Consulting · European regulation

Compliance DORA and NIS2

We analyze how DORA and NIS2 affect you, close the gaps and help you demonstrate compliance to clients and supervisors.

The regulation

What DORA and NIS2 are and who they apply to

NIS2 is the European directive that extends cybersecurity obligations to many more sectors: energy, transport, health, water, digital infrastructure, public administration, manufacturing and food, among others. It mainly affects medium-sized and large companies in those sectors.

DORA is the European regulation on digital operational resilience for the financial sector. It has applied since January 17, 2025 to banks, insurers, payment institutions, asset managers and other financial entities, and it also reaches the ICT providers that serve them.

Neither can be certified like an ISO standard: you comply with them and demonstrate it to supervisors and clients. A well-implemented ISO 27001 is the best foundation for doing so.

Does it apply to you?

Tick everything that applies to your organization.

Tick at least one option.

Frequently asked questions

What people ask us before getting started

No. There is no official DORA or NIS2 certificate: you comply with them and demonstrate it to supervisors and clients. Certifications such as ISO 27001 or the ENS help prove it.

Cybersecurity risk management measures, reporting of significant incidents with an early warning within 24 hours, supply chain security and direct accountability for management.

A technology risk management framework, reporting of major incidents, regular resilience testing and oversight of ICT providers, with a register of all contracts with them.

Indirectly, yes. Both regulations require companies to oversee their suppliers' security, so your clients will ask you for guarantees, contract clauses and, often, certifications.

Penalties can be high. Under NIS2 they can reach €10 million or 2% of total worldwide annual turnover for essential entities, and management can be held personally liable.

With a gap analysis: we look at what applies to you, what you already have covered and what is missing, and turn it into a prioritized work plan.

Shall we talk about your compliance?

Tell us where you stand and we'll explain what you still need to comply.