NIS2 / DORA / Cyber Resilience Act: what changes and how to prepare your organisation

Scope, governance, risk, incidents, third parties, digital products and evidence: a practical structure for preparing your organisation without confusing distinct regulatory frameworks.

⏱️ Estimated reading time: 7–8 minutes

NIS2, DORA and the Cyber Resilience Act are transforming how organisations manage risk, incidents, third parties, products with digital elements and evidence. Although they share some concerns, they apply to different contexts and require different responses.

In Portugal, Decree-Law No. 125/2025 established the new Cybersecurity Legal Framework, transposing NIS2, and entered into force on 3 April 2026. Regulation No. 756/2026, in force since 23 June, set out matters such as the operation of the electronic platform, the National Cybersecurity Reference Framework, the risk matrix, minimum measures and verification criteria.

DORA has applied directly since 17 January 2025. Under the Cyber Resilience Act, reporting obligations start to apply on 11 September 2026, while the Regulation applies generally from 11 December 2027.

How should your organisation prepare for NIS2 / DORA / the Cyber Resilience Act?

Preparation should begin by confirming scope: which entities, activities, services, operations and products fall within each framework. The organisation should then assign responsibilities, assess risks and dependencies, identify gaps and organise the required evidence.

The objective is not to create three completely isolated programmes, but to establish a common foundation for governance, risk, incidents, third parties, testing and evidence, supplemented by the specific requirements of each regime.

The critical point

Starting with a generic list of controls can create duplicated work, unclear responsibilities and documentation that does not demonstrate execution.

Scope should be confirmed before implementation begins.

What distinguishes NIS2, DORA and the Cyber Resilience Act?

At a glance, the differences concern the organisations in scope, the subject being protected and the first point that needs to be confirmed:

Framework Primarily applies to Primary focus First point to confirm
NIS2 / Portuguese framework Essential entities, important entities and relevant public entities Entity-level risk management and resilience Entities, activities and services in scope
DORA Financial-sector entities Digital operational resilience Critical functions and ICT dependencies
Cyber Resilience Act Manufacturers, as well as importers and distributors Security of products with digital elements throughout their lifecycle Products, role in the supply chain and support period

NIS2 and Portugal’s cybersecurity framework

NIS2 focuses on the resilience of the entities within its scope. The new Portuguese framework covers 17 sectors and a significant part of the Public Administration, allowing entities to be classified as essential, important or relevant public entities.

It strengthens the accountability of management bodies, the risk-based approach, supply chain security and incident preparedness. The MyCiber platform supports processes such as self-identification, classification, registration of designated responsible persons and incident notification. Organisations that may be in scope should confirm the applicable procedures and deadlines in the official guidance currently in force.

Central question

Can the organisation demonstrate that cybersecurity risks are identified, treated, overseen and reported?

DORA

DORA applies to the financial sector and seeks to ensure that entities can maintain or recover their critical functions when faced with technological disruption.

The Regulation covers ICT risk management, incident management and reporting, digital operational resilience testing and the control of risks associated with third-party ICT service providers.

Central question

Can the entity continue to provide critical services when a technology failure, an incident or a supplier disruption occurs?

Cyber Resilience Act

The Cyber Resilience Act is primarily directed at manufacturers of products with digital elements, including hardware and software, although it also assigns responsibilities to importers and distributors.

Its focus is product security throughout the lifecycle: risk assessment, security by design, vulnerability management, technical documentation, updates and conformity assessment. From 11 September 2026, the Regulation provides for an initial warning within 24 hours and a full notification within 72 hours for actively exploited vulnerabilities and severe incidents affecting product security.

Central question

Can the organisation demonstrate that it has embedded security in the product and continues to manage vulnerabilities throughout the support period?

The same organisation may be affected by more than one framework. A financial entity, for example, may be subject to DORA while also developing or distributing products covered by the Cyber Resilience Act.

The analysis should be conducted by legal entity, activity, service, product and role in the value chain — not merely by the group’s commercial name.

Five priorities for starting your preparation

1. Confirm the scope

Identify the entities, activities, services, products and geographies that may be in scope. Requirements imposed by clients, partners, contracts or sectoral authorities should also be considered. Without this analysis, the organisation may apply controls to the wrong context or leave relevant responsibilities uncovered.

2. Establish governance and responsibilities

Clarify who approves the plan, who coordinates implementation, who maintains external contacts and who makes decisions during an incident. Responsibility should not be concentrated solely within the cybersecurity team: management, IT, risk, compliance, operations, procurement, product and internal audit may have different but complementary roles.

3. Assess risks and dependencies

Map assets, critical services, third-party providers, software components and single points of failure. The assessment should show which dependencies could interrupt a service, affect a product or prevent the organisation from meeting a reporting obligation.

4. Prepare for incidents, vulnerabilities and continuity

Procedures should establish criteria for classification, escalation, decision-making, information gathering and reporting. They should also be tested: a procedure that has never been exercised may reveal weaknesses precisely when the organisation needs it most.

