Access to EU financial clients
Banks and insurers push DORA testing and evidence duties to suppliers. Gaps can cost contracts.
DORA and NIS2 make management bodies directly accountable for resilience. Summit delivers gap analysis, penetration testing, control validation and board-ready reporting, so leadership can evidence tested controls and supplier readiness.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting DORA & NIS2 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
Banks and insurers push DORA testing and evidence duties to suppliers. Gaps can cost contracts.
Management bodies approve and oversee measures. NIS2 penalties reach EUR 10M or 2% of turnover.
Early warning is due in 24 hours and notification in 72. Tested processes prevent improvisation.
DORA applies since 17 January 2025 and NIS2 depends on national law. Owners and dates keep pace.
Financial entities fall under DORA’s ICT risk, reporting, testing and third-party rules.
ICT providers to EU financial firms face contract clauses and security evidence requests.
Energy, health, transport, digital infrastructure and others fall under NIS2.
MSPs and security providers are explicitly in scope of NIS2 in many member states.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
Governance, reporting, testing and supplier practices compared with DORA and NIS2 duties.
Human-led testing of critical ICT systems, with TLPT scoping support where designated.
Checks that detection, response and recovery controls work as documented.
Dated reports and fix records suited to regulator and client requests.
Fix guidance, then a retest confirming closure.
Resilience posture and gaps for management bodies.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Determine whether DORA, NIS2 (and which national law) or both apply, and in what role.
Compare current governance, reporting, testing and supplier practices to the requirements.
Assign board accountability and build incident classification and reporting workflows.
Plan vulnerability assessments and penetration tests, and prepare for TLPT if designated.
Create the supplier register, update contracts and collect evidence from key vendors.
Run incident exercises and report test findings to management.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Resilience posture and top risks in plain language.
Annual testing cadence and TLPT preparation steps.
Test summaries clients can use in their reviews.
Findings with owners, severity and status.
The same Summit team stays with you through regulator and client questions.
The Digital Operational Resilience Act (DORA) is an EU regulation, applying since 17 January 2025, that sets uniform ICT risk rules for banks, insurers, investment firms, payment and crypto providers and other financial entities. It also brings critical ICT third-party providers, such as cloud services, under oversight.
NIS2 is an EU directive that raises cybersecurity requirements for “essential” and “important” entities in sectors such as energy, transport, health, digital infrastructure, ICT service management and manufacturing. Member states transpose it into national law, so details and dates vary by country. Management bodies carry direct responsibility for approving and overseeing measures.
For financial firms DORA generally takes priority over NIS2 for overlapping topics. Both focus on governance, incident reporting, resilience testing and supply chain risk. If you sell to EU banks, insurers or critical sector companies, expect these topics to appear in their vendor questionnaires and contracts.
DORA is organised in pillars. NIS2 lists minimum risk management measures in Article 21. The two share many themes.
The management body must own the ICT risk framework. Identify assets, protect them, detect anomalies, respond and recover. NIS2 Article 21 sets minimum measures such as risk analysis, incident handling, business continuity, supply chain security and use of cryptography.
Classify incidents and report major ones to the authorities in set timeframes. NIS2 uses a 24 hour early warning, 72 hour notification and a final report within a month. DORA has its own templates and deadlines for major ICT incidents.
Financial entities need a testing programme covering vulnerability assessments, scenario tests, network security assessments and penetration tests. Designated entities must perform advanced TLPT at least every three years.
Keep a register of ICT providers, assess concentration and exit risks and include required clauses in contracts. NIS2 adds supply chain security measures including supplier due diligence.
Entities are encouraged to share cyber threat information in trusted communities. Critical ICT providers are subject to direct EU oversight under DORA.
DORA names penetration testing and TLPT explicitly. NIS2 requires policies to assess the effectiveness of cybersecurity measures, which testing helps to evidence. Customers who are in scope will push testing requirements down to their suppliers.
Vulnerability assessments and penetration tests of critical ICT systems are part of the required programme.
Designated entities run advanced testing based on realistic threat scenarios about every three years.
Policies and procedures to assess the effectiveness of risk management measures. Test reports are direct evidence.
Financial and critical-sector customers will ask suppliers for recent independent testing evidence.
It is a directive. National laws differ in scope, deadlines and penalties.
TLPT is intelligence-led and follows a specific framework. Plan scope, testers and time well ahead.
DORA needs a complete record of ICT arrangements. Start collecting it early.
Management bodies are directly accountable. Brief and train them regularly.
Directly to financial entities, but vendors providing ICT services to them are affected through contracts, due diligence and, for designated critical providers, direct oversight.
Threat-led penetration testing: an advanced, intelligence-driven test of live production systems that follows a recognised framework, performed by qualified testers.
A 24 hour early warning for significant incidents, an incident notification within 72 hours and a final report within a month, subject to national transposition.
No. DORA is a regulation specific to the financial sector, while NIS2 is a directive covering many sectors. Financial entities are mostly governed by DORA for ICT topics.
No. It is general education. Summit focuses on resilience testing, gap analysis and board-ready reporting, and stays with your team through reviews while your legal team interprets the rules.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.