Resources
Understand your obligations. Build a clear path to compliance.
We help you understand what applies to your business, identify compliance gaps, prioritize actions, and build a practical roadmap that connects regulatory requirements with real cybersecurity improvements.
The purpose of NIS2
NIS2 strengthens cybersecurity across the European Union by expanding the scope and requirements for protecting critical infrastructure, improving preparedness for cyber threats, and raising the resilience of essential services and digital service providers.
Broader scope
NIS2 applies to a wider range of sectors — including healthcare, digital infrastructure, public administration, and food production — covering more essential and important entities than the original directive.
Tighter security measures
Organizations in scope must implement enhanced cybersecurity measures, including risk management practices, incident response protocols, and incident reporting requirements.
Incident reporting
NIS2 mandates quicker reporting of significant cybersecurity incidents to national authorities, with penalties for non-compliance.
Supply chain security
It emphasizes securing the supply chain, so organizations protect their own infrastructure and address vulnerabilities in their suppliers and partners.
Governance and oversight
The directive strengthens cooperation among member states, and between businesses and governments, through enhanced governance and oversight mechanisms.
Where Spirity fits
Gap analysis, control implementation, evidence collection, and the management reporting the directive expects leadership to be able to produce.
Is there a date in the calendar?
Organizations that missed the first round of NIS2 audits usually get 180 days, not a year — which is enough time to be ready and not enough to be leisurely about it. If your date is further out, the same programme stretches; the order of the work does not change.
The purpose of DORA
DORA is a regulation, not a directive — it has applied directly across the EU since 17 January 2025, with no national act in between. It binds financial entities and, through them, the ICT providers they depend on.
Who it binds
Around twenty categories of financial entity — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues and more — plus ICT providers designated as critical, who come under direct EU oversight.
ICT risk management
A documented framework for identifying, protecting, detecting, responding and recovering, with the management body carrying final responsibility under Article 5 and required to maintain enough knowledge to exercise it.
Incident reporting
Major ICT-related incidents are classified against prescribed criteria and reported on the regulator’s own templates: an initial notification, an intermediate report, and a final report. The clocks are obligations, not guidance.
Resilience testing
A regular testing programme, and for significant entities threat-led penetration testing against live production systems — closer to an exercise than to an annual scan.
Third-party ICT risk
Prescribed contractual terms with every ICT provider, and a Register of Information covering every arrangement, filed with your regulator. For most entities the register is a data-collection project in its own right.
Where Spirity fits
Gap analysis against the five pillars, the contractual and register work on third-party ICT risk, incident classification and reporting workflows agreed before you need them, and the retainer that backs the response itself.
The one you can actually be certified against
NIS2 and DORA are supervised. ISO/IEC 27001 is certified — by an accredited body, against an information security management system you build and operate. It is the framework your customers are most likely to ask you for by name.
A management system, not a checklist
The standard certifies how you run security: scope, risk assessment, treatment decisions, objectives, internal audit and management review. The controls follow from that rather than the other way round.
Annex A, as revised
The 2022 revision reorganised the controls into four themes — organizational, people, physical and technological — and added controls for threat intelligence, cloud services, and secure development that the 2013 version did not have.
The 2013 certificates have expired
The transition from ISO/IEC 27001:2013 to the 2022 revision closed on 31 October 2025. A certificate issued against the old version is no longer valid, which catches organizations that assumed recertification was routine.
The certification cycle
A stage 1 readiness review, a stage 2 audit, then surveillance audits through a three-year cycle ending in recertification. Certification is a commitment to keep operating the system, not a one-off exercise.
Why your customers ask for it
It is the shortest credible answer to a security questionnaire. An accredited certificate transfers trust in a way that a self-assessment cannot, which is why it turns up in procurement and insurance conversations.
Where Spirity fits
We build the management system, run the internal audit and a mock stage 2, and prepare the people who will be interviewed. We cannot certify you — the accreditation rules bar a consultant from certifying what it built. We hold the certificate ourselves, obtained in early 2025 through a UKAS-accredited body.
Twenty or so others, assessed in days
NIS2, DORA and ISO 27001 are the three we are asked about most in Europe. They are not the only ones we assess against — and if your obligation arrived from a customer, a regulator or a US parent company, it is probably on this list.
CyFun, NIST CSF 2.0, CMMC for defence contractors, HIPAA, the FTC Safeguards Rule and NY DFS Part 500 for financial institutions, ISO/IEC 42001 for AI management systems, and more. These run as a fixed-scope assessment at a fixed fee rather than as a programme: scoping, the gap analysis, a prioritised backlog, an evidence pack and a report written for management — in days rather than months.
Framework mapping
Requirements across different standards, regulations and internal policies mapped into one structure, so a control you already operate is not rebuilt for each new obligation.
Control management
Controls, responsibilities, tasks and evidence organised so that each item has an owner and a due date rather than a colour.
Evidence tracking
Documentation, proof points and audit materials kept attached to the requirement they satisfy, which is what makes the second assessment cheaper than the first.
Progress reporting
Readiness scored, gaps identified, and a report that shows leadership where the organization stands and what moved since last time.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
Because you asked three people about three different laws. NIS2 is a directive, so it does not bind you directly — it binds you through your own country’s implementing act, and the thresholds, the registration duty and the audit regime differ by member state. That is the single most useful thing to understand about it, and it is why the answers disagreed.
The stable part is the directive’s own structure. You are in scope if you operate in one of the listed sectors and you are a medium-sized enterprise or larger — broadly 50 or more staff, or turnover above €10 million. Above roughly 250 staff or €50 million in one of the high-criticality sectors you are an essential entity; most of the rest are important entities, and the difference is how closely you are supervised rather than whether the duties apply. Some entities are in regardless of size, including DNS and TLD operators, trust service providers and public electronic communications.
