security practices of its suppliers as part of its own risk management, again pushing the requirement downward through contracts rather than through direct regulation of every supplier. The UK is not bound by NIS2 directly, but UK businesses that supply into EU operations, or into UK organisations who themselves supply into the EU, are seeing the same pressure arrive through the same route, contracts and questionnaires rather than legislation.

What this looks like in practice

For most of the SMEs we work with, this does not arrive as a letter from a regulator. It arrives as a longer, more technical version of the vendor security questionnaire they are used to, sometimes with a contractual right for the customer to audit their controls, and sometimes with a requirement to notify the customer of a security incident within a specific number of hours rather than whenever is convenient. Businesses that cannot answer these questionnaires with any confidence tend to lose the deal, or lose negotiating leverage on price, well before anyone gets as far as talking about an audit.

Where to actually start

You do not need a compliance department to respond well to this. Three things move the needle more than anything else. First, know what you would say if a customer asked you to describe your incident response plan today, in writing, not from memory. Second, have an honest, current picture of where your real risk sits, not a document written two years ago and never revisited. Third, be able to show that your controls have actually been tested, not just designed. That third point is where most SMEs fall down, because a policy document proves you wrote something, not that it works under pressure.

This is deliberately not legal advice, and if a specific contract clause is asking you to commit to something specific, it is worth having that reviewed properly. What we can tell you from direct experience is that the businesses who handle these questionnaires calmly are almost always the ones who already treat risk assessment as a live, ongoing exercise rather than a box that gets ticked once a year.

Not sure how your business would answer that questionnaire

Our Supplier Assurance and Risk Assessment services exist for exactly this situation, a clear, honest picture of where you stand and what to fix first.