Skip to main content
DORA · NIS2 · EU resilience

Show EU regulators and clients that your operations hold under attack.

DORA and NIS2 make management bodies directly accountable for resilience. Summit delivers gap analysis, penetration testing, control validation and board-ready reporting, so leadership can evidence tested controls and supplier readiness.

Human-led VAPT · NDA first · report in 48h

17 Jan 2025
the date DORA began to apply across the EU
5
DORA pillars, including digital operational resilience testing
24 h
NIS2 early warning for significant incidents, then 72 hours and one month
3 yrs
the usual cycle for advanced threat-led penetration testing under DORA
Board and leadership view

Why DORA and NIS2 matter to your board

The work is technical. The consequences of getting DORA & NIS2 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Access to EU financial clients

Banks and insurers push DORA testing and evidence duties to suppliers. Gaps can cost contracts.

Direct leadership accountability

Management bodies approve and oversee measures. NIS2 penalties reach EUR 10M or 2% of turnover.

Reporting clocks

Early warning is due in 24 hours and notification in 72. Tested processes prevent improvisation.

Deadlines and ownership

DORA applies since 17 January 2025 and NIS2 depends on national law. Owners and dates keep pace.

Fit

Who is in scope

Banks, insurers and fintechs

Financial entities fall under DORA’s ICT risk, reporting, testing and third-party rules.

Cloud and software suppliers

ICT providers to EU financial firms face contract clauses and security evidence requests.

Essential and important entities

Energy, health, transport, digital infrastructure and others fall under NIS2.

Managed service providers

MSPs and security providers are explicitly in scope of NIS2 in many member states.

Scope of work

What Summit delivers for DORA & NIS2

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Governance, reporting, testing and supplier practices compared with DORA and NIS2 duties.

Penetration testing

Human-led testing of critical ICT systems, with TLPT scoping support where designated.

Control validation

Checks that detection, response and recovery controls work as documented.

Evidence pack

Dated reports and fix records suited to regulator and client requests.

Remediation support and retest

Fix guidance, then a retest confirming closure.

Board-ready report

Resilience posture and gaps for management bodies.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical resilience readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Confirm your status

    Weeks 1 to 2

    Determine whether DORA, NIS2 (and which national law) or both apply, and in what role.

  2. 2

    Assess gaps

    Weeks 2 to 6

    Compare current governance, reporting, testing and supplier practices to the requirements.

  3. 3

    Fix governance and reporting

    Months 2 to 4

    Assign board accountability and build incident classification and reporting workflows.

  4. 4

    Build the testing programme

    Months 3 to 5

    Plan vulnerability assessments and penetration tests, and prepare for TLPT if designated.

  5. 5

    Manage suppliers

    Months 3 to 6

    Create the supplier register, update contracts and collect evidence from key vendors.

  6. 6

    Rehearse

    Ongoing

    Run incident exercises and report test findings to management.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • An executive summary

    Resilience posture and top risks in plain language.

  • A testing programme plan

    Annual testing cadence and TLPT preparation steps.

  • Supplier assurance evidence

    Test summaries clients can use in their reviews.

  • A remediation tracker

    Findings with owners, severity and status.

  • Support through reviews

    The same Summit team stays with you through regulator and client questions.

The detail

What DORA and NIS2 actually are

The Digital Operational Resilience Act (DORA) is an EU regulation, applying since 17 January 2025, that sets uniform ICT risk rules for banks, insurers, investment firms, payment and crypto providers and other financial entities. It also brings critical ICT third-party providers, such as cloud services, under oversight.

NIS2 is an EU directive that raises cybersecurity requirements for “essential” and “important” entities in sectors such as energy, transport, health, digital infrastructure, ICT service management and manufacturing. Member states transpose it into national law, so details and dates vary by country. Management bodies carry direct responsibility for approving and overseeing measures.

For financial firms DORA generally takes priority over NIS2 for overlapping topics. Both focus on governance, incident reporting, resilience testing and supply chain risk. If you sell to EU banks, insurers or critical sector companies, expect these topics to appear in their vendor questionnaires and contracts.

