NIS2 / DORA / Cyber Resilience Act: what changes and how to prepare your organisation

Practical Guide NIS 2_DORA_Cyber Resilience Act

NIS2 / DORA / Cyber Resilience Act: what changes and how to prepare your organisation

Scope, governance, risk, incidents, third parties, digital products and evidence: a practical structure for preparing your organisation without confusing distinct regulatory frameworks.

⏱️ Estimated reading time: 7–8 minutes

NIS2, DORA and the Cyber Resilience Act are transforming how organisations manage risk, incidents, third parties, products with digital elements and evidence. Although they share some concerns, they apply to different contexts and require different responses.

In Portugal, Decree-Law No. 125/2025 established the new Cybersecurity Legal Framework, transposing NIS2, and entered into force on 3 April 2026. Regulation No. 756/2026, in force since 23 June, set out matters such as the operation of the electronic platform, the National Cybersecurity Reference Framework, the risk matrix, minimum measures and verification criteria.

DORA has applied directly since 17 January 2025. Under the Cyber Resilience Act, reporting obligations start to apply on 11 September 2026, while the Regulation applies generally from 11 December 2027.

ISO 22301: practical guide to business continuity

ISO 22301_Practical Guide to Business Continuity

ISO 22301: practical guide to business continuity

How to prepare your organisation, structure evidence and build capability.

⏱️ Estimated reading time: 8 minutes

This practical guide to ISO 22301 and business continuity explains how to prepare your organisation, define recovery priorities and objectives, test plans and compile audit evidence.

ISO 22301 and business continuity: what is it and who does it apply to?

ISO 22301 specifies the requirements for establishing, implementing, maintaining and improving a Business Continuity Management System (BCMS). It can be applied by organisations of any size or sector that need to ensure the delivery of prioritised products and services during a disruption.

The standard is voluntary as a management system and certification framework. Nevertheless, legal, sector-specific or contractual requirements may require specific continuity, recovery and evidence capabilities. Certification is one way to demonstrate conformity with the standard, but it does not replace obligations applicable to the organisation.

ISO 27001 and DORA: how to align information security, ICT risk and operational resilience

ISO 27001 and DORA alignment guide

ISO 27001 and DORA: how to align information security, ICT risk and operational resilience

ISO/IEC 27001 does not replace DORA, but it can provide a solid foundation for organising Information Security, ICT risk management, continuity, documented evidence and supplier oversight.

⏱️ Estimated reading time: 5 minutes

Information Security is no longer only a technical responsibility. Today, it is also a priority for management, compliance, business continuity and digital trust.

With DORA, financial entities and many of their service providers face more demanding requirements for ICT risk, incidents, digital operational resilience testing and third-party management. In this context, ISO/IEC 27001 becomes particularly relevant because it offers a recognised framework for organising policies, responsibilities, controls, evidence and continual improvement.

For organisations and professionals, understanding the connection between ISO 27001 and DORA can be a strategic advantage.

Regulation 756/2026: what changes in cybersecurity in Portugal and how to prepare your organisation

Cybersecurity Regulation 256_2026

Regulation 756/2026: what is changing in cybersecurity in Portugal and how to prepare your company

Regulation No. 756/2026 implements the new Legal Framework for Cybersecurity in Portugal and turns cybersecurity into a demonstrable responsibility of governance, risk, evidence, incident response and operational resilience.

⏱️ Estimated reading time: 4 minutes

Regulation No. 756/2026, of 22 June, has been published, implementing the new Legal Framework for Cybersecurity in Portugal. This regulation operationalises several obligations provided for in Decree-Law No. 125/2025, the legal instrument that transposed the NIS2 Directive into Portuguese law.

For companies, the message is clear: cybersecurity is no longer only a technical topic. It is becoming a demonstrable responsibility of governance, risk, evidence, incident response and operational resilience.

Cybersecurity in 2026: why digital risk is no longer just an IT responsibility

Cybersecurity in 2026

Cybersecurity in 2026: why digital risk is no longer just an IT responsibility

Cybersecurity is no longer just a technical issue. In 2026, it is also a matter of governance, risk management, compliance, operational continuity, evidence and team readiness.

That is why discussing cybersecurity in 2026 means discussing digital risk, compliance, operational resilience and the ability to demonstrate evidence.

⏱️ Estimated reading time: 7 minutes

“`For years, cybersecurity was treated as an essentially technical matter. The focus was on firewalls, antivirus, access management, backups, tools, systems and IT teams.

All of this remains essential. But it is no longer enough.

Frameworks vs Regulations: what do you really need to implement?

Frameworks vs Regulations_eng

Frameworks & Regulations • Article

Frameworks vs Regulations: what to implement and why

⏱️ Estimated reading time: 8 minutes

Frameworks vs regulations is one of the most common questions for organisations that need to improve maturity, meet legal obligations and avoid duplicated compliance work.

Frameworks vs regulations: comparison between best practices and legal requirements

In a world saturated with standards, frameworks, directives and regulations, many organisations face the same question:
After all, what should we implement? ISO/IEC 27001? NIST? NIS 2? DORA? Everything?