The determination is a scoping exercise with a written answer at the end of it, signed off by management rather than assumed. It is the first thing we produce.
You build once and prove three times.
The build overlaps heavily. One control set, one asset and supplier register, one evidence store and one risk process serve all three: ISO 27001’s Annex A covers most of what NIS2 Article 21 asks for, and DORA’s ICT risk management chapter is recognisably the same material with financial-sector specifics on top.
What does not merge is the proof. ISO 27001 is certified by an accredited body. NIS2 is supervised by a national authority under national law. DORA is supervised directly by your financial regulator. Three audiences, three mechanisms, three sets of evidence drawn from the same underlying work.
The platform behind our advisory practice scores your posture against each framework separately from the same set of answers, which is what makes “build once” real rather than aspirational.
An assessment, and it produces two documents: a scope statement and a gap analysis.
Scope is the step people skip and the one everything else rests on — which legal entity, which systems, where the boundaries run. It is approved by management, not assumed by us.
The gap analysis runs off structured questionnaires with your IT and security owners, external scanning of your internet-facing addresses and services, and internal review of identity, endpoint and cloud configuration. What comes back is your posture scored against the framework you are actually held to, the gaps ranked by risk and urgency rather than listed alphabetically, and a plan with an owner and a date against every task.
You can buy the assessment on its own as a paid one-off if you want the picture before committing to a programme.
If you have an audit or a supervisory date, plan on about six months of concentrated work. Our readiness programme is built to 180 days for exactly that reason: roughly the first month on scope and gap analysis, three and a half months building and correcting, the last six weeks proving — evidence organised, an internal mock audit, and a reasoned go or no-go put to leadership before the real thing.
If your date is further out the same sequence stretches. The order does not change.
The honest cost is not our time, it is yours. Expect one to one and a half days a week from IT operations through the build phase, because somebody inside your organisation has to make the changes and demonstrate them. Where 180 days is not enough for everything, the findings are split into audit-critical and achievable, audit-critical but longer — started immediately, with a compensating control and progress on file — and not audit-critical. Your management approves that split at the sixty-day mark rather than discovering it at the end.
We do. Policies, procedures, the system security plan and the asset, data and supplier registers behind them are our work — generated against your actual environment and the framework you are held to, then tailored. Not a template pack with your logo on it.
What stays with you is implementation. We can specify that MFA is enforced, verify it, and write the evidence that it is — but somebody with access to your systems has to make the change. We do not touch your systems.
That boundary is deliberate, and we would rather you knew it before signing than discovered it in month two.
Under NIS2 it is specific: the management body has to approve the cybersecurity risk-management measures, oversee their implementation, and undergo training — and members can be held personally liable for failures. For an essential entity the sanctions reach a temporary ban on the chief executive or legal representative exercising managerial functions. DORA says the same thing in its own words: the management body carries final responsibility for ICT risk and must keep enough knowledge to exercise it.
In practice, proving it means a documented trail — approvals with dates, minuted decisions, a training record, and a report that shows what changed between one period and the next.
What you get is that trail as a by-product of the work rather than something assembled the week before a board meeting: a monthly management report on progress against milestones, open risks, and the decisions we need from you, plus a periodic management review that sets the new report against the old one. It comes out of the same system that runs the work, so it cannot quietly diverge from it.
No, and we could not even if we wanted to. Certification is issued by an accredited certification body after a two-stage audit, and the accreditation rules require that a firm which consulted on your management system stays out of certifying it. The same separation applies to the NIS2 audit, which is performed by a registered independent auditor whose fee is not part of ours.
What we do is everything up to the auditor’s door, and then stand beside you at it: build the management system, run an internal mock audit using the real audit’s own method — document review, sampled evidence, interviews, controls demonstrated rather than described — prepare the people who will be interviewed, give leadership a go or no-go with reasons, and coordinate the official audit.
We can tell you not to go, and sometimes do.
We hold ISO/IEC 27001 ourselves, certified in early 2025 through a UKAS-accredited body and scoped to our own operation as a managed security service provider. So we have been through it from your side of the table.
No. The clock is on the entity, and no monitoring contract moves it.
NIS2 requires an early warning to your national authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. DORA is tighter for major ICT incidents, on the regulator’s own templates.
A security operations centre detects, triages and tells you. The judgement that an incident is significant, the submission itself, and the consequences of a late or wrong one remain yours. Managed-service contracts say so in writing: retaining logs for regulatory purposes is the customer’s responsibility, and platform output is explicitly not a substitute for the customer’s own legal and regulatory judgement.
What actually closes the gap is the plumbing between the two — a classification rule set agreed in advance against the criteria your regulator uses, a named decision-maker reachable at three in the morning, notification content drafted before you need it, and the whole path rehearsed once while nothing is on fire. That is governance work, and it is what the advisory engagement is for.
Three things, in rising order of unpleasantness.
First, contract. NIS2 obliges your customer to manage supply-chain risk, so their duties arrive at your door as security clauses, questionnaires, audit rights and incident-notification terms. That is the usual route, and it is enforceable against you as contract law rather than regulation.
Second, check the size and sector test again, because “not regulated” is frequently wrong. Managed ICT service providers, cloud, data centre, CDN and trust service providers are themselves named sectors under NIS2 — an IT supplier to a regulated company is quite often in scope in its own right.
Third, if your customers are financial entities, DORA can reach you directly. Providers designated as critical by the European supervisory authorities come under an EU oversight framework, and every financial customer must list you in a register of information filed with its regulator, on prescribed contract terms.
Practically: the first step is the same scoping exercise, and the second is being able to answer supplier questionnaires with evidence instead of assertions. That is considerably cheaper than failing them.
Ready to get started?
Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.