Key terms in plain English

ICT risk management
Governance, identification, protection, detection, response and recovery for technology systems.
TLPT
Threat-led penetration testing: an advanced red team style test based on realistic threat intelligence.
ICT third-party provider
A supplier of digital or data services, such as cloud, software or managed security.
Register of information
A DORA record of all contractual arrangements with ICT third-party providers.
Requirements

The five DORA pillars and NIS2 measures

DORA is organised in pillars. NIS2 lists minimum risk management measures in Article 21. The two share many themes.

1

ICT risk management and governance

The management body must own the ICT risk framework. Identify assets, protect them, detect anomalies, respond and recover. NIS2 Article 21 sets minimum measures such as risk analysis, incident handling, business continuity, supply chain security and use of cryptography.

What it looks like in practice

  • Board approval and training
  • Asset and dependency inventory
  • Policies for access, encryption and change control
2

Incident management and reporting

Classify incidents and report major ones to the authorities in set timeframes. NIS2 uses a 24 hour early warning, 72 hour notification and a final report within a month. DORA has its own templates and deadlines for major ICT incidents.

What it looks like in practice

  • A classification method with thresholds
  • Pre-assigned reporting roles
  • Evidence logs and timelines
3

Digital operational resilience testing

Financial entities need a testing programme covering vulnerability assessments, scenario tests, network security assessments and penetration tests. Designated entities must perform advanced TLPT at least every three years.

What it looks like in practice

  • An annual test plan
  • Findings tracked to remediation
  • TLPT scoped with qualified testers where required
4

ICT third-party risk management

Keep a register of ICT providers, assess concentration and exit risks and include required clauses in contracts. NIS2 adds supply chain security measures including supplier due diligence.

What it looks like in practice

  • Supplier register with criticality ratings
  • Contract clauses for security and audit
  • Exit and substitution plans
5

Information sharing and oversight

Entities are encouraged to share cyber threat information in trusted communities. Critical ICT providers are subject to direct EU oversight under DORA.

What it looks like in practice

  • Participation in sector information sharing
  • Regulator contact points
  • Clear communication with customers during incidents
Where testing fits

How penetration testing supports DORA & NIS2

DORA names penetration testing and TLPT explicitly. NIS2 requires policies to assess the effectiveness of cybersecurity measures, which testing helps to evidence. Customers who are in scope will push testing requirements down to their suppliers.

DORA testing

Annual resilience testing

Vulnerability assessments and penetration tests of critical ICT systems are part of the required programme.

DORA TLPT

Threat-led penetration testing

Designated entities run advanced testing based on realistic threat scenarios about every three years.

NIS2 Art. 21

Measures to assess effectiveness

Policies and procedures to assess the effectiveness of risk management measures. Test reports are direct evidence.

Supply chain

Supplier assurance

Financial and critical-sector customers will ask suppliers for recent independent testing evidence.

Avoid these

Common DORA & NIS2 mistakes, and how to avoid them

!

Assuming NIS2 is identical everywhere

It is a directive. National laws differ in scope, deadlines and penalties.

!

Treating TLPT like a normal pen test

TLPT is intelligence-led and follows a specific framework. Plan scope, testers and time well ahead.

!

No supplier register

DORA needs a complete record of ICT arrangements. Start collecting it early.

!

Leaving the board out

Management bodies are directly accountable. Brief and train them regularly.

FAQ

DORA & NIS2 questions, answered

Does DORA apply to software vendors?

Directly to financial entities, but vendors providing ICT services to them are affected through contracts, due diligence and, for designated critical providers, direct oversight.

What is TLPT?

Threat-led penetration testing: an advanced, intelligence-driven test of live production systems that follows a recognised framework, performed by qualified testers.

What are the NIS2 reporting deadlines?

A 24 hour early warning for significant incidents, an incident notification within 72 hours and a final report within a month, subject to national transposition.

Is DORA the same as NIS2?

No. DORA is a regulation specific to the financial sector, while NIS2 is a directive covering many sectors. Financial entities are mostly governed by DORA for ICT topics.

Is this legal advice?

No. It is general education. Summit focuses on resilience testing, gap analysis and board-ready reporting, and stays with your team through reviews while your legal team interprets the rules.

Ready to get DORA & NIS2 sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →