EU Security Regulations for Financial Companies: A Strategic Guide to Compliance
By Zetta Henigman
The EU has built five overlapping ICT security regimes, and left financial firms to work out the interactions themselves. Each regime was drafted separately, yet they share some requirements: incident reporting, risk management, third-party oversight, and consumer protection. The result is a compliance landscape where the same breach or the same vendor relationship can trigger obligations under two or three frameworks at once.
Cyber threats, data breaches, and financial crimes can destabilize markets, erode customer trust, and trigger systemic crises. For financial companies operating in the European Union (EU), compliance with these security-focused regulations and directives is essential to survive and thrive in a rapidly evolving landscape.
This article introduces the key EU regulations and directives with a security component that apply to financial companies.
For the full list of EU regulations Anove tracks, visit our regulations page.
The Regulatory Landscape: What Financial Companies Need to Know
1. Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) is a landmark EU regulation introduced to strengthen the digital resilience of financial entities.[1] It entered into force on 16 January 2023 and applies from 17 January 2025, ensuring that financial institutions can withstand, respond to, and recover from ICT (Information and Communication Technology) disruptions, such as cyberattacks or system failures.[2]
What DORA Covers
DORA establishes a comprehensive framework for managing ICT risks in the financial sector. The regulation covers the following key areas:
- ICT Risk Management: Financial entities must develop and maintain a robust ICT risk management framework, including strategies for identifying, assessing, and mitigating ICT risks.
- ICT Third-Party Risk: Financial entities must maintain a register of ICT third-party arrangements and ensure contracts with critical providers include exit strategies, audit rights and performance targets.
- Digital Operational Resilience Testing: Financial entities are required to regularly test their ICT systems to evaluate their resilience, which includes vulnerability assessments, scenario-based testing, and, for critical institutions, threat-led penetration testing (TLPT) every three years.
- ICT-Related Incident Reporting: DORA mandates that financial entities establish systems for monitoring, managing, logging, classifying, and reporting ICT-related incidents.
- Information Sharing: While not mandatory, DORA encourages financial entities to participate in voluntary threat intelligence sharing arrangements to enhance collective resilience against cyber threats.
Who DORA Applies To
DORA applies to a wide range of financial entities, including:
- Financial entities: Traditional institutions (banks, insurance companies, investment firms) and non-traditional entities (crypto-asset service providers, crowdfunding platforms).
- ICT third-party providers: Only those designated as Critical Third-Party Providers (CTPPs) by the European Supervisory Authorities (ESAs).
2. Network and Information Security Directive (NIS 2)
The Network and Information Security Directive (NIS 2) is the EU’s updated cybersecurity framework, replacing the original NIS Directive.[3] Its objective is to achieve a high common level of cybersecurity across the EU by strengthening the security of network and information systems. Member States were required to transpose NIS 2 into national law by 17 October 2024, though countries such as the Netherlands, France, Spain, and Ireland missed this deadline, creating practical uncertainty for businesses.[4]
What NIS 2 Covers
The key provisions of NIS 2 include:
- Risk Management and Reporting: The directive introduces risk management measures and incident reporting requirements for entities in critical sectors. Medium-sized and large entities must implement appropriate cybersecurity risk-management measures and notify relevant national authorities of significant incidents.
- Governance and Accountability: NIS 2 holds top management accountable for cybersecurity risk management, bringing cybersecurity to the attention of the boardroom. It grants national competent authorities enhanced supervisory and enforcement powers, including the authority to impose substantial administrative fines for non-compliance.
- Cooperation and Information Sharing: The directive establishes a network of Computer Security Incident Response Teams (CSIRTs) to exchange information on cyber threats and respond to incidents. It also creates the European Cyber Crisis Liaison Organization Network (EU-CyCLONe) to support coordinated management of large-scale cybersecurity incidents or crises.
- All-Hazards Approach: NIS 2 requires organizations to prepare for a broad spectrum of risks, strengthening operational resilience and ensuring the continuity of essential and important services. Entities must implement technical, operational, and organizational measures to manage risks in network and information systems, protecting not only their own operations but also minimizing the impact of incidents on service recipients and interconnected systems.
Relationship with DORA: Under Article 4 of NIS 2, where sector-specific Union legal acts (such as DORA) impose cybersecurity risk-management or incident notification requirements that are at least equivalent to NIS 2, the relevant NIS 2 provisions, including Articles 21 (risk management) and 23 (incident notification), as well as supervision and enforcement, do not apply. DORA is lex specialis for financial entities, meaning banks and other financial institutions are not required to comply with both frameworks in full.
