NIS2 and DORA can affect a Latin American supplier without automatically making it a regulated entity. The usual mechanism is contractual: the European entity within scope must govern its supply chain or ICT risk and passes on part of that requirement to the supplier through information, controls, notification, continuity, auditing and exit arrangements. Legal scope and contractual requirements are two distinct dimensions. Confusing them overstates the legislation and weakens the conversation with the client.


NIS2 · entities within scope must examine their direct suppliers

NIS2 is a directive. Its specific application depends on its text and each Member State's transposition. Essential and important entities within its scope must adopt proportionate cybersecurity risk management measures. Article 21 includes supply chain security, with attention to the relationship between each entity and its direct suppliers or service providers.

The directive encourages incorporating these measures into contractual agreements with direct suppliers. This is why a Latin American supplier may receive a questionnaire, a notification clause, continuity requirements or a security assessment. The requirement stems from the client's duty; it does not in itself demonstrate that the supplier is directly subject to NIS2.

A European cybersecurity regulation does not need to apply directly to a Latin American company to affect its contracts. It only needs to apply to that company's European clients.

DORA · the contract is part of ICT risk control

DORA has applied since 17 January 2025 to financial entities within its scope. Its articles 28 to 30 set out ICT third-party risk management requirements: strategy, register of arrangements, prior assessment, concentration, subcontracting, contractual provisions and exit.

When the ICT service supports a critical or important function, the contract must incorporate enhanced obligations, including cooperation, security measures, continuity, testing, access, inspection and auditing, as well as an exit strategy. These rights belong to the financial entity, its designated third party or the competent authority, as applicable. The provider assumes them because it signs the contract.

DORA also establishes direct oversight for ICT providers formally designated as critical under article 31. This designation is specific; it does not extend to every provider simply because it serves a financial entity. A third-country provider designated as critical is also subject to the conditions established for maintaining a presence in the Union.

NIS2 and DORA, side by side

DimensionNIS2DORA
Legal natureDirective · requires national transposition in each Member StateRegulation · direct and identical application throughout the EU
Direct addresseeEssential or important entities under the directive and national transpositionFinancial entities included in the regulation; additional regime for ICT third parties designated as critical
Relationship with third partiesSupply chain security, including relationships with direct suppliers and service providersComprehensive ICT third-party risk management and enhanced clauses for critical or important functions
Possible contractual effectSecurity, evidence, incident and continuity requirements defined by the entity within scopeInformation, cooperation, testing, access, auditing, subcontracting and exit arrangements depending on the service
Legal effect on a LATAM supplierNot automatic; requires analysis of the applicable legislation and the supplier's specific positionNot automatic; there may be a direct effect if the third party is designated as critical and the regulation's conditions are met

ISO/IEC 27001 as a system of control and evidence

Fact sheet

A useful system, with clear limitations

ISO/IEC 27001 can help organise responsibilities, risks, controls, auditing and improvement. Certification can provide relevant evidence for a client, but does not in itself demonstrate compliance with NIS2, DORA, national transposition or a contract. The gap must be mapped requirement by requirement.

What to review in contracts

If your organisation provides technology, financial or infrastructure services to European clients, review active contracts and identify which of those clients have obligations under NIS2 or DORA. If the answer is yes, the contract may already include — or include at the next renewal — cybersecurity audit clauses. Preparing beforehand costs less than responding while the contract is under discussion.

The review must separate four questions: whether the client is legally within scope; what function the supplier performs; what obligations appear in the contract; and what evidence exists today. Only then should a decision be made on whether an ISO/IEC 27001 system, additional controls or a specific legal review addresses the gap.