{"id":3219,"date":"2025-10-28T14:52:22","date_gmt":"2025-10-28T14:52:22","guid":{"rendered":"https:\/\/phishia.fr\/?p=3219"},"modified":"2025-10-31T08:09:07","modified_gmt":"2025-10-31T08:09:07","slug":"nis2-dora-obligations-ue","status":"publish","type":"post","link":"https:\/\/phishia.fr\/de\/blog\/steuerung-der-konformitat\/nis2-dora-obligations-ue\/","title":{"rendered":"NIS2 &amp; DORA: EU-Verpflichtungen, Schl\u00fcsselunterschiede, konkreter Fahrplan"},"content":{"rendered":"<h2>Warum wird so viel \u00fcber NIS2 und DORA gesprochen<\/h2>\n<p data-start=\"193\" data-end=\"335\">Zwei europ\u00e4ische Texte, zwei benachbarte Ziele : <strong data-start=\"241\" data-end=\"287\">die Auswirkungen von digitalen Vorf\u00e4llen verringern<\/strong> und <strong data-start=\"291\" data-end=\"332\">Organisationen kontrollierbar machen<\/strong>.<\/p>\n<ul data-start=\"336\" data-end=\"547\">\n<li data-start=\"336\" data-end=\"468\">\n<p data-start=\"338\" data-end=\"468\"><strong data-start=\"338\" data-end=\"346\">NIS2<\/strong> zielt auf \u00abwesentliche\u00bb und \u00abwichtige\u00bb Sektoren ab (Energie, Gesundheit, Verkehr, Wasser, Digitales, Verwaltungen usw.).<\/p>\n<\/li>\n<li data-start=\"469\" data-end=\"547\">\n<p data-start=\"471\" data-end=\"547\"><strong data-start=\"471\" data-end=\"479\">DORA<\/strong> zielt auf den <strong data-start=\"489\" data-end=\"510\">Finanzsektor<\/strong> und ihre kritischen ICT-Anbieter.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"549\" data-end=\"735\">In beiden F\u00e4llen: Governance auf F\u00fchrungsebene, Risikomanagement, Vorbereitung auf Vorf\u00e4lle, <strong data-start=\"654\" data-end=\"665\">Beweise<\/strong>verf\u00fcgbar... und <strong data-start=\"686\" data-end=\"703\">Fristen\/Format<\/strong> der Benachrichtigung auf Beh\u00f6rdenseite.<\/p>\n<h2>NIS2 in K\u00fcrze (was die Beh\u00f6rde von Ihnen erwartet)<\/h2>\n<ul data-start=\"864\" data-end=\"1505\">\n<li data-start=\"864\" data-end=\"984\">\n<p data-start=\"866\" data-end=\"984\"><strong data-start=\"866\" data-end=\"888\">Wer ist betroffen?<\/strong> \u00abWesentliche\u00bb Einheiten, die Folgendes besitzen <strong>+50 Angestellte\u00a0<\/strong>oder\u00a0<strong>+10M Umsatz.<\/strong><\/p>\n<\/li>\n<li data-start=\"985\" data-end=\"1337\">\n<p data-start=\"987\" data-end=\"1018\"><strong data-start=\"987\" data-end=\"1016\">Was demonstriert werden muss:<\/strong><\/p>\n<ol data-start=\"1021\" data-end=\"1337\">\n<li data-start=\"1021\" data-end=\"1088\">\n<p data-start=\"1024\" data-end=\"1088\"><strong data-start=\"1024\" data-end=\"1039\">Regierungsf\u00fchrung<\/strong> mit ausdr\u00fccklicher Verantwortung des Managements.<\/p>\n<\/li>\n<li data-start=\"1091\" data-end=\"1151\">\n<p data-start=\"1094\" data-end=\"1151\"><strong data-start=\"1094\" data-end=\"1117\">Umgang mit Risiken<\/strong> (einschlie\u00dflich der <strong data-start=\"1131\" data-end=\"1147\">supply-chain<\/strong>).<\/p>\n<\/li>\n<li data-start=\"1154\" data-end=\"1217\">\n<p data-start=\"1157\" data-end=\"1217\"><strong data-start=\"1157\" data-end=\"1181\">Kontinuit\u00e4t &amp; Reaktion<\/strong> : Verfahren, \u00dcbungen, Beweise.<\/p>\n<\/li>\n<li data-start=\"1220\" data-end=\"1337\">\n<p data-start=\"1223\" data-end=\"1337\"><strong data-start=\"1223\" data-end=\"1250\">Benachrichtigung \u00fcber einen Vorfall<\/strong> in <strong data-start=\"1260\" data-end=\"1279\">eingerahmte Fristen<\/strong> (Fr\u00fchwarnung, Meldung innerhalb von 72 Stunden, Abschlussbericht).