ciso.diy

DORA and NIS2 — operational resilience and the third parties inside it

DORA has applied to financial entities and their critical ICT third parties since 17 January 2025; the NIS2 transposition deadline passed on 17 October 2024. Both make the management body accountable and both reach deep into the supply chain, which is why the register of information and the vendor programme matter more than the policy set.

Key dates

2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.

In force Member-state transposition deadline — essential and important entities in scope
In force Regulation applies to financial entities and their critical ICT third parties

What practitioners need to know

Lifted verbatim from the kits below, each attributed to the product that says it.

  • Residency breaks in the backup — an EU-only contract satisfied at rest and broken by the US DR copy. The register tracks at rest, in transit and in backup separately, and the engine resolves each placement on its own.

    — Data Center Assessment Kit
  • Data centre operators are NIS2 essential entities; UK Ofcom regulates from 1 MW; EU EED reporting starts at 500 kW with a mandatory sustainability label in 2026; 27-plus US states are legislating.

    — Data Center Assessment Kit
  • AI and GPU halls run 50–120 kW per rack with liquid cooling and step loads, and crypto-mining neighbours are a tenancy risk — two 2026 risk classes no Tier III certificate covers.

    — Data Center Assessment Kit
  • BMC/IPMI on a shared VLAN is persistent below-OS access, and GPU firmware is the newest supply-chain surface in the building.

    — Data Center Assessment Kit
  • It reads a SOC 2 for what it does not say. An operator report has a scope, and the boundary of that scope is where your risk starts.

    — Data Center Assessment Kit
  • One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.

    — Pillar 01 — The Compliance Operating System
  • A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.

    — Pillar 01 — The Compliance Operating System
  • Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.

    — Pillar 01 — The Compliance Operating System
  • In the ESA dry run, 93% of firms failed data-quality checks — and the failures were mechanical, not conceptual: missing LEIs, critical functions with no exit reference, contracts not linked to functions, subcontractor chains that stop halfway.

    — Vendor Risk Operations Kit
  • The Register of Information builder carries ten automatic quality checks aimed at exactly those failures. It tells you which rows would be rejected before a supervisor does.

    — Vendor Risk Operations Kit

Kits that cover it

8 products, cheapest first.

Vendor Risk Featured

Data Center Assessment Kit

Where your data physically lives — at rest, in transit and in backup — and what sits next to it. One data centre and colocation assessment across colo, cloud regions, hosted private, edge and air-gapped estates, merging EN 50600, SOC 2 and ISO 27001 with the residency regimes and the 2026 tenancy risks.

ZIP 3 licences
From $99.00 View →
Security Program Pillars Featured

Pillar 01 — The Compliance Operating System

Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.

PDF 3 licences
From $149.00 View →
Vendor Risk Featured

Vendor Risk Operations Kit

The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.

ZIP 2 licences
From $149.00 View →
Governance Featured

Executive Tabletop Exercise Kit

Eight board-ready scenarios, ninety minutes each — 64 injects that each name the decision they force and the question to ask the room, a decision log that pre-fills and scores itself on time-to-decide, and an after-action report carrying the regulatory evidence statement for NYDFS 500.16(d), DORA Art. 11 and NIS2 Art. 20. A billable engagement in a box.

ZIP 2 licences
From $149.00 View →
Threat Intelligence Featured

Threat Intel Policy & Governance Pack

Six adoptable documents covering marking, handling, sharing, retention, membership, and machine access — with DORA Article 45, NIS2 Article 29 and ISO 27001 mappings. The governance a sharing programme is required to have and almost never does.

PDF Word 2 licences
From $199.00 View →
Vendor Risk Featured

TPRM Program Kit

Tier your vendors in an afternoon, then run the programme — a seven-factor tiering model everything else computes from, a 150-question bank across 15 domains (with an AI-vendor domain) mapped to CSF 2.0 / ISO 27001 / SOC 2, 20 contract clauses with a fallback ladder, an ERR-01-compatible risk register, monitoring cadence, and fourth-party concentration scoring.

ZIP 3 licences
From $199.00 View →
Compliance Featured

DORA + NIS2 EU Compliance Workbook

14-tab EU regulatory compliance workbook covering all 5 DORA pillars, NIS2 Article 21 measures, dual framework applicability decision tree, penalty calculator (2% DORA / €10M NIS2), and cross-framework mapping across 17 control domains.

Excel Word 3 licences
From $499.00 View →
Compliance Featured

UK Cyber Security & Resilience Act Kit

MSPs are in scope, and it is twenty-four hours to notify. The CAF-aligned kit for the UK Bill — scope test, CAF v4.0 crosswalk, 24/72-hour notice templates, the MSP customer-notice duty, designated-supplier readiness, and the map to NIS2 and DORA.

ZIP 2 licences
From $499.00 View →

Bundles

3 bundles cover this alongside adjacent work — always below the sum of the parts.

Other regimes: EU AI Act · HIPAA · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum

Working to a date? The compliance calendar. Not legal advice.