NIS2 & DORA
NIS2 and DORA have drastically broadened the scope of European cybersecurity regulation. Many medium-sized organisations that were never previously ‘covered’ are now covered — and the obligations are very real, with management held accountable. Here’s what’s changing and how to deal with both without running two programmes.
NIS2 in a nutshell
NIS2 raises the bar for cybersecurity risk management to cover a much wider range of ‘essential’ and ‘important’ organisations. It requires governance, risk management measures, incident handling and reporting, supply chain security and business continuity — with senior management responsible for oversight.
DORA in a paragraph
DORA aims to promote digital operational resilience in the financial sector and amongst its ICT suppliers. It covers ICT risk management, incident reporting, resilience testing and — notably — third-party ICT risk, including a register of suppliers and concentration risk.
Where they overlap
Ambos exigem forte gestão de risco TIC, resposta a incidentes e supervisão de fornecedores. If you run them separately, you’ll end up writing the same policies and gathering the same evidence twice. If they are run on shared controls, an access review or incident response control will highlight both.
- Governance — identified responsible parties and oversight of management.
- Risk management — a living record, not an annual document.
- Incident management — detection, response and reporting to the regulator.
- Third-party risk — supplier due diligence and ongoing monitoring.
How to highlight effectively
Map the NIS2 and DORA requirements to a library of controls, assign responsible parties, collect evidence once, and let the platform display the coverage of both frameworks side by side. Out-of-date evidence and overdue tasks should be escalated automatically — manual follow-up does not meet the requirements of both regulations.