European regulation has moved from asking whether controls exist to asking whether they work. NIS2 requires policies on assessing effectiveness. DORA requires risk-based digital operational resilience testing; Article 26 additionally requires advanced threat-led penetration testing for identified financial entities. Both make senior management accountable rather than delegating compliance to a security team.
20.1 NIS2, Directive (EU) 2022/2555#
Commission Implementing Regulation (EU) 2024/2690 specifies technical and methodological cybersecurity risk-management requirements and incident significance criteria for the entity categories expressly covered by that Regulation — specified DNS service providers, TLD registries, cloud providers, data-centre providers, CDNs, managed service providers, managed security service providers, trust service providers and the specified online marketplace, search engine and social networking platform categories. It does not apply to every NIS2 entity.
NIS2 has broad sectoral scope across essential and important entities and applies much more broadly across sectors than DORA, covering essential and important entities across energy, transport, banking, health, water, digital infrastructure, public administration, manufacturing, food, chemicals, postal services, waste management, space and research. Far more organisations than DORA, which is limited to financial entities.
Article 21 requires risk analysis, incident handling, business continuity, supply chain security, and policies and procedures to assess the effectiveness of cybersecurity risk management measures. That last requirement is where most programmes are weakest, because effectiveness cannot be evidenced by a control inventory. Article 20 makes management bodies responsible for approving and overseeing these measures. Article 23 requires an early warning within 24 hours, an incident notification within 72 hours, and a final report not later than one month after the incident notification. Where the incident is still ongoing at that point, a progress report is submitted and the final report follows within one month after handling of the incident is completed.
20.2 DORA, Regulation (EU) 2022/2554#
DORA applies to financial entities and establishes a Union oversight framework for designated critical ICT third-party service providers, across ICT risk management, incident classification and reporting, digital operational resilience testing, with advanced threat-led penetration testing (TLPT) under Article 26 for identified financial entities, third-party risk and information sharing. It is more prescriptive than NIS2 on testing: Articles 24–25 require a risk-based digital operational resilience testing programme, and Article 26 additionally requires advanced testing by means of TLPT for financial entities identified under the applicable criteria. Commission Delegated Regulation (EU) 2025/1190 specifies the TLPT identification criteria, internal-tester requirements, scope, testing methodology, results and closure, remediation, and supervisory cooperation.
20.3 GDPR Article 33#
Where Article 33 notification is required, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The processor must notify the controller without undue delay after becoming aware of a personal data breach. UTIOM supports operational readiness; it does not determine whether the legal notification threshold has been met. Operationally, meeting that deadline depends heavily on how quickly the organisation can detect, classify and scope the breach.
20.4 Mapping requirements to UTIOM outputs#
NIS2 Article 21(2)(a), risk analysis. Crown jewel registry with named owners, business impact mapping, and threat models per asset.
NIS2 Article 21(2)(b), incident handling. Pre-engineered playbooks per crown jewel and containment authority with named individuals.
NIS2 Article 21(2)(f), effectiveness. UTIOM uses adversary emulation, detection-validation records and response-readiness evidence as operational evidence supporting the Article 21(2)(f) effectiveness-assessment requirement.
NIS2 Article 20, management accountability. Vision and Strategy governance artefacts, stakeholder map, and KPIs tied to crown jewels.
NIS2 Article 23, reporting timelines. Contextual incident records tagged with crown jewel, TTPs and attack path, plus MTTD measured per priority TTP.
DORA, ICT risk management. Crown-jewel-driven prioritisation with dependency matrices.
DORA Arts. 24–25, digital operational resilience testing. Adversary emulation aligned to the documented threat profile.
GDPR Article 33. Telemetry engineered outward from crown jewels, with dependency mapping that makes impact scoping a lookup rather than an investigation.
UTIOM is an operating model, not legal advice and not a certification scheme. Obligations vary by member state transposition, sector and entity classification.
Adineh, R. (2026). UTIOM for NIS2 and DORA. UTIOM Framework
Book, edition 1.2. utiom.de/book/nis2-dora/