EU regulations are putting real pressure on how organizations protect and recover their data. If you run Kubernetes workloads in financial services, insurance, healthcare, energy, telco, and public administration, your backup strategy is no longer just an IT concern. It is something regulators and auditors can examine directly.
Most Kubernetes environments were set up for operational convenience rather than compliance. You may have snapshots running, maybe even a Velero script, but that is often not enough to satisfy what regulators look for. If you have no immutable storage, no centralized audit log or no tested recovery time you are not compliant.
What are NIS2 and DORA?
NIS2 (Network and Information Security Directive 2) has been in effect across EU member states since October 2024. Organizations must document risk management measures, maintain incident response plans, and submit an initial breach notification within 24 hours, followed by a full report. Fines for non-compliance can reach €10 million or 2% of global annual turnover.
DORA (Digital Operational Resilience Act) applies specifically to financial entities and their ICT providers. Enforceable since January 2025, it requires organizations to define and meet recovery time and point objectives, conduct resilience testing, and maintain detailed audit trails.
Both require proof that you can recover data, not just a claim that you can.
What this means for Kubernetes backup
Most Kubernetes environments rely on CSI snapshots, Velero, or storage-level replication. None of these fully satisfy what regulators expect. Here is where the gaps typically appear:
- Snapshots are not backups. They are cluster- and storage-scoped, with no retention enforcement or off-cluster copy. If the cluster fails, the snapshots go with it.
- No audit trail. Most DIY setups have no centralized log of who triggered a backup, what was restored, or when policies changed.
- No documented RTO/RPO. DORA expects organizations to define recovery objectives and demonstrate they can meet them.
- No immutability. Without immutable storage, backups can be deleted or altered, whether by ransomware or by accident.
- Data residency gaps. If backup data crosses EU borders without controls, you may fail data sovereignty requirements under both frameworks.
How CloudCasa covers the compliance requirements
CloudCasa is available as a SaaS platform or as a fully self-hosted deployment, which matters for organizations with EU data residency or air-gap requirements. Here is what that looks like in practice:
- Immutable backups. CloudCasa stores backups in object storage of your choice and makes them immutable. Backups cannot be deleted or modified during the retention period, directly supporting NIS2 risk management and DORA resilience requirements.
- Audit logs and RBAC. Role-based access control and audit logging are built in. You have a clear record of who did what and when, which is what an auditor will ask for.
- Testable RTO/RPO. CloudCasa supports disaster recovery with select storage integrations. Recovery workflows are guided and repeatable, so you can test and document results.
- Data residency control. The self-hosted option keeps all backup data within your own infrastructure, in your chosen region. No data leaves your environment unless you decide it does.
- Centralized governance. One control plane manages backup policy across all clusters. Set the policy once, apply it everywhere, and report on compliance across your entire estate.
Who this applies to
If your organization operates in the EU, or provides services to EU entities, and runs Kubernetes, you are likely in scope for NIS2, DORA, or both. The most directly affected sectors include financial services, insurance, healthcare, energy, telco, and public administration. The definition of “important entity” under NIS2 is broad enough to include many mid-sized technology and infrastructure companies as well.
See it for yourself
CloudCasa gives you the backup controls, audit evidence, and recovery capability that NIS2 and DORA require, without the cost and complexity of traditional enterprise backup tools. You can start with a free trial of the SaaS version for 60 days or deploy self-hosted if your environment requires it.
CloudCasa is a cost-effective way to meet compliance-grade backup and recovery requirements, and we are happy to walk you through what that looks like in your environment.
Start your free 60-day trial here.



