
Compliance
NIS2 and DORA: who is affected and what to do
Two European frameworks that turn cybersecurity from a recommendation into an obligation with management liability.
4 min read
NIS2 is the EU directive on the security of network and information systems, which widened the circle of companies with security obligations. DORA is the regulation on digital operational resilience for the financial sector. Both apply in the EU and affect Ukrainian companies that provide services to European customers.
NIS2: who falls under it
- Medium and large companies in energy, transport, healthcare, digital infrastructure, manufacturing, food, research and other sectors.
- Suppliers of these companies through contractual requirements.
- Management is personally responsible for approving the measures.
DORA: who falls under it
- Banks, insurers, payment institutions, crypto providers, investment firms.
- Their ICT service providers, including cloud and software vendors.
What both require
- Risk management and documented policies.
- Incident reporting within tight deadlines (NIS2: first notification within 24 hours).
- Regular testing, under DORA including threat-led pentesting for large institutions.
- Supplier and supply chain control.
Where to start
A gap analysis: where you are now relative to the requirements. Then a 6 to 12 month plan with priorities, policies that are actually followed, and a first pentest as evidence.
Articles

ISO 27001 or SOC 2: which to choose
Both are about managing security systematically. The difference is who you prove it to.
4 min read
What a pentest is and how it differs from a vulnerability scanner
A scanner finds known holes from a list. A pentester thinks like an attacker and chains small things into a real breach.
4 min read