<\/p>\n<\/li>\n<\/ol>\n<\/li>\n<li data-start=\"1338\" data-end=\"1505\">\n<p data-start=\"1340\" data-end=\"1505\"><strong data-start=\"1340\" data-end=\"1372\">Was sich im Alltag \u00e4ndert :<\/strong> Nachvollziehbare Entscheidungen, formalisierte Lieferantenanforderungen, fertige Nachrichten, um einen Vorfall zu melden, m\u00f6gliche Kontrollen durch die Beh\u00f6rde (hohe Geldstrafen bei Nichteinhaltung).<\/p>\n<\/li>\n<\/ul>\n<h2>DORA in K\u00fcrze (finanzspezifisch)<\/h2>\n<ul>\n<li data-start=\"1617\" data-end=\"1750\">\n<p data-start=\"1619\" data-end=\"1750\"><strong data-start=\"1619\" data-end=\"1641\">Wer ist betroffen?<\/strong> Banken, Versicherungen, Investmentgesellschaften, verbundene Unternehmen ... und einige <strong data-start=\"1717\" data-end=\"1737\">IKT-Anbieter<\/strong> Kritiker.<\/p>\n<\/li>\n<li data-start=\"1751\" data-end=\"2117\">\n<p data-start=\"1753\" data-end=\"1784\"><strong data-start=\"1753\" data-end=\"1782\">Was demonstriert werden muss:<\/strong><\/p>\n<ol data-start=\"1787\" data-end=\"2117\">\n<li data-start=\"1787\" data-end=\"1836\">\n<p data-start=\"1790\" data-end=\"1836\"><strong data-start=\"1790\" data-end=\"1809\">IKT-Governance<\/strong> von der Gesch\u00e4ftsleitung getragen.<\/p>\n<\/li>\n<li data-start=\"1839\" data-end=\"1925\">\n<p data-start=\"1842\" data-end=\"1925\"><strong data-start=\"1842\" data-end=\"1867\">Verwaltung von Vorf\u00e4llen<\/strong> mit <strong data-start=\"1873\" data-end=\"1896\">harmonisierte Berichterstattung<\/strong> an die Finanzbeh\u00f6rden.<\/p>\n<\/li>\n<li data-start=\"1928\" data-end=\"1995\">\n<p data-start=\"1931\" data-end=\"1995\"><strong data-start=\"1931\" data-end=\"1944\">ICT-Tier<\/strong> : Register, Klauseln, Nachverfolgung, Ausstiegsstrategie.<\/p>\n<\/li>\n<li data-start=\"1998\" data-end=\"2069\">\n<p data-start=\"2001\" data-end=\"2069\"><strong data-start=\"2001\" data-end=\"2024\">Resilienztests<\/strong> regelm\u00e4\u00dfig (bis hin zu fortgeschrittenen Szenarien).<\/p>\n<\/li>\n<li data-start=\"2072\" data-end=\"2117\">\n<p data-start=\"2075\" data-end=\"2117\"><strong data-start=\"2075\" data-end=\"2089\">Kontinuit\u00e4t<\/strong> &amp; Krisenkommunikation.<\/p>\n<\/li>\n<\/ol>\n<\/li>\n<li data-start=\"2118\" data-end=\"2282\">\n<p data-start=\"2120\" data-end=\"2282\"><strong data-start=\"2120\" data-end=\"2152\">Was sich im Alltag \u00e4ndert :<\/strong> Formate und Kan\u00e4le von <strong data-start=\"2174\" data-end=\"2187\">Berichterstattung<\/strong> Die Sch\u00fclerinnen und Sch\u00fcler sollten sich an die Regeln halten, die f\u00fcr sie gelten, die vertraglich geregelten Lieferantenbeziehungen, den Zeitplan f\u00fcr Tests und \u00dcbungen.<\/p>\n<\/li>\n<\/ul>\n<h2>NIS2 vs. DORA: Gleiches Fundament, unterschiedliche Akzente<\/h2>\n<table style=\"caret-color: #000000; color: #000000;\">\n<thead>\n<tr>\n<th>Thema<\/th>\n<th>NIS2<\/th>\n<th>DORA<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Natur<\/td>\n<td>Richtlinie \u00abwesentliche\/wichtige Sektoren\u00bb<\/td>\n<td>Finanzverordnung (gilt unver\u00e4ndert)<\/td>\n<\/tr>\n<tr>\n<td>Leitung<\/td>\n<td>Explizite Rolle, nachvollziehbare Entscheidungen<\/td>\n<td>Dito, + Verantwortung f\u00fcr IKT-Governance<\/td>\n<\/tr>\n<tr>\n<td>Vorf\u00e4lle<\/td>\n<td>Fr\u00fchwarnung, Benachrichtigung, Abschlussbericht<\/td>\n<td>Harmonisierte Berichterstattung + kurze