← UTIOM
UTIOMv1.4

Think smarter. Stay secure.

UTIOM for NIS2 and DORA

European regulation has moved from asking whether controls exist to asking whether they work. NIS2 requires policies on assessing effectiveness. DORA requires risk-based digital operational resilience testing; Article 26 additionally requires advanced threat-led penetration testing for identified financial entities. Both make senior management accountable.

Why this matters more in Europe

European organisations face a regulatory environment that has moved from asking whether controls exist to asking whether they work. NIS2 requires policies on assessing effectiveness. DORA requires resilience testing. Both make senior management accountable rather than delegating compliance to a security team.

That shift is exactly what UTIOM was designed for. A framework that documents intent satisfies the older generation of regulation. A framework that pairs every design decision with an activity that proves it satisfies this one.

Compliant on paper, exposed in reality is the failure mode these regulations were written to close. UTIOM addresses it structurally: controls are validated against real adversary behaviour through purple team exercises and detection testing, not asserted through documentation.

The regulations

NIS2Directive (EU) 2022/2555, with Commission Implementing Regulation (EU) 2024/2690
NIS2 has broad sectoral scope across essential and important entities and applies much more broadly across sectors than DORA. It covers essential and important entities across energy, transport, banking, health, water, digital infrastructure, public administration, manufacturing, food, chemicals, postal services, waste management, space and research — far more organisations than DORA, which is limited to financial entities.

Article 21 requires risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, and — critically — policies and procedures to assess the effectiveness of cybersecurity risk management measures. That last requirement is where most programmes are weakest, because effectiveness cannot be evidenced by a control inventory.

Article 20 makes management bodies responsible for approving and overseeing these measures, with training obligations and potential personal liability.

Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report not later than one month after the incident notification.
DORARegulation (EU) 2022/2554, with Commission Delegated Regulation (EU) 2025/1190 on TLPT
DORA applies to financial entities and establishes a Union oversight framework for designated critical ICT third-party service providers. Five pillars: ICT risk management, incident classification and reporting, a risk-based digital operational resilience testing programme under Articles 24–25, with TLPT under Article 26 for financial entities identified under the applicable criteria, third-party risk management, and information sharing.

DORA is more prescriptive than NIS2 on testing. Articles 24–25 require a risk-based digital operational resilience testing programme; Article 26 additionally requires advanced testing by means of TLPT for financial entities identified under the applicable criteria, set out in Commission Delegated Regulation (EU) 2025/1190.
GDPR Article 33Regulation (EU) 2016/679
Notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach.

Operationally, meeting that deadline depends heavily on how quickly the organisation can detect, classify and scope the breach. UTIOM supports that operational readiness; it does not determine whether the legal notification threshold has been met. It is a detection and scoping question: how quickly you become aware, and how quickly you can determine which data and which subjects were affected. Both are determined by telemetry design and asset dependency mapping made months earlier.

How UTIOM operationalises each requirement

These regulations state obligations. They do not describe how to build the capability that satisfies them. That gap is the one UTIOM fills.

Regulatory requirementWhat it demandsWhat UTIOM produces
NIS2 Art. 21(2)(a)
Risk analysis
Policies on risk analysis and information system securityCrown jewel registry with named business owners, business impact mapping across financial, regulatory, safety and reputational consequence, and threat models per asset
NIS2 Art. 21(2)(b)
Incident handling
Incident handling capabilityPre-engineered playbooks per crown jewel, containment authority and escalation thresholds defined in advance with named individuals, tiered response with decision gates
NIS2 Art. 21(2)(f)
Effectiveness assessment
Policies and procedures to assess the effectiveness of cybersecurity risk management measuresThe validation pairing. Purple team exercises emulating profiled adversaries, detection validation rate, response readiness validation, and failed detections raised as engineering defects with owners and dates
NIS2 Art. 20
Management accountability
Management bodies approve and oversee measures, with training obligationsVision and Strategy phases produce the governance artefacts: documented purpose, stakeholder map with decision authority, KPIs and KRIs tied to crown jewels, and stakeholder scorecards on a cadence
NIS2 Art. 23
24h early warning → 72h incident notification → one-month final report
Early warning within 24 hours, incident notification within 72 hours, final report not later than one month after the incident notificationContextual incident records tagged with crown jewel, TTPs observed and attack path, plus MTTD measured against priority TTPs — the inputs that make classification possible inside the window
DORA
ICT risk management
Identify and manage ICT risk to critical functionsCrown-jewel-driven prioritisation focused on systems critical to financial stability, with dependency matrices linking each to its supporting infrastructure
DORA
Resilience testing
Digital operational resilience testing, threat-led for financial entities identified under the applicable criteriaAdversary emulation aligned to the documented threat profile, validating telemetry completeness, detection timing and analyst decision quality
GDPR Art. 33
72-hour notification
Notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to result in a risk to the rights and freedoms of natural personsThreat visibility engineered outward from crown jewels, with dependency mapping that makes scoping which data and which subjects were affected a lookup rather than an investigation
A note on scope. UTIOM is an operating model, not legal advice and not a certification scheme. It produces the operational capability and evidence that these regulations require, but obligations vary by member state transposition, sector and entity classification. Verify against your own regulatory position and, where relevant, your national competent authority's guidance.

Where to start

If you are preparing for NIS2 or DORA and have limited time, the sequence that produces the most regulatory evidence per unit of effort is the same one UTIOM prescribes anyway.

1. Crown jewel registry
Named business owners and impact mapping. This is the artefact that NIS2 Article 21(2)(a) risk analysis and DORA ICT risk management both rest on, and almost nothing downstream is defensible without it.
2. Documented threat profile
Which adversaries realistically target an organisation of your sector and size. DORA Article 26 TLPT requirements is unsatisfiable without it, and NIS2 effectiveness assessment is meaningless against a generic threat.
3. Validation evidence
Exercises that produce dated records of what was tested, what failed and what changed as a result. UTIOM uses these validation records as operational evidence supporting the Article 21(2)(f) effectiveness-assessment requirement.
4. Response authority defined in advance
Who may authorise containment on which asset, at what threshold. Pre-defining response authority can materially improve the organisation’s ability to act within the Article 23 reporting timeline, and is the single cheapest improvement in most organisations.

This page is a summary. The full treatment is in the book: UTIOM for NIS2 and DORA →

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →