Level 3 · 01
NIS2 and DORA readiness
NIS2 and DORA readiness is preparation for two EU laws on cybersecurity and operational resilience. NIS2, Directive (EU) 2022/2555, sets security and incident reporting duties for medium and large organisations in sectors listed in the Directive, such as energy, transport, health and digital infrastructure. DORA, Regulation (EU) 2022/2554, sets rules on managing technology risk for financial entities in the EU and for some of their technology suppliers. UK organisations fall under the UK NIS Regulations 2018 and the ICO regime instead, so which set applies depends on where you operate. Whether any of them applies to your company is a legal question for your counsel; our work is preparation, not legal advice.
Inside it
- Requirement breakdown from Directive (EU) 2022/2555 or Regulation (EU) 2022/2554
- Mapping to systems and teams
- Incident handling and reporting procedures
- Supplier and third party risk review
- Gap register with owners
Measured by Requirements with a working control and current evidence, and gaps closed against their planned dates.
Deliverable · Level 4→ Control gap registerControl gap register: every requirement, the control that meets it or the gap where none does, the evidence and an owner.