Regulatory Compliance
One roadmap, not one project per regulation.
DORA, NIS2, GDPR, the Cyber Resilience Act and the AI Act share more requirements than most organisations realise: governance, risk management, incident response, third-party oversight and business continuity show up in nearly every one of them. Treat each text as a separate project and you triple the work. Build one control framework and you satisfy several at once.
What does regulatory compliance mean in cybersecurity?
Regulatory compliance in cybersecurity is the ability to demonstrate, with evidence, that an organisation meets its legal and contractual security obligations, not simply that it intends to. It covers the mapping of applicable requirements, the controls that satisfy them, and the proof a regulator, auditor or client can inspect.
The regulations that matter to your organisation
Regulatory compliance in cybersecurity is the ability to demonstrate, with evidence, that an organisation meets its legal and contractual security obligations, not simply that it intends to. It covers the mapping of applicable requirements, the controls that satisfy them, and the proof a regulator, auditor or client can inspect.
| Regulation | Who it applies to | Key requirements | Sanctions |
|---|---|---|---|
| DORA | Banks, insurers, investment firms, fintechs and their critical ICT providers | ICT risk management, incident classification and notification, resilience testing, third-party oversight | Set by national authorities (ACPR, AMF in France); in serious cases, withdrawal of authorisation |
| NIS2 | Essential and important entities across 18 critical sectors | Risk management measures, board-level accountability, 24-hour incident notification, supply chain security | Up to €10M or 2% of global turnover (essential entities) |
| GDPR | Any organisation processing EU personal data | Lawful processing, data subject rights, breach notification, data transfer safeguards | Up to €20M or 4% of global turnover |
| Cyber Resilience Act | Manufacturers, importers and distributors of digital products | Secure-by-design, vulnerability handling, CE marking, lifecycle security | Up to €15M or 2.5% of global turnover |
| AI Act | Providers and deployers of AI systems, especially high-risk use cases | Risk classification, transparency, human oversight, technical documentation | Up to €35M or 7% of global turnover (prohibited practices) |
| ISO 27001 | Any organisation seeking a certifiable, audit-ready control framework | Risk-based ISMS, structured risk assessment, control objectives | Not a regulatory requirement, but often required contractually by clients, sometimes alongside sector-specific extensions such as TISAX in automotive, which complements ISO 27001 on prototype protection. |
Where your obligations overlap
Most organisations discover the overlap the hard way: a NIS2 gap analysis and a DORA readiness assessment end up recommending the same policy, the same risk register, the same incident process, written twice by two different teams. We map your applicable regulations against a single control set once, so every deliverable serves more than one requirement.
How we build your compliance programme
Four phases take you from uncertainty to an audit-ready programme.
- Gap analysis. We assess your current posture against every regulation and standard that applies to you, not one at a time, in a single structured review.
- Roadmap. Findings become a prioritised roadmap, sequenced by risk, deadline and budget, not by which regulation happens to be most urgent this quarter.
- Implementation and evidence. Policies, controls and documentation are built once and mapped to every requirement they satisfy, so your evidence file works for a regulator, an auditor and a client audit alike.
- Continuous monitoring. Dashboards and periodic reviews keep the programme current as regulations evolve and new obligations are transposed.
Gap analysis
Roadmap
Implementation & evidence
Continuous monitoring
Questions
Frequently Asked Questions
General questions about regulatory compliance
The ability to demonstrate, with evidence, that an organisation meets its legal and contractual security obligations, not simply that it intends to.
Possibly. Each regulation applies by activity and entity type, not by group as a whole, so overlap is common but never assumed.
A structured comparison between your current security posture and what a specific regulation or standard requires, resulting in a prioritised list of what’s missing.
NIS2 sets harmonised fines of up to €10 million or 2% of global turnover for essential entities. DORA leaves the exact fine to each Member State’s competent authority, but for a regulated financial entity the more serious consequence is often prudential: repeated non-compliance can lead to capital add-ons or, in serious cases, withdrawal of authorisation to operate.
ISO 27001 is voluntary, but its control structure covers most of what NIS2 and DORA require. Organisations that build their compliance programme around it typically satisfy several regulations from the same evidence base.
