NIS2 & DORA

The regulation is in force. The question is whether you can prove it.

NIS2 sets a new baseline for cybersecurity across essential and important entities. DORA has applied to financial services since January 2025. Edge7 Networks confirms where you stand, closes the gaps against a single control set, and keeps the evidence ready for the day an auditor or regulator asks.

ISO 27001
Cyber Essentials
IT, OT & IoT
Evidence-led
NIS2 DORA ESSENTIAL IMPORTANT
The problem

Knowing the rules exist is not the same as being able to evidence them.

NIS2 widened the net. It brings far more organisations into scope than the original directive, across sectors from energy and health to digital infrastructure and manufacturing, and it makes management bodies accountable for overseeing cyber risk. DORA does the same for the financial sector, with detailed requirements for ICT resilience, testing, and supplier oversight.

The obligations are clear enough on paper. The difficulty is turning them into controls that actually operate, and into evidence that holds up when an auditor, an insurer, or a regulator asks to see it.

Edge7 Networks turns the regulation into a programme you can run. We confirm your scope, prioritise what matters, and build the controls and evidence into how your organisation works. Across IT, OT, and IoT.

Unsure if you are in scope

NIS2 and DORA scope is not always obvious. Many organisations are caught through a sector, a size threshold, or a regulated customer.

No clear owner at board level

NIS2 puts accountability on the management body. If nobody has signed off the measures, that gap sits with leadership.

Incident reporting untested

Both regimes set tight reporting timelines. Without a rehearsed process, the clock starts before you are ready.

Supply chain unassessed

NIS2 and DORA both require oversight of ICT suppliers. Third-party risk is acknowledged but rarely reviewed in a structured way.

Evidence built at the last minute

Policies, risk registers, and test results pulled together before an audit rather than maintained through the year.

Two regulations, two workstreams

NIS2 and DORA are treated as separate projects, duplicating effort on controls that are largely the same underneath.

This is not a box-ticking exercise. The point of NIS2 and DORA is a security posture that actually holds up, with the evidence to show it. Done well, compliance is a by-product of running security properly, not a separate burden bolted on the side. That is the position Edge7 Networks builds towards.

€10M or 2%
Maximum NIS2 fine for essential entities, of global annual turnover
NIS2 Directive
17 Jan 2025
DORA has applied across EU financial services since this date
DORA Regulation (EU) 2022/2554
5 pillars
ICT risk, incident reporting, testing, third-party risk, information sharing
DORA framework
What changes

One programme that answers to both regulations.

NIS2Broad sectors

The EU Network and Information Security Directive. Sets risk management and incident reporting duties for essential and important entities across sectors from energy and health to digital infrastructure and manufacturing. In Ireland it is being transposed through the National Cyber Security Bill, with the NCSC as lead authority.

DORAFinancial sector

The Digital Operational Resilience Act. In force since January 2025, it sets uniform ICT resilience requirements for banks, insurers, investment firms, and other financial entities, plus the critical ICT providers that serve them.

The controls underneath are largely the same. Edge7 Networks maps both to a single set of controls and evidence, so financial organisations caught by both build once, not twice.

Scope is confirmed in writing. Whether you are an essential entity, an important entity, in scope for DORA, or caught by both, you have a clear answer and a documented rationale rather than an assumption.

NIS2 makes the management body accountable for approving and overseeing cyber risk measures. Your leadership gets governance, reporting, and a risk picture they can stand behind with confidence.

Both regimes set defined reporting timelines. Your process is documented and rehearsed, with the roles and templates in place, so notification is a procedure rather than a scramble.

Third-party ICT risk moves from an acknowledged gap to a managed process, with critical suppliers assessed and contractual expectations aligned to what NIS2 and DORA require.

Risk registers, policies, test results, and control evidence are kept current through a Cybersecurity Compliance Toolkit. When the audit comes, the answer already exists.

How it works

From uncertain to audit-ready, in a defined path.

There is no generic template. The programme is shaped around your sector, your maturity, and which regulations actually apply to you.

01
Scope and gap assessment
We confirm which regulations apply and as which entity type, then measure your current position against the obligations. You get a clear picture of where you stand and what is missing.
02
Prioritised remediation roadmap
The gaps are turned into a roadmap that leads with the highest risk and the clearest regulatory exposure, sequenced around your resources and your operational reality.
03
Controls and evidence in place
Policies, risk management, incident response, and supplier oversight are implemented and documented. Because Edge7 Networks also runs security operations, controls are built to work, not just to pass.
04
Ongoing governance and reporting
Your compliance position is maintained continuously, with board reporting, refreshed evidence, and testing that keeps the programme current as the regulation and your business evolve.

What being ready actually looks like.

