What NIS2 and DORA ask of a marketing website and its vendors
Most marketing sites are out of scope of NIS2 and DORA on their own. The duty arrives through the client: supply chain security under Article 21, mandatory contract clauses under Article 30, and a reporting clock.
Contents
Most public-facing marketing sites fall outside NIS2 and DORA on their own. The duty arrives through the customer: an entity covered by Directive (EU) 2022/2555 must manage the security of its direct suppliers, and a financial entity under Regulation (EU) 2022/2554 must put named clauses into every ICT contract. It reaches you as a questionnaire.
Key takeaways
- NIS2 covers Annex I and II entities of at least 50 staff, or with turnover or balance sheet above €10 million.
- Article 21(2)(d) makes supplier security an obligation of the covered entity, which is how the questionnaire reaches a web vendor.
- DORA has applied since 17 January 2025; Article 30 lists what an ICT contract must carry, and the clock on a major incident starts four hours after classification.
- Spain missed the 17 October 2024 transposition deadline and was referred to the Court of Justice on 8 July 2026.
Who NIS2 and DORA actually bind
NIS2 runs a size-and-sector test. Article 2(1) of Directive (EU) 2022/2555 covers entities listed in Annex I or II that qualify as medium-sized or larger: at least 50 staff, or turnover or balance sheet above €10 million.
Annex I added a sector that catches technology suppliers, ICT service management. Article 6(39) defines a managed service provider as an entity that installs, manages, operates or maintains ICT products, networks, infrastructure or applications through assistance or active administration. A studio that designs a site and hands it over sits outside that. A vendor administering hosting, CMS and DNS on a retainer sits inside it.
DORA works from the other end. Regulation (EU) 2022/2554 binds financial entities, not their ordinary ICT suppliers. It reaches those suppliers through the contract their client must now write.
Why the duty reaches your web vendor anyway
Article 21(2)(d) puts supply chain security among the risk-management measures a covered entity must take, and Article 21(3) tells it to weigh each direct supplier's vulnerabilities and secure development procedures. The obligation belongs to the client. The evidence comes from the vendor.
DORA is prescriptive about the paperwork. Article 30 fixes what every ICT contract must contain, from service description and delivery locations to data recovery on termination, service levels, incident assistance at a price agreed in advance, and termination rights. Article 30(3) adds performance targets, audit rights, penetration testing and an exit plan wherever the service supports a critical or important function.
DORA Article 30(3) requires contracts covering critical or important functions to include unrestricted rights of access, inspection and audit, and an exit strategy with a mandatory transition period. Source: Regulation (EU) 2022/2554, applicable since 17 January 2025.
The reporting clocks you have to support
NIS2 Article 23 sets three deadlines for a significant incident: an early warning within 24 hours of becoming aware of it, a full notification within 72 hours, and a final report one month later.
Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 says when that threshold is crossed for cloud, data centre, content delivery network, DNS and managed service providers. One general criterion is direct financial loss above €500,000 or 5% of annual turnover, whichever is lower.
Under Commission Delegated Regulation (EU) 2025/301, a financial entity must notify a major ICT-related incident within four hours of classifying it and no later than 24 hours from becoming aware of it, with an intermediate report at 72 hours. Source: Official Journal, 20 February 2025.
Spain: the law is late, the obligation is not
The Consejo de Ministros approved the anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad on 14 January 2025, naming three supervisory authorities and a national cybersecurity centre. It has not reached the BOE.
After formal notices in November 2024 and reasoned opinions in May 2025, the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026, asking for a lump sum and daily penalties.
Two things follow. DORA already applies in Spain, because a regulation needs no national statute. The Article 34 fines—€10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones—wait on the Spanish law. Procurement teams do not.
What a site owner is accountable for
Not the client's core systems. The accountable surface is the estate you actually run, and it is smaller than most questionnaires imply.
It is an inventory of domains, DNS records, certificates, CMS and plugin versions, and every third-party script the pages load. It is access control with multi-factor authentication, a patch cadence with an owner, backups restored at least once, logs long enough to reconstruct an incident, and a named contact reachable inside a working day.
Third-party scripts deserve a separate review, for the same reason choosing which crawlers and bots to allow is a decision rather than a default. The rule that made the European Accessibility Act a build requirement holds here too.
FAQ
Is a corporate website in scope of NIS2?
Rarely on its own. Scope depends on the Annex I or II sector and on size. A site is reached through its owner, if that organization is covered, or through its vendor, if the vendor administers systems and meets the Article 6(39) definition.
Does DORA apply to a web agency?
Not directly, unless the European Supervisory Authorities designate it a critical ICT third-party provider. It applies through the contract with a financial entity, which must carry the Article 30 clauses on service levels, audit rights, incident assistance and exit.
What changes in Spain when the law is published?
Supervision and sanctions become enforceable domestically, and the register of essential and important entities gets an owner. Articles 21 and 23 have been the procurement reference since 2024, so a well-run estate should not need to change much.
Where to start
Start with the inventory, because nobody can answer a supplier questionnaire about assets that were never listed. Then access control and patch cadence, then the incident contact written into the contract. The scoping work overlaps with what Kit Digital actually pays for and with the EU AI Act calendar, so do it once. Within six months the Court of Justice case will price Spain's delay; the obligations are already enforced through purchase orders.



