Regulatory Compliance

One roadmap, not one project per regulation.

DORA, NIS2, GDPR, the Cyber Resilience Act and the AI Act share more requirements than most organisations realise: governance, risk management, incident response, third-party oversight and business continuity show up in nearly every one of them. Treat each text as a separate project and you triple the work. Build one control framework and you satisfy several at once.

What does regulatory compliance mean in cybersecurity?

Regulatory compliance in cybersecurity is the ability to demonstrate, with evidence, that an organisation meets its legal and contractual security obligations, not simply that it intends to. It covers the mapping of applicable requirements, the controls that satisfy them, and the proof a regulator, auditor or client can inspect.

The regulations that matter to your organisation

Regulatory compliance in cybersecurity is the ability to demonstrate, with evidence, that an organisation meets its legal and contractual security obligations, not simply that it intends to. It covers the mapping of applicable requirements, the controls that satisfy them, and the proof a regulator, auditor or client can inspect.

Regulation Who it applies to Key requirements Sanctions
DORA Banks, insurers, investment firms, fintechs and their critical ICT providers ICT risk management, incident classification and notification, resilience testing, third-party oversight Set by national authorities (ACPR, AMF in France); in serious cases, withdrawal of authorisation
NIS2 Essential and important entities across 18 critical sectors Risk management measures, board-level accountability, 24-hour incident notification, supply chain security Up to €10M or 2% of global turnover (essential entities)
GDPR Any organisation processing EU personal data Lawful processing, data subject rights, breach notification, data transfer safeguards Up to €20M or 4% of global turnover
Cyber Resilience Act Manufacturers, importers and distributors of digital products Secure-by-design, vulnerability handling, CE marking, lifecycle security Up to €15M or 2.5% of global turnover
AI Act Providers and deployers of AI systems, especially high-risk use cases Risk classification, transparency, human oversight, technical documentation Up to €35M or 7% of global turnover (prohibited practices)
ISO 27001 Any organisation seeking a certifiable, audit-ready control framework Risk-based ISMS, structured risk assessment, control objectives Not a regulatory requirement, but often required contractually by clients, sometimes alongside sector-specific extensions such as TISAX in automotive, which complements ISO 27001 on prototype protection.

Where your obligations overlap

NIS2 DORA ISO 27001 Shared controls
Governance Risk management Incident response Third-party risk Business continuity

Most organisations discover the overlap the hard way: a NIS2 gap analysis and a DORA readiness assessment end up recommending the same policy, the same risk register, the same incident process, written twice by two different teams. We map your applicable regulations against a single control set once, so every deliverable serves more than one requirement.

How we build your compliance programme

Four phases take you from uncertainty to an audit-ready programme.

  1. Gap analysis. We assess your current posture against every regulation and standard that applies to you, not one at a time, in a single structured review.
  2. Roadmap. Findings become a prioritised roadmap, sequenced by risk, deadline and budget, not by which regulation happens to be most urgent this quarter.
  3. Implementation and evidence. Policies, controls and documentation are built once and mapped to every requirement they satisfy, so your evidence file works for a regulator, an auditor and a client audit alike.
  4. Continuous monitoring. Dashboards and periodic reviews keep the programme current as regulations evolve and new obligations are transposed.
01

Gap analysis

02

Roadmap

03

Implementation & evidence

04

Continuous monitoring

DORA

Banks, insurers, fintechs, financial service providers.

Learn more

NIS2

18 critical sectors, from energy to digital providers.

Learn more

AI Act

AI providers, deployers, high-risk sectors.

Learn more

GDPR

Organizations processing EU citizens’ data.

Learn more

Questions

Frequently Asked Questions

General questions about regulatory compliance

The ability to demonstrate, with evidence, that an organisation meets its legal and contractual security obligations, not simply that it intends to.

Possibly. Each regulation applies by activity and entity type, not by group as a whole, so overlap is common but never assumed.

A structured comparison between your current security posture and what a specific regulation or standard requires, resulting in a prioritised list of what’s missing.

NIS2 sets harmonised fines of up to €10 million or 2% of global turnover for essential entities. DORA leaves the exact fine to each Member State’s competent authority, but for a regulated financial entity the more serious consequence is often prudential: repeated non-compliance can lead to capital add-ons or, in serious cases, withdrawal of authorisation to operate.

ISO 27001 is voluntary, but its control structure covers most of what NIS2 and DORA require. Organisations that build their compliance programme around it typically satisfy several regulations from the same evidence base.

Proudly Powered by WordPress