NIS2 & DORA // MAPPING

WHICH REQUIREMENT
WHICH SERVICE COVERS.

NIS2 and DORA demand demonstrable technical measures, not just paperwork. This page maps the requirements to our services: article by article, and honest about the ones we contribute nothing to.

01 POSITIONING

WE ARE NOT A COMPLIANCE CONSULTANCY.

Deliberately so. We do not produce ISO-style gap analyses, run certification audits or replace legal advice. What we deliver are the technical measures and the evidence both regulations ask for: finding and prioritising exposure, simulating real attacks, detecting and responding to incidents, controlling access. If you need formal compliance guidance, engage it separately; we will feed into it.

Why this matters: NIS2 Article 21(2)(f) requires policies and procedures for assessing the effectiveness of your own risk-management measures. The directive prescribes no method for it, but effectiveness cannot be demonstrated through documentation. It requires execution and evidence, and penetration testing is the established means of producing both.

02 NIS2: ARTICLE 21(2)

THE TEN MEASURES.

Article 21 of the NIS2 Directive (EU 2022/2555) obliges in-scope entities to implement ten categories of risk-management measures. Here is where our services fit:

ART. 21(2)(A)

Risk analysis & information system security policies

Systematically identify, assess and treat risks to network and information systems.

ART. 21(2)(B)

Incident handling

Detect, analyse, contain and respond to incidents, including detection and response processes.

ART. 21(2)(C)

Business continuity, backup & crisis management

Keeping operations running, recovering from outages, organising for a crisis.

ART. 21(2)(D)

Supply chain security

Managing cybersecurity risk arising from direct suppliers and service providers.

ART. 21(2)(E)

Security in acquisition, development & maintenance

Including vulnerability handling and disclosure across the whole lifecycle.

ART. 21(2)(F)

Assessing the effectiveness of the measures

What is required are policies and procedures for assessing effectiveness: no method is prescribed. Penetration testing and red-team exercises are an established means of doing so; the choice is yours.

ART. 21(2)(G)

Cyber hygiene & training

Basic practices and staff awareness.

Phishing simulation Training: not in our portfolio
ART. 21(2)(H)

Cryptography & encryption

Policies and procedures on the use of cryptographic measures.

Not offered as a distinct service
ART. 21(2)(I)

Human resources security, access control & asset management

Who may access what and is the asset inventory even known?

ART. 21(2)(J)

Multi-factor authentication & secured communications

MFA or continuous authentication, secured voice, video and text communication.

03 DORA: REGULATION (EU) 2022/2554

DIGITAL OPERATIONAL RESILIENCE.

DORA applies to financial entities and their ICT providers. The regulation is organised in chapters; our services feed mainly into three of them:

CHAPTER II · ART. 5–16

ICT risk management

Identify, protect, detect: continuous assessment of ICT risk and attack surface.

CHAPTER III · ART. 17–23

ICT-related incident management & reporting

Detect, classify and report incidents within tight deadlines: which presupposes reliable detection.

CHAPTER IV · ART. 24–27

Digital operational resilience testing

Regular testing, plus threat-led penetration testing (TLPT) under Art. 26–27 for certain entities.

CHAPTER V · ART. 28–44

ICT third-party risk management

Governing and monitoring risk from outsourcing and provider relationships.

On TLPT: Threat-led penetration testing under DORA Art. 26 is subject to specific requirements for testers in Art. 27. Our red-team methodology follows TIBER-EU; whether a given engagement can be run as a formal TLPT in the meaning of the regulation is something we clarify openly upfront, with you and your supervisory authority.

● NIS2 · DORA · KRITIS

WHICH REQUIREMENTS HIT YOU: AND WHAT IS STILL MISSING?

A free 30-minute call: we walk through which of the measures above you can already evidence and where the technical gaps are. No sales pressure: if nothing of ours fits, we will say so.