Think smarter. Stay secure.
European regulation has moved from asking whether controls exist to asking whether they work. NIS2 requires policies on assessing effectiveness. DORA requires risk-based digital operational resilience testing; Article 26 additionally requires advanced threat-led penetration testing for identified financial entities. Both make senior management accountable.
European organisations face a regulatory environment that has moved from asking whether controls exist to asking whether they work. NIS2 requires policies on assessing effectiveness. DORA requires resilience testing. Both make senior management accountable rather than delegating compliance to a security team.
That shift is exactly what UTIOM was designed for. A framework that documents intent satisfies the older generation of regulation. A framework that pairs every design decision with an activity that proves it satisfies this one.
These regulations state obligations. They do not describe how to build the capability that satisfies them. That gap is the one UTIOM fills.
| Regulatory requirement | What it demands | What UTIOM produces |
|---|---|---|
| NIS2 Art. 21(2)(a) Risk analysis | Policies on risk analysis and information system security | Crown jewel registry with named business owners, business impact mapping across financial, regulatory, safety and reputational consequence, and threat models per asset |
| NIS2 Art. 21(2)(b) Incident handling | Incident handling capability | Pre-engineered playbooks per crown jewel, containment authority and escalation thresholds defined in advance with named individuals, tiered response with decision gates |
| NIS2 Art. 21(2)(f) Effectiveness assessment | Policies and procedures to assess the effectiveness of cybersecurity risk management measures | The validation pairing. Purple team exercises emulating profiled adversaries, detection validation rate, response readiness validation, and failed detections raised as engineering defects with owners and dates |
| NIS2 Art. 20 Management accountability | Management bodies approve and oversee measures, with training obligations | Vision and Strategy phases produce the governance artefacts: documented purpose, stakeholder map with decision authority, KPIs and KRIs tied to crown jewels, and stakeholder scorecards on a cadence |
| NIS2 Art. 23 24h early warning → 72h incident notification → one-month final report | Early warning within 24 hours, incident notification within 72 hours, final report not later than one month after the incident notification | Contextual incident records tagged with crown jewel, TTPs observed and attack path, plus MTTD measured against priority TTPs — the inputs that make classification possible inside the window |
| DORA ICT risk management | Identify and manage ICT risk to critical functions | Crown-jewel-driven prioritisation focused on systems critical to financial stability, with dependency matrices linking each to its supporting infrastructure |
| DORA Resilience testing | Digital operational resilience testing, threat-led for financial entities identified under the applicable criteria | Adversary emulation aligned to the documented threat profile, validating telemetry completeness, detection timing and analyst decision quality |
| GDPR Art. 33 72-hour notification | Notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons | Threat visibility engineered outward from crown jewels, with dependency mapping that makes scoping which data and which subjects were affected a lookup rather than an investigation |
If you are preparing for NIS2 or DORA and have limited time, the sequence that produces the most regulatory evidence per unit of effort is the same one UTIOM prescribes anyway.
This page is a summary. The full treatment is in the book: UTIOM for NIS2 and DORA →
Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →