First: NIS2, DORA, or both?
Not all organizations are subject to the same requirements. The first step is to determine:
- Whether the organization falls within the scope of NIS2.
- Whether it is within the perimeter of DORA.
- Whether it acts as an ICT provider to regulated entities.
- What contractual obligations may be passed down from regulated clients.
From there we build the project's actual scope.
How we work
01 — Applicability
We determine the regulatory scope and relevant obligations.
02 — Gap Assessment
We analyze governance, risk, incidents, continuity, third parties, documentation and existing controls.
03 — Remediation
We design and implement measures, policies, procedures and responsibilities.
04 — Assurance
We prepare evidence, exercises, reviews and monitoring mechanisms to demonstrate compliance.
What does it include?
- Applicability analysis.
- Governance & accountability.
- Cybersecurity risk management.
- ICT risk management.
- Incident management.
- Continuity and recovery.
- Supplier and supply chain security.
- Third-party contract management.
- Policies and procedures.
- Training for managers and leadership.
- Compliance evidence.
- Simulations and exercises when applicable.
- Remediation roadmap.
For which organizations?
- NIS2: organizations operating in sectors and activities within its scope.
- DORA: financial entities and organizations within its specific scope.
- ICT providers: companies providing critical technology or services to regulated organizations.
- B2B providers: companies starting to receive security and resilience requirements from their clients.
Deliverables
- Applicability report.
- Gap Assessment Report.
- Remediation plan.
- Policies and procedures.
- Evidence register.
- Management review report.
- Compliance Roadmap.
What happens next
Applicability
→
Gap Assessment
→
Remediation
→
Assurance
→
Regulator inspection / audit
Not sure if NIS2 or DORA affects your organization?
The first step is to determine the actual regulatory perimeter.
Request an applicability analysis →
Initial 20–30 minute meeting · No commitment