What NIS2 and DORA mean for the device in your pocket

NIS2 and DORA

The phone in your pocket holds your work email, your login codes, your files and your calendar. So does every phone your staff carry. Two EU laws now shape how those phones must be looked after, even though neither one mentions phones at all.

Here is what the two laws are, and what they mean for mobile.

What is NIS2?

NIS2 is Directive (EU) 2022/2555. It is the EU’s main cyber security law, replacing an earlier version from 2016.

It does two things: It widens the list of sectors that have to meet a cyber security standard, and it raises that standard for all of them.

Annex I of the directive covers essential sectors such as energy, transport, banking, health, water and digital infrastructure. Annex II covers important sectors such as post, waste, food, manufacturing and some digital services. Size limits then apply, though a few types of firm are in scope whatever their size.

NIS2 is a directive rather than a regulation, so it reaches firms through each country’s own law. The duties come from the directive. Details like who you register with and who you report to are set at home, and the timing varied from one country to the next.

Article 21 lists ten basic measures that firms have to take. The ones that land on mobile are risk policies, incident handling, supply chain security, access control and asset management, encryption, staff training and multi-factor login. The rest cover business continuity, building and maintaining software safely, and checking that your own measures work. Article 20 adds that the board has to sign all of that off, and that senior managers can be held liable in person if the firm falls short.

What is DORA?

DORA is Regulation (EU) 2022/2554, the Digital Operational Resilience Act. It applies to a wide range of financial entities and also establishes requirements and an oversight framework for ICT third-party service providers.

DORA is a regulation rather than a directive, so it applies direct with no national law in between. It has applied since 17 January 2025.

Where NIS2 asks a wide set of sectors to reach a baseline, DORA asks a narrower set to prove they can take a hit and keep running. It covers ICT risk management, incident reporting, resilience testing, supplier risk and threat intelligence sharing. DORA is accompanied by detailed sector-specific technical standards and reporting/classification rules, making its requirements more granular for financial entities.

What this means for mobile

Neither law has a mobile section. Phones come in because both laws are written about the whole ICT estate, and phones are part of that estate. Five things follow.

Phones are part of the ICT risk picture: Both laws require organisations to understand and manage the ICT assets and systems they rely on. A work phone that accesses company email or systems therefore needs to be accounted for in the organisation’s risk and security controls. The same can apply to a personal phone used for work.

Most logins now go through a phone: Access control is one of the ten measures of Article 21, and the phone is where access is granted, by push prompt or by passkey. That puts the handset in the login path rather than at the edge of it.

Mobile software creates supply chain risk: NIS2 requires firms to address security risks in their relationships with suppliers and service providers. For mobile that can include app developers, cloud and backend providers, and the technology suppliers an app depends on. It is worth remembering how much of a mobile app is other people’s code, since a lot of what ends up on the handset never came through a supplier contract at all.

Both laws run on a clock, and a phone is often the last thing to be noticed: NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an interim report if requested, and a final report within one month of the notification.

DORA is tighter still. First notice of a major incident is due within 4 hours of ranking it as major, and within 24 hours of spotting it at the latest. If a mobile attack is not detected until the user calls the help desk, the organisation may already have lost valuable time in detecting, assessing and responding to an incident.

Image showing NIS2 and DORA notification and reporting timelines

Mobile uptime counts as resilience: DORA is about keeping services going. Where a mobile app supports a business service or a critical or important function, its availability can form part of the ICT resilience picture DORA requires the firm to manage.

Who carries the risk?

Most cyber rules land on the company. NIS2 also lands on people, and that is the part worth reading twice.

Article 20 asks the board to approve the risk measures, keep an eye on how they get put in place, and do enough training to judge cyber risk for themselves. Senior managers can be held personally liable if the firm falls short, and in serious cases an authority can bar a chief executive from running the company for a while. What that looks like in practice depends on how your own country wrote the directive into law.

The big figures you see quoted, up to at least €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities, are administrative-fine ceilings that Member States must provide for in national law; they are not automatic fines.

A board signs off the risk picture it gets shown. Most board packs cover the network and the laptops properly. Mobile usually appears as one line saying the devices are managed, which describes how they are set up rather than what is happening on them. If the picture you approved had a mobile-shaped hole in it, you approved something that was not accurate. Your name is on that approval.

What it does not mean

Neither law tells you to buy anything. There is no NIS2 approved product list and no DORA mobile standard. Both ask for measures that fit the risk, a way to spot incidents, a way to handle them, and proof that all of it is in place.

Nor do the laws reach into a personal phone that never touches work. The trigger is the link to the business, not the hardware.

Why teams look at mobile threat defence next

Nothing above says you have to buy a tool. But both laws ask for something most mobile setups cannot currently do, so it is worth being clear about where the gap usually sits.

Most firms already run mobile device management. MDM does a specific job, and does it well. It sets the passcode rule, checks the OS version, pushes the apps you have approved, and wipes a handset that goes missing. That covers a good part of the asset and access work in Article 21.

What most MDMs do not do is watch for an attack. They do not look at where a phone is connecting or what it is being asked to do. A handset can sit green in the MDM console while it loads a phishing page, talks to an attacker’s server, or runs an app that is quietly leaking data. The console reports the device as compliant, because by its own measure it is.

That gap matters, because the incident duties in both laws are about spotting and handling rather than about configuration. That is where mobile-specific detection can close a control gap: it can provide visibility into threats occurring on the handset that device-management controls alone may not reveal.

There is a second argument that has nothing to do with audits. An attack that is detected and blocked early may never develop into a reportable incident. Early detection therefore reduces both operational impact and the risk of discovering a serious incident late in the reporting window. 

The cheapest incident is the one that never happens. And when something does get through, what your team logged at the time is what your reporting has to be built from.

Get our list of Mobile threat Detection Providers in 2026

The takeaway

NIS2 and DORA never use the word phone, but still land on it. NIS2 lifts the cyber security floor across a wide set of sectors. DORA makes financial firms show they can keep running through trouble. In both cases, the phone in your pocket is part of the estate being asked about, because it holds the logins, the data, the access, and often the second factor too.

Corrata is an EU-native company. We help security teams in regulated sectors see mobile threats on iOS and Android, and keep the records that support compliance efforts.

Book a demo to see how Corrata supports mobile risk work under NIS2 and DORA.

Frequently Asked Questions

Not to the phone itself. NIS2 puts duties on firms, not on devices. But if a phone reaches a company system, it counts as part of the ICT estate the firm has to manage under Article 21.

Not for the same requirements in the same way. DORA is the sector-specific EU framework for financial entities, and its requirements take precedence over corresponding NIS2 requirements on matters covered by DORA, particularly ICT risk management and incident reporting. But NIS2 does not simply disappear: some provisions continue to apply, and other entities in the same corporate group may remain subject to NIS2.

The deadlines are the same for a phone as for anything else. Under NIS2 an early warning is due within 24 hours of becoming aware of a serious incident, a full report within 72 hours, and a final report within a month of that full report. Under DORA first notice of a major incident is due within 4 hours of ranking it as major, and within 24 hours of spotting it at the latest.

Yes, in principle. Article 20 requires each country to make sure senior managers can be held liable where the firm falls short, so the detail depends on how your country wrote it into law. In serious cases an authority can also bar a chief executive from running the company for a while.

No. Neither law names a type of product. Both ask for measures that fit the risk, a way to spot and handle incidents, and proof that they are in place. How a firm does that on mobile is its own call.

MDM and mobile threat defence address different parts of the problem. MDM primarily manages device configuration, policy, applications and compliance. Mobile threat defence focuses on detecting and responding to threats such as malicious network activity, phishing and other attacks on the mobile device. Whether an organisation needs both depends on its risk profile and existing controls; neither NIS2 nor DORA mandates an MTD product by name.

Related Resources

Related Resources

Read the latest news on endpoint threat detection and response from the experts.

Read the latest news on endpoint threat detection and response from the experts.

  • NIS2 and DORA
    blog

    Blog

    What NIS2 and DORA mean for the device in your pocket

    Read more
  • european data sovereignty and mobile security
    blog

    Blog

    European Data Sovereignty and Mobile Security Requirements

    Read more
  • corrata and microsoft defender
    blog

    Blog

    Corrata and Microsoft Defender for Endpoint: How they compare on mobile

    Read more
  • mobile threat defense software
    blog

    Blog

    Mobile Threat Defense Software: The Market in 2026

    Read more