NIS2 and DORA: What Software Vendors Must Now Prove to EU Clients
Europe’s security regulations bind your customers and reach you by contract. The supplier obligations, incident timelines and evidence packs to have ready.
Two EU regimes changed the sales conversation for anyone supplying software or services to European enterprises. NIS2 binds "essential and important entities" across 18 sectors to serious cybersecurity duties, with management personally accountable; DORA does the same for financial entities with even sharper teeth. Neither regulates most vendors directly — they regulate your customers, who are explicitly required to manage supply-chain risk. Which means the obligations arrive at your door wearing a procurement questionnaire.
What flows down, concretely
Supplier risk management clauses. NIS2 entities must assess and contract for supplier security. Expect: security requirements in the MSA, audit or evidence rights, subcontractor transparency, and termination triggers for security failures. DORA goes further for financial clients — register of ICT providers, exit strategies, and for "critical" providers, direct EU oversight.
Incident-notification chains. NIS2's clock is famous: early warning within 24 hours, incident notification within 72 hours, final report within a month. Your customer cannot meet their 24-hour duty if your incident reaches them in a fortnightly status call. Contracts now specify your notification window — typically "without undue delay, at most 24h from awareness" for anything touching their service. Your incident path needs this lane built and tested.
Resilience evidence. Business continuity, backup testing, RTO/RPO statements, and for DORA clients, participation in their resilience testing — potentially including threat-led penetration testing on systems serving them.
The evidence pack that ends questionnaires
Vendors who sail through this have a standing pack, versioned and honest: SOC 2 Type II or ISO 27001 (the accepted shorthand for "run properly"), a security whitepaper mapping controls, incident-response summary with the notification SLA stated, sub-processor list with locations (residency matters), BCP/DR summary with last test date, and named security contact. Assembled once, it turns each questionnaire from a week of engineering interruption into an attachment.
Reading it strategically
Compliance floors are competitive moats when you are the compliant one. Mid-market EU buyers are actively consolidating away from vendors who cannot answer these questions — every regulation-shaped questionnaire is a chance to be the easy choice. And the requirements themselves — tested backups, real incident drills, supplier registers — are the hygiene that keeps systems boring, which was the goal before it was the law.
We build the engineering side of this posture into client platforms by default — logging, backup verification, incident runbooks, sub-processor tracking — so that when the first NIS2-flavoured questionnaire lands, the answer is an export, not a project. The vendors treating this as paperwork are about to lose deals to the ones treating it as product.
Work with us
House of Marka is the applied-AI and commerce engineering studio of Marka Modern Retail Private Limited. We research, advise and then build — for merchants and enterprises in the US, UK and Europe.
Next step
Tell us what you are trying to build.
A short call, a written view on whether we are the right studio for it, and a plan you can act on either way.