WHICH REQUIREMENT
WHICH SERVICE COVERS.
NIS2 and DORA demand demonstrable technical measures, not just paperwork. This page maps the requirements to our services: article by article, and honest about the ones we contribute nothing to.
WE ARE NOT A COMPLIANCE CONSULTANCY.
Deliberately so. We do not produce ISO-style gap analyses, run certification audits or replace legal advice. What we deliver are the technical measures and the evidence both regulations ask for: finding and prioritising exposure, simulating real attacks, detecting and responding to incidents, controlling access. If you need formal compliance guidance, engage it separately; we will feed into it.
Why this matters: NIS2 Article 21(2)(f) requires policies and procedures for assessing the effectiveness of your own risk-management measures. The directive prescribes no method for it, but effectiveness cannot be demonstrated through documentation. It requires execution and evidence, and penetration testing is the established means of producing both.
THE TEN MEASURES.
Article 21 of the NIS2 Directive (EU 2022/2555) obliges in-scope entities to implement ten categories of risk-management measures. Here is where our services fit:
Risk analysis & information system security policies
Systematically identify, assess and treat risks to network and information systems.
Incident handling
Detect, analyse, contain and respond to incidents, including detection and response processes.
Business continuity, backup & crisis management
Keeping operations running, recovering from outages, organising for a crisis.
Supply chain security
Managing cybersecurity risk arising from direct suppliers and service providers.
Security in acquisition, development & maintenance
Including vulnerability handling and disclosure across the whole lifecycle.
Assessing the effectiveness of the measures
What is required are policies and procedures for assessing effectiveness: no method is prescribed. Penetration testing and red-team exercises are an established means of doing so; the choice is yours.
Cyber hygiene & training
Basic practices and staff awareness.
Cryptography & encryption
Policies and procedures on the use of cryptographic measures.
Human resources security, access control & asset management
Who may access what and is the asset inventory even known?
Multi-factor authentication & secured communications
MFA or continuous authentication, secured voice, video and text communication.
DIGITAL OPERATIONAL RESILIENCE.
DORA applies to financial entities and their ICT providers. The regulation is organised in chapters; our services feed mainly into three of them:
ICT risk management
Identify, protect, detect: continuous assessment of ICT risk and attack surface.
ICT-related incident management & reporting
Detect, classify and report incidents within tight deadlines: which presupposes reliable detection.
Digital operational resilience testing
Regular testing, plus threat-led penetration testing (TLPT) under Art. 26–27 for certain entities.
ICT third-party risk management
Governing and monitoring risk from outsourcing and provider relationships.
On TLPT: Threat-led penetration testing under DORA Art. 26 is subject to specific requirements for testers in Art. 27. Our red-team methodology follows TIBER-EU; whether a given engagement can be run as a formal TLPT in the meaning of the regulation is something we clarify openly upfront, with you and your supervisory authority.
WHICH REQUIREMENTS HIT YOU: AND WHAT IS STILL MISSING?
A free 30-minute call: we walk through which of the measures above you can already evidence and where the technical gaps are. No sales pressure: if nothing of ours fits, we will say so.