International Directives and Law

Governments do not all reach for the same tool when they decide to improve data security. Here is a short guide to how the rules actually get made — and why two of the most active ones right now, NIS2 and DORA, are worth understanding in detail.

01 · HOW REGULATION WORKS

Three ways a country pushes for better data security

When a government decides that data security and breach prevention need to improve, it generally reaches for one of three tools, and which one it picks changes how quickly it applies to you and how much it varies by country.

Tool How it works Example
RegulationBinding law the moment it takes effect, worded identically in every country it covers. No local rewriting.DORA (EU), directly applicable since January 2025
DirectiveBinding on the goal, not the method. Each country writes its own national law to get there, so scope, timing and detail vary by country even though the underlying directive is the same.NIS2 (EU), still being transposed into national law across member states
Framework or recommendationVoluntary guidance with no force of its own. It becomes mandatory only when something else — a contract, a regulator, a piece of separate legislation — points to it.The NIST Cybersecurity Framework (US), made mandatory for defence contractors only because DFARS contract clauses require it

Outside the EU, most countries regulate sector by sector rather than with one cross-cutting law. In the United States, defence, financial services and healthcare each have their own separate rules rather than a single umbrella statute. The United Kingdom runs its own regime entirely — built on its own NIS regulations and financial-sector rules — distinct from both the EU's NIS2 and DORA.

Whichever mechanism a country uses, the substance converges on the same handful of questions: who is allowed to access what, how that access is actually proven at the moment it matters, and whether you can show a regulator the record afterwards.

02 · WHY NOW

Why this matters right now

In Europe specifically, this is an unusually active moment. NIS2's national transposition is still being finalised in several member states through 2026. DORA has been directly applicable since January 2025, and 2026 is shaping up to be the first real cycle of supervisory enforcement. High-profile incidents have put a concrete number on what happens when the underlying control fails — and short, real deadlines mean this is not a topic compliance and security teams can leave for next year's roadmap.

The two pages below go into the detail: what NIS2 and DORA actually require, article by article, and how one specific, frequently overlooked control — identity verification at the IT service desk — maps against them.

» DEEPER READING

NIS2 and DORA compliance for the IT service desk

» ON REQUEST

NIS2 & DORA control mapping document

FastPassCorp A/S · Frederiksborggade 15.3, 1360 Copenhagen · Listed on Nasdaq First North Copenhagen. This page is provided for information and is not legal advice. Regulatory obligations depend on your sector, size, jurisdiction and national transposition.

Scroll to Top