Fristen m\u00f6glich<\/td>\n<\/tr>\n<tr>\n<td>Dritte<\/td>\n<td>Anforderungen an Lieferanten\/Supply-Chain<\/td>\n<td><strong>IKT-Anbieter<\/strong>\u00a0: starke Vertragsbindung &amp; Ausstieg<\/td>\n<\/tr>\n<tr>\n<td>Tests<\/td>\n<td>Regelm\u00e4\u00dfige \u00dcbungen (IR\/BCP)<\/td>\n<td><strong>Resilienztests<\/strong>\u00a0strukturiert, einschlie\u00dflich fortgeschritten<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong data-start=\"2891\" data-end=\"2908\">In der Praxis :<\/strong> eine <strong data-start=\"2912\" data-end=\"2930\">Strukturiertes ISMS<\/strong> (Typ ISO 27001) deckt den Gro\u00dfteil der Basis ab; man f\u00fcgt die Bausteine hinzu <strong data-start=\"3000\" data-end=\"3020\">Fristen\/Reporting<\/strong> und die <strong data-start=\"3027\" data-end=\"3043\">Drittschicht<\/strong> spezifisch f\u00fcr NIS2\/DORA.<\/p>\n<h2>Wie man sich intelligent vorbereitet (ohne die Baustellen zu vervielfachen)<\/h2>\n<p><strong>Status &amp; Umfang<\/strong><\/p>\n<p data-start=\"3171\" data-end=\"3310\">Pr\u00fcfen Sie, ob\/was gilt, kartografieren Sie die betroffenen Aktivit\u00e4ten, Einheiten und Lieferanten, identifizieren Sie die zust\u00e4ndige Beh\u00f6rde (und ihre Formate).<\/p>\n<p><strong>Governance &amp; Beweise<\/strong><\/p>\n<p data-start=\"3341\" data-end=\"3481\">Verantwortliche benennen, dokumentieren <strong data-start=\"3377\" data-end=\"3388\">wie<\/strong> Entscheidungen getroffen werden, Protokolle aufbewahren und Absteckungen von <strong data-start=\"3458\" data-end=\"3480\">periodische Zeitschriften<\/strong>.<\/p>\n<p data-start=\"3341\" data-end=\"3481\"><strong>Vorf\u00e4lle &amp; Kommunikation<\/strong><\/p>\n<p data-start=\"3516\" data-end=\"3662\">Schreiben Sie den <strong data-start=\"3526\" data-end=\"3543\">Gebrauchsanweisung<\/strong> : Erkennung, Qualifizierung, wer warnt wen, Nachrichtenmodelle, Sendekan\u00e4le, <strong data-start=\"3624\" data-end=\"3646\">Fristenuhr<\/strong>, .<\/p>\n<p data-start=\"3516\" data-end=\"3662\"><strong>Dritte &amp; Vertr\u00e4ge<\/strong><\/p>\n<p data-start=\"3688\" data-end=\"3877\">Segmentieren Sie die Lieferanten nach Kritikalit\u00e4t, definieren Sie die <strong data-start=\"3742\" data-end=\"3765\">Mindestanforderungen<\/strong>, Die <strong data-start=\"3780\" data-end=\"3791\">Klauseln<\/strong> (Benachrichtigung, Audits, Sicherheit, Ausstiegsplan) und die Einf\u00fchrung eines <strong data-start=\"3858\" data-end=\"3867\">Nachbereitung<\/strong> regelm\u00e4\u00dfig.<\/p>\n<p data-start=\"3688\" data-end=\"3877\"><strong>Kontinuit\u00e4t &amp; Tests<\/strong><\/p>\n<p>Realistischer Plan B, \u00dcbungen, <strong data-start=\"3933\" data-end=\"3956\">Resilienztests<\/strong> (weiterf\u00fchrend in DORA), Protokollierung der Ergebnisse und getroffenen Entscheidungen.<\/p>\n<h2>Schlussfolgerung<\/h2>\n<p>NIS2 und DORA verlangen weniger nach Versprechungen als nach <strong data-start=\"5549\" data-end=\"5560\">Beweise<\/strong> : lesbare Governance, rechtzeitig verwaltete und gemeldete Vorf\u00e4lle, Dritte unter Kontrolle, getestete Kontinuit\u00e4t. Mit einer Grundlage wie <strong data-start=\"5690\" data-end=\"5703\">ISO 27001<\/strong> und eine Fokussierung auf <strong data-start=\"5729\" data-end=\"5755\">Fristen\/Reporting\/Drittmittel<\/strong>, Sie sind bereit - auch am Tag der Pr\u00fcfung.<\/p>\n<p>Sie wollen einen <strong data-start=\"5827\" data-end=\"5857\">Blindkontrolle NIS2\/DORA<\/strong> und einen priorisierten Fahrplan? Lassen Sie uns dar\u00fcber sprechen.<\/p>","protected":false},"excerpt":{"rendered":"<p>Pourquoi on parle autant de NIS2 et DORA Deux textes europ\u00e9ens, deux objectifs voisins : r\u00e9duire les impacts d\u2019incidents num\u00e9riques et rendre les organisations contr\u00f4lables. NIS2 vise les secteurs \u00ab essentiels \u00bb et \u00ab importants \u00bb (\u00e9nergie, sant\u00e9, transports, eau, num\u00e9rique, administrations, etc.). DORA cible le secteur financier et ses prestataires TIC critiques. Dans les [&hellip;]<\/p>","protected":false},"author":3,"featured_media":3224,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[22],"tags":[],"class_list":["post-3219","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pilotage-conformite"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS2 &amp; DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te - Phishia<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/phishia.fr\/de\/blog\/steuerung-der-konformitat\/nis2-dora-obligations-ue\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2 &amp; DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te - Phishia\" \/>\n<meta property=\"og:description\" content=\"Pourquoi on parle autant de NIS2 et DORA Deux textes europ\u00e9ens, deux objectifs voisins : r\u00e9duire les impacts d\u2019incidents num\u00e9riques et rendre les organisations contr\u00f4lables. NIS2 vise les secteurs \u00ab essentiels \u00bb et \u00ab importants \u00bb (\u00e9nergie, sant\u00e9, transports, eau, num\u00e9rique, administrations, etc.). DORA cible le secteur financier et ses prestataires TIC critiques. Dans les [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/phishia.fr\/de\/blog\/steuerung-der-konformitat\/nis2-dora-obligations-ue\/\" \/>\n<meta property=\"og:site_name\" content=\"Phishia\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-28T14:52:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-31T08:09:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/10\/nis2-dora.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"864\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"3\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/\"},\"author\":{\"name\":\"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/#\\\/schema\\\/person\\\/ab1f38ad06f750da69863e8f06e86528\"},\"headline\":\"NIS2 &#038; DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te\",\"datePublished\":\"2025-10-28T14:52:22+00:00\",\"dateModified\":\"2025-10-31T08:09:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/\"},\"wordCount\":611,\"publisher\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/phishia.fr\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/nis2-dora.png\",\"articleSection\":[\"Pilotage et conformit\u00e9\"],\"inLanguage\":\"de\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/\",\"url\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/\",\"name\":\"NIS2 & DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te - Phishia\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/phishia.fr\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/nis2-dora.png\",\"datePublished\":\"2025-10-28T14:52:22+00:00\",\"dateModified\":\"2025-10-31T08:09:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#primaryimage\",\"url\":\"https:\\\/\\\/phishia.fr\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/nis2-dora.png\",\"contentUrl\":\"https:\\\/\\\/phishia.fr\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/nis2-dora.png\",\"width\":1536,\"height\":864},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/pilotage-conformite\\\/nis2-dora-obligations-ue\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/phishia.fr\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Pilotage et conformit\u00e9\",\"item\":\"https:\\\/\\\/phishia.fr\\\/blog\\\/category\\\/pilotage-conformite\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"NIS2 &#038; DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/#website\",\"url\":\"https:\\\/\\\/phishia.fr\\\/\",\"name\":\"Phishia\",\"description\":\"Cabinet de Conseil IT, Cybers\u00e9curit\u00e9, Durabilit\u00e9\",\"publisher\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/phishia.fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/#organization\",\"name\":\"Phishia\",\"url\":\"https:\\\/\\\/phishia.fr\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/phishia.fr\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/Logotype.png\",\"contentUrl\":\"https:\\\/\\\/phishia.fr\\\/wp-content\\\/uploads\\\/2025\\\/01\\\/Logotype.png\",\"width\":512,\"height\":128,\"caption\":\"Phishia\"},\"image\":{\"@id\":\"https:\\\/\\\/phishia.fr\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/phishia\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/phishia.fr\\\/#\\\/schema\\\/person\\\/ab1f38ad06f750da69863e8f06e86528\",\"name\":\"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIS2 &amp; DORA: EU-Verpflichtungen, Schl\u00fcsselunterschiede, konkreter Fahrplan - Phishia","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/phishia.fr\/de\/blog\/steuerung-der-konformitat\/nis2-dora-obligations-ue\/","og_locale":"de_DE","og_type":"article","og_title":"NIS2 & DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te - Phishia","og_description":"Pourquoi on parle autant de NIS2 et DORA Deux textes europ\u00e9ens, deux objectifs voisins : r\u00e9duire les impacts d\u2019incidents num\u00e9riques et rendre les organisations contr\u00f4lables. NIS2 vise les secteurs \u00ab essentiels \u00bb et \u00ab importants \u00bb (\u00e9nergie, sant\u00e9, transports, eau, num\u00e9rique, administrations, etc.). DORA cible le secteur financier et ses prestataires TIC critiques. Dans les [&hellip;]","og_url":"https:\/\/phishia.fr\/de\/blog\/steuerung-der-konformitat\/nis2-dora-obligations-ue\/","og_site_name":"Phishia","article_published_time":"2025-10-28T14:52:22+00:00","article_modified_time":"2025-10-31T08:09:07+00:00","og_image":[{"width":1536,"height":864,"url":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/10\/nis2-dora.png","type":"image\/png"}],"author":"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9","twitter_card":"summary_large_image","twitter_misc":{"Verfasst von":"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9","Gesch\u00e4tzte Lesezeit":"3\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#article","isPartOf":{"@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/"},"author":{"name":"Enzo Debosque, consultant junior en CyberS\u00e9curit\u00e9","@id":"https:\/\/phishia.fr\/#\/schema\/person\/ab1f38ad06f750da69863e8f06e86528"},"headline":"NIS2 &#038; DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te","datePublished":"2025-10-28T14:52:22+00:00","dateModified":"2025-10-31T08:09:07+00:00","mainEntityOfPage":{"@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/"},"wordCount":611,"publisher":{"@id":"https:\/\/phishia.fr\/#organization"},"image":{"@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#primaryimage"},"thumbnailUrl":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/10\/nis2-dora.png","articleSection":["Pilotage et conformit\u00e9"],"inLanguage":"de"},{"@type":"WebPage","@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/","url":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/","name":"NIS2 &amp; DORA: EU-Verpflichtungen, Schl\u00fcsselunterschiede, konkreter Fahrplan - Phishia","isPartOf":{"@id":"https:\/\/phishia.fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#primaryimage"},"image":{"@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#primaryimage"},"thumbnailUrl":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/10\/nis2-dora.png","datePublished":"2025-10-28T14:52:22+00:00","dateModified":"2025-10-31T08:09:07+00:00","breadcrumb":{"@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/"]}]},{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#primaryimage","url":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/10\/nis2-dora.png","contentUrl":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/10\/nis2-dora.png","width":1536,"height":864},{"@type":"BreadcrumbList","@id":"https:\/\/phishia.fr\/blog\/pilotage-conformite\/nis2-dora-obligations-ue\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/phishia.fr\/"},{"@type":"ListItem","position":2,"name":"Pilotage et conformit\u00e9","item":"https:\/\/phishia.fr\/blog\/category\/pilotage-conformite\/"},{"@type":"ListItem","position":3,"name":"NIS2 &#038; DORA : obligations UE, diff\u00e9rences cl\u00e9s, feuille de route concr\u00e8te"}]},{"@type":"WebSite","@id":"https:\/\/phishia.fr\/#website","url":"https:\/\/phishia.fr\/","name":"Phishia","description":"IT-Beratung, Cybersicherheit, Nachhaltigkeit","publisher":{"@id":"https:\/\/phishia.fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/phishia.fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de"},{"@type":"Organization","@id":"https:\/\/phishia.fr\/#organization","name":"Phishia","url":"https:\/\/phishia.fr\/","logo":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/phishia.fr\/#\/schema\/logo\/image\/","url":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/01\/Logotype.png","contentUrl":"https:\/\/phishia.fr\/wp-content\/uploads\/2025\/01\/Logotype.png","width":512,"height":128,"caption":"Phishia"},"image":{"@id":"https:\/\/phishia.fr\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/phishia\/"]},{"@type":"Person","@id":"https:\/\/phishia.fr\/#\/schema\/person\/ab1f38ad06f750da69863e8f06e86528","name":"Enzo Debosque, Juniorberater f\u00fcr Cybersicherheit"}]}},"_links":{"self":[{"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/posts\/3219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/comments?post=3219"}],"version-history":[{"count":5,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/posts\/3219\/revisions"}],"predecessor-version":[{"id":3342,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/posts\/3219\/revisions\/3342"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/media\/3224"}],"wp:attachment":[{"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/media?parent=3219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/categories?post=3219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/phishia.fr\/de\/wp-json\/wp\/v2\/tags?post=3219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}