Who NIS 2 Applies To
NIS 2 applies to medium and large-sized essential and important entities operating in sectors of high criticality (Annex I), as well as other critical sectors (Annex II).[5] These include:
- Energy,
- Transport,
- Banking,
- Financial market infrastructures,
- Health,
- Drinking water,
- Waste water,
- Digital infrastructure,
- ICT service management (business-to-business),
- Public administration,
- Space,
- Postal and courier services,
- Waste management,
- Manufacture, production and distribution of chemicals,
- Production, processing and distribution of food,
- Manufacturing,
- Digital providers, and
- Research.
3. General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is the EU’s data privacy regulation.[6] It entered into force on 24 May 2016 and applies from 25 May 2018, designed to protect the personal data and privacy of EU residents by imposing strict requirements on how personal data is collected, processed, and stored.[7]
What GDPR Covers
GDPR establishes a comprehensive framework for data protection, ensuring that individuals have control over their personal data. Key provisions include:
- Principles of Data Processing: GDPR sets out core principles for processing personal data, including lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
- Data Breach Notification: Organizations must report personal data breaches to the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
- Technical and Organizational Measures: Organizations must implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including pseudonymization, encryption, access controls, and regular security testing.
- Data Protection Impact Assessments (DPIAs): Organizations must conduct DPIAs for high-risk data processing activities to identify and mitigate potential privacy risks.
- Data Protection Officer (DPO): Certain organizations, particularly those involved in large-scale processing of sensitive data, are required to appoint a DPO to oversee compliance with GDPR.
- Cross-Border Data Transfers: GDPR imposes strict rules on the transfer of personal data outside the EU, requiring organizations to ensure that data transferred to third countries is protected by adequate safeguards.
Who GDPR Applies To
GDPR applies to all organizations, including financial companies, that process the personal data of EU residents, regardless of where the organization is based.
4. Payment Services Directives and Regulation (PSD2, PSD3, and PSR)
PSD2 (Payment Services Directive 2) is the current EU directive governing payment services, entered into force in Januray 2016 and applied from January 2018, to promote competition, enhance security, and protect consumers.[8]
The PSD3 and PSR represent the next phase of EU payment services regulation.[9] Political agreement on PSD3/PSR was reached on 27 November 2025, with final texts agreed on 23 April 2026.[10] Official Journal publication is expected this summer, with application targeted for Q2/Q3 2028.[11] The PSD3 is a directive (requiring transposition into national law), while PSR is a regulation (directly applicable across all EU member states). Together, they aim to further strengthen fraud prevention, expand open banking capabilities, and harmonize payment rules across the EU.
Note: The Financial Data Access (FIDA) framework was also proposed alongside PSD3/PSR and remains in trilogue negotiations.[12]
What They Cover
PSD2, PSD3, and PSR introduce key requirements for payment services, including:
- Strong Customer Authentication (SCA): Mandatory authentication using two or more elements from independent categories (knowledge, possession, inherence) for electronic transactions.
- Open Banking: Secure access for third-party providers to bank account data.
- Transparency: Clear disclosure of fees, exchange rates, and transaction details.
- Refund Rights: Customer protection for unauthorized transactions.
- Security: Requirements for confidentiality, integrity, and availability of payment data.
- Licensing: Mandatory registration and authorization for payment service providers.
- Incident Reporting: Obligation to report significant security incidents.
Who They Apply To
- Payment Service Providers (PSPs): Banks, fintechs, and payment processors.
- Third-Party Providers (TPPs): Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs).
- Merchants and retailers offering payment services.
- Companies providing online banking and payment services across the EU.
5. Markets in Crypto-Assets (MiCA) Regulation
The Markets in Crypto-Assets Regulation (MiCA) is the EU’s first comprehensive framework for regulating crypto-assets.[13] It establishes uniform market rules for crypto-assets not currently covered by existing financial services legislation, aiming to support market integrity, financial stability, and consumer protection. MiCA entered into force on 29 June 2023, applying from 30 December 2024, except for Titles III and IV (asset-referenced tokens and e-money tokens), which applied from 30 June 2024.[14] Crypto-asset service providers operating before 30 December 2024 may continue under the grandfathering provisions until 1 July 2026 or until authorization is granted or refused, whichever is sooner, though Member States may opt out or shorten this transitional period.[15]
What MiCA Covers
The key provisions of MiCA include:
- Transparency and Disclosure: Requires issuers of crypto-assets to provide clear and comprehensive information about their assets, including risks, to ensure consumers are well-informed.
- Technical Standards: The regulation sets data standards and formatting requirements for crypto-asset white papers and record-keeping, which include system resilience and security access protocols to protect platforms and services from cyber threats and unauthorized access.
- Market Integrity: Regulates public offers of crypto-assets to prevent market abuse and ensure financial stability.
- Authorisation and Supervision: Introduces authorization and supervision requirements for crypto-asset issuers and service providers, including those dealing with asset-referenced tokens (ARTs) and e-money tokens.
