16

Immagine creata con IAAI-generated image

NIS 2, DORA and the Cyber Resilience Act: how to find your way when perimeters overlap

Three European acts, three regulatory logics, one goal: digital resilience. But for those who fall within several perimeters — from a bank to a software vendor — the question is concrete: which discipline prevails? The answer lies in the coordination clauses: Article 4 of NIS 2, the lex specialis of DORA and the complementarity of the CRA. Let us clarify.

In our previous contributions we dealt with the labyrinth of EU cybersecurity rules, which now has three main strands: Directive (EU) 2022/2555 (NIS 2), transposed in Italy by Legislative Decree 138/2024; Regulation (EU) 2022/2554 (DORA), on the digital operational resilience of the financial sector; and Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA), on horizontal cybersecurity requirements for products with digital elements. This seems the right place to examine how the three acts coordinate.

Three calendars to bear in mind

The first order of clarity is temporal. For NIS 2, Article 41 requires Member States to apply the transposing measures “from 18 October 2024”; in Italy the implementation phase entrusted to the ACN’s determinations is in full swing. For DORA, Article 64 is clear: “it applies from 17 January 2025” — the financial sector is therefore already fully operational. For the CRA, Article 71(2) sets three stages: “this Regulation applies from 11 December 2027. However, Article 14 applies from 11 September 2026 and Chapter IV (Articles 35 to 51) applies from 11 June 2026.” This is crucial: the reporting obligations of Article 14 kick in already from 11 September 2026, before the general product obligations.

NIS 2 and DORA: the sectoral-acts clause

The pivot of coordination is Article 4 of NIS 2, headed “Sector-specific Union legal acts”, which at paragraph 1 provides that “where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents, and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, the relevant provisions of this Directive […] shall not apply to such entities”. DORA qualifies itself precisely in these terms. Recital 16 clarifies that “this Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555”, and Article 1(2) makes the coordination operative: for financial entities identified as essential or important under the national rules transposing Article 3 of NIS 2, “this Regulation is considered a sector-specific Union legal act in relation to Article 4 of that Directive”. In other words: for financial entities subject to DORA, the corresponding NIS 2 provisions on measures and notifications give way. But beware of the hasty reading: the yielding operates for the “relevant provisions”, not for the whole framework, and presupposes equivalence of effects; punctual mapping remains a case-by-case exercise.

The CRA: a different plane, not a derogation

The CRA’s logic is different: it does not regulate entities and services, but products with digital elements — security by design across the lifecycle, manufacturer obligations, CE marking. Not by chance, the CRA contains no speciality clause vis-à-vis NIS 2; Recital 13 describes rather its complementarity. The most concrete point of contact is procedural: Article 14(1) of the CRA hooks reporting onto the NIS architecture: “a manufacturer shall notify simultaneously to the CSIRT designated as coordinator […] and to ENISA any actively exploited vulnerability contained in the product with digital elements that it becomes aware of”. The NIS entity that is also a manufacturer of digital products will therefore have to oversee two distinct notification channels, each with its own triggers and timing.

ENISA’s compass

To support operators, ENISA has made available valuable mapping tools. The NIS360 report “assesses the maturity and criticality of sectors of high criticality under the NIS2 Directive”. And the ENISA Threat Landscape 2025 gives the picture of the threat: “this latest edition […] analyses 4875 incidents over a period spanning from 1 July 2024 to 30 June 2025”.

Conclusions

For those within several perimeters, the operational sequence we suggest is: map your roles (NIS entity? DORA financial entity? CRA manufacturer?); identify, for each obligation, the applicable discipline in light of the coordination clauses; build a unitary governance framework satisfying the most demanding requirement, avoiding documentary duplication; oversee the distinct notification channels with dedicated procedures. In the light of the above, one wonders whether the European cybersecurity mosaic will find in practice the coherence that positive law entrusts, for now, to the coordination clauses: a truly integrated resilience requires bringing the obligations of the different perimeters back to unity, rather than duplicating them, so as to raise the level of effective security in the face of a threat that knows no perimeters.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project