A directive, not a regulation
A directive, not a regulation
This distinction determines how you should organise your entire compliance effort, so it is worth being precise about it.
A regulation applies directly and identically in every member state. DORA is a regulation: a bank in Dublin and a bank in Athens read the same text and owe the same duties.
A directive binds member states as to the result to be achieved, and leaves them to legislate the means. NIS2 is a directive. What binds your organisation is not Directive (EU) 2022/2555 — it is the national law that transposed it.
What follows in practice
Some things are fixed by the directive and will not differ:
- The ten minimum measures of article 21(2)
- The reporting deadlines of article 23 — 24 hours, 72 hours, one month
- The management body duties of article 20
- The fine ceilings of article 34
Other things are national and differ substantially: the registration procedure and portal, whether scope was extended below the directive's thresholds, whether regional and local public bodies are covered, the intensity of supervision, and how an authority calibrates a fine within the ceilings.
So: build the security programme once, centrally. Treat registration, supervision and reporting channels as a per-country matter with a named owner. Groups that invert this — one compliance relationship, six security programmes — spend far more and end up less defensible.