NIS2 & DORA: what changes for mid-market teams

A clear explanation of the obligations, deadlines and how to document them efficiently — without doubling the workload.

The iComply Team
AI Governance

NIS2 & DORA

NIS2 and DORA have drastically broadened the scope of European cybersecurity regulation. Many medium-sized organisations that were never previously ‘covered’ are now covered — and the obligations are very real, with management held accountable. Here’s what’s changing and how to deal with both without running two programmes.

NIS2 in a nutshell

NIS2 raises the bar for cybersecurity risk management to cover a much wider range of ‘essential’ and ‘important’ organisations. It requires governance, risk management measures, incident handling and reporting, supply chain security and business continuity — with senior management responsible for oversight.

DORA in a paragraph

DORA aims to promote digital operational resilience in the financial sector and amongst its ICT suppliers. It covers ICT risk management, incident reporting, resilience testing and — notably — third-party ICT risk, including a register of suppliers and concentration risk.

Where they overlap

Ambos exigem forte gestão de risco TIC, resposta a incidentes e supervisão de fornecedores. If you run them separately, you’ll end up writing the same policies and gathering the same evidence twice. If they are run on shared controls, an access review or incident response control will highlight both.

  • Governance — identified responsible parties and oversight of management.
  • Risk management — a living record, not an annual document.
  • Incident management — detection, response and reporting to the regulator.
  • Third-party risk — supplier due diligence and ongoing monitoring.

How to highlight effectively

Map the NIS2 and DORA requirements to a library of controls, assign responsible parties, collect evidence once, and let the platform display the coverage of both frameworks side by side. Out-of-date evidence and overdue tasks should be escalated automatically — manual follow-up does not meet the requirements of both regulations.

Here’s how iComply puts this into practice

A platform for every regulation, law and risk — focused on controls and powered by AI.

Read on

Two interconnected circles representing the relationship between the ISO 42001 standard and the European AI Regulation

A management system meets a regulation — and why you operationalise both as a single AI governance suite.

Bar chart showing salaries within a defined range, illustrating an analysis of the gender pay gap at iComply

Analysis of pay gaps, pay bands and auditable remuneration criteria — what to implement now.

Seven ascending layers representing the stages involved in building a unified governance programme with iComply

A step-by-step approach to scope, controls, evidence and ongoing assurance — designed to be scalable across domains.