News 18 augusti 2026

NIS2 and DORA in mid-2026: what boards should be asking now

Enforcement is maturing across the EU. The questions have shifted from 'are we in scope?' to 'can we evidence it?' Here is a board-level checklist.

Two years into NIS2 transposition and with DORA now part of day-to-day supervision for financial entities, the conversation in the boardroom has changed. It is no longer about whether an organisation is in scope — many more are than expected, often through the supply chain — but about whether they can demonstrate their controls, their incident reporting, and their oversight of critical suppliers.

Compliance checklist and assurance

Both regimes place accountability with senior management. A useful set of questions for your next board meeting:

  • Do we have a current, owned risk assessment, and who signs it off?
  • Can we meet the incident-reporting timelines, and have we ever rehearsed the notification?
  • Do we hold register-level visibility of critical ICT third parties, including their concentration risk?
  • Is there evidence — not just intent — of testing, training and management oversight?

The good news is that the underlying work maps neatly onto ISO 27001, the NIST Cybersecurity Framework and CIS Controls. Organisations with a healthy ISMS are usually closer to compliance than they think; the gap tends to be in evidence and in supplier oversight rather than in technology.

If a readiness gap-analysis against NIS2 or DORA would help focus your next budget cycle, that is exactly the kind of engagement we run.

All briefings Talk to us about this