- Business Continuity Requirements: Entities must implement measures to ensure the ongoing availability and reliability of crypto-asset services, even in the event of disruptions or failures.
Who MiCA Applies To
- Issuers of Crypto-Assets: Entities issuing asset-referenced tokens (ARTs), e-money tokens, and other crypto-assets.
- Crypto-Asset Service Providers (CASPs): Entities providing services such as trading, custody, or exchange of crypto-assets.
- Cross-Border Service Providers: Entities operating across EU Member States, benefiting from MiCA’s harmonized framework for scaling their business.
Summary of the Frameworks
|
Framework
|
Instrument Type |
Entered Into |
Applies From |
Supervisors |
Penalties |
|
DORA |
Regulation |
16 Jan 2023 |
17 Jan 2025 |
National competent authorities + European Supervisory Authorities (ESAs) directly oversee designated CTPPs |
Financial entities: up to 2% of global turnover (serious breaches), 1% of average daily turnover (certain breaches), or fixed fines up to €5M. CTPPs: up to €5M + periodic penalties. Individuals: up to €1M + management bans |
|
NIS 2 |
Directive |
16 Jan 2023 |
17 Oct 2024 (transposition deadline) |
National cybersecurity/competent authorities per member state, coordinated by the NIS Cooperation Group |
Essential entities: up to €10M or 2% of global turnover, whichever is higher. Important entities: up to €7M or 1.4%, whichever is higher |
|
GDPR |
Regulation |
24 May 2016 |
25 May 2018 |
National Data Protection Authorities, coordinated by the European Data Protection Board |
Up to €20M or 4% of global annual turnover, whichever is higher |
|
PSD2, PSD3, & PSR |
PSD2 & PSD3: Directives; PSR: Regulation |
PSD2: Jan 2016. PSD3/PSR: not yet in force, final texts published 23 Apr 2026 |
PSD2: 13 Jan 2018. PSD3/PSR: Publication expected in summer 2026; Application targeted for roughly Q2/Q3 2028 |
National competent authorities for payment services |
PSD2/PSD3: no EU cap, determined by member states. PSR: at least 10% of turnover for legal persons, up to €5M for individuals, plus daily penalty payments up to 3% of daily turnover |
|
MiCA |
Regulation |
29 Jun 2023 |
30 Jun 2024 (asset-referenced/e-money tokens) / 30 Dec 2024 (CASPs); national grandfathering windows for pre-existing CASPs ended by 1 Jul 2026 |
National competent authorities + European Banking Authority (significant asset-referenced/e-money tokens) + European Securities and Markets Authority (coordination) |
Natural persons: up to €700,000. Legal persons: up to 15% of annual turnover or 2x the profits gained/losses avoided, whichever is higher. Unauthorized CASP activity specifically: up to €5M or 3–5% of turnover |
What’s Coming Next
AI Act: The Artificial Intelligence Act (AI Act) is the EU's first comprehensive framework for regulating artificial intelligence.[16] It entered into force on 1 August 2024 and applies through a phased timeline: prohibitions on unacceptable-risk practices and AI literacy requirements took effect on 2 February 2025; obligations for general-purpose AI models applied from 2 August 2025; and from 2 August 2026, the majority of remaining rules come into force, including transparency requirements.[17] High-risk AI systems, including those used for credit scoring or fraud detection were originally set to apply from 2 August 2026. However, under the Digital Omnibus Regulation, this deadline is confirmed as delayed to 2 December 2027, with high-risk AI embedded in regulated products under Annex I pushed to 2 August 2028.[18]
AMLR/AMLD6: The Anti-Money Laundering Regulation (AMLR) and the Sixth Anti-Money Laundering Directive (AMLD6) form part of the new AML package in the EU, establishing a common rulebook for customer due diligence, beneficial ownership, and suspicious transaction reporting across Member States.[19] Both entered into force on 9 July 2024.[20] The AMLR will apply directly across all Member States from 10 July 2027,[21] while the AMLD6 must be transposed by the same date.[22]
European Digital Identity Regulation (EUDI/eIDAS 2): eIDAS 2 establishes the legal basis for the EU Digital Identity Wallet (EUDI Wallet), which allows citizens, residents, and businesses to securely store credentials and share only the specific data needed for a given transaction.[23] It entered into force on 20 May 2024.[24] Every Member State must offer at least one certified EUDI Wallet by 24 December 2026, and banks must support the wallet for strong authentication by 24 December 2027, affecting the SCA processes under PSD2/PSD3.[25]
Cyber Resilience Act (CRA): The CRA sets mandatory cybersecurity requirements for connectable hardware and software placed on the EU market, including financial software.[26] It requires manufacturers to build security into the design, development, and maintenance of their products, and to handle vulnerabilities throughout the product lifecycle.[27] The CRA entered into force on 10 December 2024 and applies in full from 11 December 2027, with reporting obligations for actively exploited vulnerabilities and severe incidents applying earlier, from 11 September 2026.[28]
Navigating Overlaps and Intersections
Since many requirements, such as incident reporting, information sharing, risk management, and consumer protection, overlap between the frameworks, financial companies often struggle to navigate the complexity of various obligations. This fragmentation can lead to duplication of efforts, missed critical obligations, or misaligned internal policies, increasing both costs and risks.