A defensible compliance position that stands up to scrutiny, and a security posture that is materially stronger for it. Here is what changes in practice.

A defensible compliance position
Scope, controls, and evidence documented and current. When a regulator, auditor, or insurer asks, the answer is ready rather than assembled under pressure.
Board oversight the regulation expects
Leadership can approve and oversee cyber risk measures with reporting written in business terms, meeting the accountability NIS2 places on the management body.
Incident reporting you can execute
A rehearsed process that meets the notification timelines, so a significant incident is handled in an orderly way rather than becoming a second crisis.
Supply chain risk under control
Critical ICT suppliers assessed and monitored, with contractual expectations aligned to the requirements. Third-party risk becomes a managed process.
One programme, not two
For organisations caught by both NIS2 and DORA, a single control set and evidence base covers both, removing duplicated effort and conflicting workstreams.
Readiness score
80%ready
Up from 34% at baseline
96
Controls
19
Policies
Remediation actions
Critical open0
High4
Medium11
Closed52
Regulatory coverage
NIS2 scopeConfirmed
Risk managementIn place
Incident reportingRehearsed
DORA testingOn track
Supplier oversightActive
ISO 27001Aligned
Built from experience

We hold these standards ourselves.

Edge7 Networks is certified to ISO 27001 and ISO 9001 and holds Cyber Essentials. We run our own security operations, so we know what evidence auditors accept, where programmes stall, and how to make controls that work in the real world rather than only on paper.

ISO 27001:2022
ISO 27001:2022
Information security management
ISO 9001:2015
ISO 9001:2015
Quality management
Cyber Essentials
Cyber Essentials
Government-backed certification

We map your programme to the frameworks that apply to your sector, across IT, OT, and IoT environments. NIS2 and DORA rarely stand alone.

NIS2DORAISO 27001NIST CSF 2.0IEC 62443Cyber EssentialsGDPRISO 9001

Frequently asked questions

Common questions about NIS2 and DORA compliance.

NIS2 is the EU Network and Information Security Directive. It sets cybersecurity risk management and incident reporting obligations for essential and important entities across a wide range of sectors, from energy and health to digital infrastructure and manufacturing. In Ireland, NIS2 is being transposed through the National Cyber Security Bill, with the National Cyber Security Centre acting as the lead competent authority. NIS2 raises the baseline for security governance and makes management bodies accountable for oversight of cyber risk.

NIS2 applies to organisations that operate in one of its in-scope sectors and meet the size criteria for an essential or important entity. In-scope sectors include energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing, and digital providers. Many organisations are in scope without realising it, often because a customer or parent entity is regulated. Edge7 Networks begins every engagement with a scoping assessment to confirm whether you are in scope and as which type of entity.

NIS2 divides in-scope organisations into essential entities and important entities based on sector and size. Both must meet the same core risk management and incident reporting obligations. The difference lies mainly in supervision and penalties. Essential entities are subject to proactive supervision and face maximum administrative fines of 10 million euro or 2 percent of global annual turnover, whichever is higher. Important entities are supervised on a reactive basis and face maximum fines of 7 million euro or 1.4 percent of global annual turnover.

DORA is the EU Digital Operational Resilience Act. It has applied across the EU since 17 January 2025 and sets uniform requirements for the digital operational resilience of the financial sector. DORA applies to around 20 types of financial entity, including banks, insurers, investment firms, payment institutions, and crypto-asset service providers, as well as the critical ICT third-party providers that serve them. It is built on five areas: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing.

They can. Financial entities may fall under both frameworks, but DORA is treated as the more specific rulebook for the financial sector, so its ICT resilience requirements take precedence where the two meet. In practice the underlying controls, such as risk management, incident response, supplier oversight, and testing, are largely common. Edge7 Networks maps both regulations to a single control set so you build one governed programme rather than two parallel compliance exercises.

Under NIS2, essential entities face maximum administrative fines of 10 million euro or 2 percent of global annual turnover, and important entities face up to 7 million euro or 1.4 percent, whichever is higher. NIS2 also makes management bodies accountable for approving and overseeing cybersecurity risk measures. DORA is enforced by financial regulators and carries its own supervisory and enforcement powers. For most organisations the more practical exposure is the operational and reputational cost of an incident they were not prepared for.

Not sure where you stand?

Whether you need to confirm your scope, close known gaps, or build the whole programme, there is a sensible place to begin. Choose your starting point.

Confirm your scope

Start with a readiness assessment to establish which regulations apply, as which entity type, and where the gaps are.

Close the gaps

You know your obligations and want a prioritised roadmap and hands-on remediation to reach a defensible position.

Run it continuously

You want the programme owned and maintained over time, with governance, reporting, and evidence kept current.

Let's start with a conversation