Reference

EU Compliance Glossary

A working dictionary of the terms that appear in EU compliance documentation — NIS2, DORA, the AI Act and the regulation around them. Each entry gives a one-line definition you can quote, a short explanation, why it matters, and links to the pages where the term matters in practice.

63 terms

A

B

C

D

  • Directive vs Regulation·NIS2 overview

    The two main types of EU law: a regulation applies directly in all member states, while a directive must be transposed into national law first.

  • DORA·DORA overview

    The Digital Operational Resilience Act, Regulation (EU) 2022/2554, the EU's ICT security law for the financial sector, applicable since 17 January 2025.

E

  • Early Warning·NIS2 incident reporting timeline

    The first NIS2 incident report, due to the CSIRT within 24 hours of becoming aware of a significant incident.

  • ENISA·NIS2 overview

    The European Union Agency for Cybersecurity, which supports NIS2 implementation with guidance, coordination, and reporting.

  • ESAs (EBA, ESMA, EIOPA)·DORA overview

    The three European Supervisory Authorities for banking, securities markets, and insurance, which jointly develop DORA's technical standards and oversee critical ICT providers.

  • Essential Entity·Who NIS2 applies to

    An organisation classified under NIS2 Annex I sectors that faces the strictest supervisory regime and highest penalty ceiling.

F

G

H

I

L

  • Lead Overseer·DORA overview

    The European Supervisory Authority appointed to directly oversee a critical ICT third-party provider under DORA.

  • Lex Specialis·DORA overview

    The legal principle that a sector-specific law overrides a general one — the reason financial entities follow DORA instead of NIS2.

M

N

P

R

S

T

V