<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DORA on Sovereign Shift</title>
    <link>https://sovereignshift.eu/tags/dora/</link>
    <description>Recent content in DORA on Sovereign Shift</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 22 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://sovereignshift.eu/tags/dora/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>NIS2, DORA, and the Regulatory Case for Knowing Your Dependencies</title>
      <link>https://sovereignshift.eu/blog/nis2-dora-digital-sovereignty/</link>
      <pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://sovereignshift.eu/blog/nis2-dora-digital-sovereignty/</guid>
      <description>&lt;p&gt;Two pieces of EU legislation, NIS2 and DORA, are fundamentally changing how European organisations must think about their technology suppliers. Neither regulation bans US cloud providers. But both make it legally necessary to understand, document, and manage the risks that come with depending on them.&lt;/p&gt;&#xA;&lt;p&gt;Most organisations are not ready. Here is what the regulations actually require, and what compliance looks like in practice.&lt;/p&gt;&#xA;&lt;h2 id=&#34;nis2-supply-chain-risk-is-now-mandatory&#34;&gt;NIS2: Supply Chain Risk Is Now Mandatory&lt;/h2&gt;&#xA;&lt;p&gt;The &lt;strong&gt;Network and Information Security Directive 2&lt;/strong&gt; (NIS2), which EU member states were required to transpose into national law by October 2024, significantly expands the scope of cybersecurity obligations across Europe.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DORA Concentration Risk: How to Build an Exit Strategy Your Regulator Will Accept</title>
      <link>https://sovereignshift.eu/blog/dora-concentration-risk-exit-strategy/</link>
      <pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://sovereignshift.eu/blog/dora-concentration-risk-exit-strategy/</guid>
      <description>&lt;p&gt;The Digital Operational Resilience Act (Regulation 2022/2554), which applies from 17 January 2025, introduces a concept that no previous EU regulation stated so explicitly: financial entities must identify, assess, and manage the risk of depending too heavily on a single ICT provider. And they must have documented exit plans for their critical providers.&lt;/p&gt;&#xA;&lt;p&gt;This is not optional. DORA applies to credit institutions, investment firms, insurance undertakings, payment institutions, crypto-asset service providers, and virtually every other regulated financial entity in the EU. The European Supervisory Authorities (EBA, ESMA, EIOPA) are developing Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) to specify the details.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
