Compliance · MFT

MFT, NIS2 and DORA: from regulation to operational controls

NIS2 and DORA do not prescribe a specific MFT product. They do make clear why critical file transfer needs demonstrable governance, recoverability and operational control.

Quick answer

Do not use MFT as a compliance label. Use it where appropriate as a technical management layer for controls around identity, monitoring, recovery, audit evidence and third parties.

Source status

What is sourced fact and what is our analysis?

The legal sources are primary: NIS2 and DORA via EUR-Lex. The mapping to file-transfer controls is operational interpretation by Boermans Digital and not legal advice.

Read the editorial methodology and corrections policy.

NIS2

What NIS2 actually asks for

NIS2 is broader than file transfer. For transfer chains, the relevant themes include risk management, incident handling, business continuity, supply-chain security, cryptography, access control and assessing control effectiveness.

Practical mapping; not legal advice.
NIS2 themeFile-transfer translation
Incident handlingDetect failed or suspicious transfers and document escalation.
Business continuityDefine recovery, replay, alternative routes and dependencies.
Supply-chain securityManage external partners, accounts, certificates and agreements demonstrably.
CryptographyUse appropriate transport and, where relevant, at-rest encryption with lifecycle management.
Access controlUse roles, least privilege and clear service identities.
EffectivenessMeasure whether controls work: failures, recovery time, exceptions and review.
DORA

What DORA adds for financial organisations

DORA places strong emphasis on ICT risk management, operational resilience, incidents and third-party risk. File transfer can be part of that ICT chain when files support critical processes.

  • Identify which transfers support critical or important functions.
  • Understand dependencies on third parties and infrastructure.
  • Define availability, integrity, authenticity and confidentiality as operational requirements.
  • Test recovery and continuity rather than only documenting configuration.
  • Ensure incident data and transfer logs provide enough context for investigation.
  • Keep organisational accountability explicit when using outsourced or managed services.
Controls

A minimum control set for critical file transfer

Use regulation as a reason to govern the chain, not as a checklist for product features.

Operational control set for discovery; interpretation remains context-dependent.
ControlQuestion
InventoryWhich critical flows exist and who owns them?
IdentityWhich human and machine identities may send or receive?
PolicyWhich data types may travel through which route?
ObservabilityCan you evidence end-to-end status and failures?
RecoveryCan you replay safely without duplicates or data loss?
EvidenceCan you reconstruct timeline, actor, policy and recovery action?
Third partiesAre partner obligations, changes and escalations documented?
Boundary

MFT is a control enabler, not a compliance status

An MFT platform can centralise controls otherwise scattered across scripts, servers and applications. Governance, process, contracts, scope and configuration remain decisive.

So do not ask “which MFT product is NIS2/DORA compliant?” Ask “which concrete control must we implement demonstrably, who owns it and what evidence must be available?”

Next step

Assess first or discuss it directly?

Use the MFT Scan to structure risk and modernisation signals. If you already have a concrete transfer chain, discuss it directly.

Self-assess

Map the transfer-chain risks

The scan stays local in your browser and does not ask for sensitive transfer data.

Start the MFT Scan
Concrete question

Discuss one transfer chain

Describe source, destination, frequency and the issue. A complete design is not required.

Discuss my MFT question

Official and technical sources

This page uses primary or technical sources for definitions and regulatory frameworks. A source reference does not mean a specific product automatically meets those requirements.

FAQ

Frequently asked questions

Does MFT make you NIS2 compliant?

No. NIS2 sets organisational and technical cybersecurity risk-management requirements. MFT can support controls around transfer, logging, access, continuity and suppliers, but it is not a compliance certificate.

Is DORA only relevant to banks?

DORA applies to financial entities and specific ICT third-party providers within the scope of the regulation. Always determine legally and organisationally whether your organisation is in scope.

Which MFT data helps audit and incident analysis?

For example actor or service account, source, destination, timestamp, status, file/flow ID, protocol, error code, retry/replay, policy decision and any manual intervention.