To address this, we recommend starting with a comprehensive gap analysis to identify which requirements are already covered by these overlaps. Anove’s insAIght platform helps companies go further by:
- Visualizing overlaps across all relevant frameworks, providing a clear view of how requirements intersect.
- Centralizing documentation and evidence so one control satisfies obligations under multiple regimes.
- Tracking regulatory changes in real time, ensuring updates to one regulation are automatically reflected across all related compliance activities.
With insAIght, financial companies can adopt multiple regulatory frameworks simultaneously, eliminating redundancies and streamlining compliance.
Find out more about insAIght here: https://www.anove.ai/en/product/insaight
Ready to see it in action? Book a demo with our team to find out how insAIght can help your company navigate overlapping EU regulations, close compliance gaps, prepare for audits.
[1] Regulation (EU) 2022/2554 (DORA): Retrieved from https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng.
[2] ESMA, DORA: Retrieved from https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora.
[3] Directive (EU) 2022/2555: Retrieved from https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng.
[4] ECS, NIS2 Directive Transposition Tracker: Retrieved from https://ecs-org.eu/policy/nis2-directive-transposition-tracker/.
[5] Directive (EU) 2022/2555: Retrieved from https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng.
[6] Regulation (EU) 2016/679 (GDPR): Retrieved from https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng.
[7] European Commission, Legal Framework for EU Data Protection: Retrieved from https://commission.europa.eu/law/law-topic/data-protection/legal-framework-eu-data-protection_en.
[8] Directive (EU) 2015/2366 (PSD2): Retrieved from https://eur-lex.europa.eu/eli/dir/2015/2366/oj/eng.
[9] European Parliament, Payment Services Deal: More Protection from Online Fraud and Hidden Fees: Retrieved from https://www.europarl.europa.eu/news/en/press-room/20251121IPR31540/payment-services-deal-more-protection-from-online-fraud-and-hidden-fees.
[10] European Parliament, Revision of EU Rules on Payment Services: Retrieved from https://www.europarl.europa.eu/legislative-train/theme-an-economy-that-works-for-people/file-revision-of-eu-rules-on-payment-services.
[11] Banking Vision, PSD3 and PSR Regulations for Banks: Retrieved from https://banking.vision/en/psd3-and-psr-regulations-for-banks/.
[12] European Commission, Framework for Financial Data Access: Retrieved from https://finance.ec.europa.eu/digital-finance/framework-financial-data-access_en.
[13] Regulation (EU) 2023/1114: Retrieved from https://eur-lex.europa.eu/eli/reg/2023/1114/oj/eng.
[14] European Parliament, Summary of European Crypto-Assets Regulation (MiCA): Retrieved from https://eur-lex.europa.eu/EN/legal-content/summary/european-crypto-assets-regulation-mica.html.
[15] ESMA, Markets in Crypto-Assets Regulation (MiCA): Retrieved from https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica.
[16] Regulation (EU) 2024/1689: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng.
[17] European Commission, Timeline for Implementation of the EU AI Act: Retrieved from https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act.
[18] Council of the European Union, Artificial Intelligence: Council Simplifies and Streamlines Rules: Retrieved from https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/.
[19] Signicat, AMLR vs. AMLD6: Navigating the New Anti-Money Laundering Regulation Era: Retrieved from https://www.signicat.com/blog/amlr-vs-amld6-navigating-the-new-anti-money-laundering-regulation-era.
[20] Rapidlei, EU AML Package Readiness: Retrieved from https://rapidlei.com/eu-aml-package-readiness/.
[21] Regulation (EU) 2024/1624: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng.
[22] Directive (EU) 2024/1640: Retrieved from https://eur-lex.europa.eu/eli/dir/2024/1640/oj/eng.
[23] European Commission, eUDI Regulation: Retrieved from https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation.
[24] European Digital Identity Regulation: Retrieved from https://www.european-digital-identity-regulation.com/.
[25] OneSpan, Why European Banks Must Act Now on EUDI Wallets: Retrieved from https://www.onespan.com/cybersecurity/blog/why-european-banks-must-act-now-on-EUDI-wallets.
[26] Regulation (EU) 2024/2847: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng.
[27] European Commission, Cyber Resilience Act: Retrieved from https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act.
[28] Regulation (EU) 2024/2847: Retrieved from https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng.