DORA and NIS2 — operational resilience and the third parties inside it
DORA has applied to financial entities and their critical ICT third parties since 17 January 2025; the NIS2 transposition deadline passed on 17 October 2024. Both make the management body accountable and both reach deep into the supply chain, which is why the register of information and the vendor programme matter more than the policy set.
Key dates
2 dated obligations. Rows marked verify are not final in their source. See the whole calendar.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
Residency breaks in the backup — an EU-only contract satisfied at rest and broken by the US DR copy. The register tracks at rest, in transit and in backup separately, and the engine resolves each placement on its own.
— Data Center Assessment Kit -
Data centre operators are NIS2 essential entities; UK Ofcom regulates from 1 MW; EU EED reporting starts at 500 kW with a mandatory sustainability label in 2026; 27-plus US states are legislating.
— Data Center Assessment Kit -
AI and GPU halls run 50–120 kW per rack with liquid cooling and step loads, and crypto-mining neighbours are a tenancy risk — two 2026 risk classes no Tier III certificate covers.
— Data Center Assessment Kit -
BMC/IPMI on a shared VLAN is persistent below-OS access, and GPU firmware is the newest supply-chain surface in the building.
— Data Center Assessment Kit -
It reads a SOC 2 for what it does not say. An operator report has a scope, and the boundary of that scope is where your risk starts.
— Data Center Assessment Kit -
One control — “access to production requires MFA and is reviewed quarterly” — satisfies a SOC 2 criterion, an ISO 27001 Annex A control, a HIPAA safeguard and a PCI requirement simultaneously.
— Pillar 01 — The Compliance Operating System -
A readiness dashboard can read 98% while the auditor’s fieldwork disagrees, because completion percentage is not evidence quality.
— Pillar 01 — The Compliance Operating System -
Covers SOC 2 Type I and II, ISO 27001, HIPAA, PCI DSS v4.0.1, CMMC 2.0, DORA and NIS2, plus the 2026 AI-governance layer.
— Pillar 01 — The Compliance Operating System -
In the ESA dry run, 93% of firms failed data-quality checks — and the failures were mechanical, not conceptual: missing LEIs, critical functions with no exit reference, contracts not linked to functions, subcontractor chains that stop halfway.
— Vendor Risk Operations Kit -
The Register of Information builder carries ten automatic quality checks aimed at exactly those failures. It tells you which rows would be rejected before a supervisor does.
— Vendor Risk Operations Kit
Kits that cover it
8 products, cheapest first.
Data Center Assessment Kit
Where your data physically lives — at rest, in transit and in backup — and what sits next to it. One data centre and colocation assessment across colo, cloud regions, hosted private, edge and air-gapped estates, merging EN 50600, SOC 2 and ISO 27001 with the residency regimes and the 2026 tenancy risks.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
Vendor Risk Operations Kit
The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.
Executive Tabletop Exercise Kit
Eight board-ready scenarios, ninety minutes each — 64 injects that each name the decision they force and the question to ask the room, a decision log that pre-fills and scores itself on time-to-decide, and an after-action report carrying the regulatory evidence statement for NYDFS 500.16(d), DORA Art. 11 and NIS2 Art. 20. A billable engagement in a box.
Threat Intel Policy & Governance Pack
Six adoptable documents covering marking, handling, sharing, retention, membership, and machine access — with DORA Article 45, NIS2 Article 29 and ISO 27001 mappings. The governance a sharing programme is required to have and almost never does.
TPRM Program Kit
Tier your vendors in an afternoon, then run the programme — a seven-factor tiering model everything else computes from, a 150-question bank across 15 domains (with an AI-vendor domain) mapped to CSF 2.0 / ISO 27001 / SOC 2, 20 contract clauses with a fallback ladder, an ERR-01-compatible risk register, monitoring cadence, and fourth-party concentration scoring.
DORA + NIS2 EU Compliance Workbook
14-tab EU regulatory compliance workbook covering all 5 DORA pillars, NIS2 Article 21 measures, dual framework applicability decision tree, penalty calculator (2% DORA / €10M NIS2), and cross-framework mapping across 17 control domains.
UK Cyber Security & Resilience Act Kit
MSPs are in scope, and it is twenty-four hours to notify. The CAF-aligned kit for the UK Bill — scope test, CAF v4.0 crosswalk, 24/72-hour notice templates, the MSP customer-notice duty, designated-supplier readiness, and the map to NIS2 and DORA.
Bundles
3 bundles cover this alongside adjacent work — always below the sum of the parts.
Provider Risk Pack
The vendor programme, and a deep assessment of the vendor that holds your admin rights. Run every supplier properly, then run your MSP properly — because one row in a register does not cover the party with delegated admin on your tenant. 14% off buying separately.
Vendor Risk Complete
The TPRM Program Kit + the Vendor Risk Operations Kit — design the programme, then actually run it. Tiering, questionnaires and clauses on one side; dossiers, scorecards, exit tests and the Register of Information on the other.
EU Regulatory Estate
The two EU regimes that reach almost every regulated business at once — operational resilience and third-party risk under DORA and NIS2, and the AI Act obligations arriving on top of them. 14% off buying separately.
Other regimes: EU AI Act · HIPAA · PCI DSS · Third-party risk · Critical infrastructure · Post-quantum
Working to a date? The compliance calendar. Not legal advice.