{"id":2832,"date":"2026-07-06T13:26:00","date_gmt":"2026-07-06T12:26:00","guid":{"rendered":"https:\/\/icomply.pm\/resources\/article-nis2-dora\/"},"modified":"2026-09-08T12:23:02","modified_gmt":"2026-09-08T11:23:02","slug":"article-nis2-dora","status":"publish","type":"post","link":"https:\/\/icomply.pt\/en\/resources\/article-nis2-dora\/","title":{"rendered":"NIS2 &#038; DORA: what changes for mid-market teams"},"content":{"rendered":"<h2 data-dc-tpl=\"25\">NIS2 &#038; DORA<\/h2>\n<p data-dc-tpl=\"25\">NIS2 and DORA have drastically broadened the scope of European cybersecurity regulation. Many medium-sized organisations that were never previously \u2018covered\u2019 are now covered \u2014 and the obligations are very real, with management held accountable. Here\u2019s what\u2019s changing and how to deal with both without running two programmes.  <\/p>\n<h2 data-dc-tpl=\"26\">NIS2 in a nutshell<\/h2>\n<p data-dc-tpl=\"27\">NIS2 raises the bar for cybersecurity risk management to cover a much wider range of \u2018essential\u2019 and \u2018important\u2019 organisations. It requires governance, risk management measures, incident handling and reporting, supply chain security and business continuity \u2014 with senior management responsible for oversight. <\/p>\n<h2 data-dc-tpl=\"28\">DORA in a paragraph<\/h2>\n<p data-dc-tpl=\"29\">DORA aims to promote digital operational resilience in the financial sector and amongst its ICT suppliers. It covers ICT risk management, incident reporting, resilience testing and \u2014 notably \u2014 third-party ICT risk, including a register of suppliers and concentration risk. <\/p>\n<h2 data-dc-tpl=\"30\">Where they overlap<\/h2>\n<p data-dc-tpl=\"31\">Ambos exigem forte gest\u00e3o de risco TIC, resposta a incidentes e supervis\u00e3o de fornecedores. If you run them separately, you\u2019ll end up writing the same policies and gathering the same evidence twice. If they are run on shared controls, an access review or incident response control will highlight both.  <\/p>\n<ul data-dc-tpl=\"32\">\n<li data-dc-tpl=\"33\"><strong data-dc-tpl=\"34\">Governance<\/strong> \u2014 identified responsible parties and oversight of management.<\/li>\n<li data-dc-tpl=\"35\"><strong data-dc-tpl=\"36\">Risk management <\/strong>\u2014 a living record, not an annual document.<\/li>\n<li data-dc-tpl=\"37\"><strong data-dc-tpl=\"38\">Incident management <\/strong>\u2014 detection, response and reporting to the regulator.<\/li>\n<li data-dc-tpl=\"39\"><strong data-dc-tpl=\"40\">Third-party risk<\/strong> \u2014 supplier due diligence and ongoing monitoring.<\/li>\n<\/ul>\n<h2 data-dc-tpl=\"41\">How to highlight effectively<\/h2>\n<p data-dc-tpl=\"42\">Map the NIS2 and DORA requirements to a library of controls, assign responsible parties, collect evidence once, and let the platform display the coverage of both frameworks side by side. Out-of-date evidence and overdue tasks should be escalated automatically \u2014 manual follow-up does not meet the requirements of both regulations. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>A clear explanation of the obligations, deadlines and how to document them efficiently \u2014 without doubling the workload.<\/p>\n","protected":false},"author":1,"featured_media":2849,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_ice_seo_score":0,"_ice_review":"","footnotes":""},"categories":[43],"tags":[],"class_list":["post-2832","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/comments?post=2832"}],"version-history":[{"count":4,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2832\/revisions"}],"predecessor-version":[{"id":4065,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2832\/revisions\/4065"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media\/2849"}],"wp:attachment":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media?parent=2832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/categories?post=2832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/tags?post=2832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}