NIS2 and DORA can affect a Latin American supplier without automatically making it a regulated entity. The usual mechanism is contractual: the European entity within scope must govern its supply chain or ICT risk and passes on part of that requirement to the supplier through information, controls, notification, continuity, auditing and exit arrangements. Legal scope and contractual requirements are two distinct dimensions. Confusing them overstates the legislation and weakens the conversation with the client.
NIS2 · entities within scope must examine their direct suppliers
NIS2 is a directive. Its specific application depends on its text and each Member State's transposition. Essential and important entities within its scope must adopt proportionate cybersecurity risk management measures. Article 21 includes supply chain security, with attention to the relationship between each entity and its direct suppliers or service providers.
The directive encourages incorporating these measures into contractual agreements with direct suppliers. This is why a Latin American supplier may receive a questionnaire, a notification clause, continuity requirements or a security assessment. The requirement stems from the client's duty; it does not in itself demonstrate that the supplier is directly subject to NIS2.
DORA · the contract is part of ICT risk control
DORA has applied since 17 January 2025 to financial entities within its scope. Its articles 28 to 30 set out ICT third-party risk management requirements: strategy, register of arrangements, prior assessment, concentration, subcontracting, contractual provisions and exit.
When the ICT service supports a critical or important function, the contract must incorporate enhanced obligations, including cooperation, security measures, continuity, testing, access, inspection and auditing, as well as an exit strategy. These rights belong to the financial entity, its designated third party or the competent authority, as applicable. The provider assumes them because it signs the contract.
DORA also establishes direct oversight for ICT providers formally designated as critical under article 31. This designation is specific; it does not extend to every provider simply because it serves a financial entity. A third-country provider designated as critical is also subject to the conditions established for maintaining a presence in the Union.
NIS2 and DORA, side by side
| Dimension | NIS2 | DORA |
|---|---|---|
| Legal nature | Directive · requires national transposition in each Member State | Regulation · direct and identical application throughout the EU |
| Direct addressee | Essential or important entities under the directive and national transposition | Financial entities included in the regulation; additional regime for ICT third parties designated as critical |
| Relationship with third parties | Supply chain security, including relationships with direct suppliers and service providers | Comprehensive ICT third-party risk management and enhanced clauses for critical or important functions |
| Possible contractual effect | Security, evidence, incident and continuity requirements defined by the entity within scope | Information, cooperation, testing, access, auditing, subcontracting and exit arrangements depending on the service |
| Legal effect on a LATAM supplier | Not automatic; requires analysis of the applicable legislation and the supplier's specific position | Not automatic; there may be a direct effect if the third party is designated as critical and the regulation's conditions are met |
ISO/IEC 27001 as a system of control and evidence
A useful system, with clear limitations
ISO/IEC 27001 can help organise responsibilities, risks, controls, auditing and improvement. Certification can provide relevant evidence for a client, but does not in itself demonstrate compliance with NIS2, DORA, national transposition or a contract. The gap must be mapped requirement by requirement.
What to review in contracts
If your organisation provides technology, financial or infrastructure services to European clients, review active contracts and identify which of those clients have obligations under NIS2 or DORA. If the answer is yes, the contract may already include — or include at the next renewal — cybersecurity audit clauses. Preparing beforehand costs less than responding while the contract is under discussion.
The review must separate four questions: whether the client is legally within scope; what function the supplier performs; what obligations appear in the contract; and what evidence exists today. Only then should a decision be made on whether an ISO/IEC 27001 system, additional controls or a specific legal review addresses the gap.