5. Organise capabilities and evidence

The organisation should be able to demonstrate what it decided, who was assigned responsibility, what was implemented and how effectiveness was verified. Regulation No. 756/2026 defines verification criteria as factual, documentary or technical evidence that cybersecurity measures have been applied. Having a policy is not enough: the organisation must prove that it was implemented, monitored and reviewed.

Quick evidence test

  • What was decided?
  • Who was assigned responsibility?
  • What was actually carried out?
  • How was effectiveness verified?

Choose training aligned with the applicable framework

NIS 2, DORA and the Cyber Resilience Act share themes such as governance, risk, incidents, third parties and evidence, but each regime requires specific capabilities. Explore the pathway directly aligned with your context and your team’s responsibilities.

A practical phased plan

The five priorities show what should be assessed. The following three phases show how to sequence the work, adapting the order to the organisation’s size, maturity and exposure.

Some activities may take place in parallel, provided that priorities, accountable owners and completion criteria are clearly defined.

Phase 1 — Confirm scope and establish governance

During this phase, the organisation should:

  • map the entities, activities, services and products that may be in scope;
  • define accountable owners, points of contact and decision-making channels;
  • establish management oversight and a central evidence repository.

Expected outcome: a formally approved scope map identifying accountable owners, entities and services in scope.

Phase 2 — Assess gaps and set priorities

The organisation should compare applicable requirements with existing practices and evidence, identify dependencies and gaps, and prioritise work according to risk, criticality and the potential impact on clients and operations.

Expected outcome: a gap matrix showing the requirement, existing practice, available evidence, accountable owner and priority.

Phase 3 — Implement, test and demonstrate

The third phase turns decisions into verifiable practices. The organisation should implement or strengthen priority controls, update policies and contracts, test incident, vulnerability and continuity procedures, and monitor corrective actions.

Evidence should be reviewed to confirm that it demonstrates not only the existence of controls, but also their implementation and effectiveness.

Expected outcome: priority controls in operation, a test report, corrective actions and an evidence dossier reviewed by management.

This model does not, by itself, represent full compliance. It provides a structure for organising capability development, implementation, advisory support or internal audit.

What capabilities should be developed?

Preparation should be adapted to the functions performed. Management bodies need to understand risk, approve priorities and monitor deviations. Security, IT and operations teams should implement controls and carry out response procedures.

Procurement and supplier management need to assess dependencies and contracts. Product and engineering teams should integrate security into development and manage components, updates and vulnerabilities. Internal audit, risk and compliance should be able to assess controls and link conclusions to verifiable criteria and evidence.

The organisation should therefore identify not only who needs awareness, but also who requires decision-making, implementation, reporting, testing and verification capabilities.

How Behaviour can support you

Behaviour can support you through framework-specific training, advisory services and internal audit/readiness assessment.

Framework-specific training

NIS 2 Compliance Lead Manager

For designing, leading and improving a NIS 2 compliance framework that connects governance, risk, measures, incidents, reporting, supervision and evidence.

View the NIS 2 course

DORA Compliance Lead Manager

For operationalising DORA through governance, ICT risk, incidents, digital operational resilience testing, third parties and evidence.

View the DORA course

Cyber Resilience Act Foundation

For understanding the scope and cybersecurity requirements applicable to products with digital elements throughout their lifecycle.

View the Cyber Resilience Act course

View all Digital Compliance and Operational Resilience pathways

Advisory

Helps clarify scope, set priorities and turn the diagnosis into an executable path.

View advisory services

Internal audit / readiness assessment

Provides an independent assessment of implemented controls, available evidence and the monitoring of corrective actions.

View internal audit and readiness assessment

The pathway should be selected according to the applicable framework, participant roles and the objective: awareness, foundations, governance, implementation, management or verification.

Frequently asked questions about NIS2, DORA and the Cyber Resilience Act

Why should I prepare my team for NIS2 / DORA / the Cyber Resilience Act?
Preparation reduces uncertainty, improves the consistency of decisions and helps the organisation demonstrate evidence to auditors, authorities, clients or partners. It also makes it possible to allocate responsibilities before an incident occurs or an urgent request for information is received.
Is training enough?
It depends on the objective. Training is a starting point for developing capabilities and creating a common language. When the organisation needs to implement, review or verify controls, training may need to be complemented by advisory services or internal audit.
Which course should I choose?

Choose according to the applicable framework, your role and your level of responsibility:

  • NIS 2 Compliance Lead Manager: for professionals who need to lead a NIS 2 compliance framework, from scope and governance to measures, reporting, supervision and evidence.
  • DORA Compliance Lead Manager: for professionals who need to operationalise governance, ICT risk, incidents, resilience testing, third parties and evidence in the DORA context.
  • Cyber Resilience Act Foundation: for professionals who need to understand the scope and security requirements applicable to products with digital elements throughout their lifecycle.

When the objective is awareness, foundation-level knowledge or executive governance, explore the other pathways available in Digital Compliance and Operational Resilience.

Conclusion

NIS2, DORA and the Cyber Resilience Act may share a common foundation of governance, risk, incidents, third parties, testing, capabilities and evidence. However, the scope, addressees, reporting processes and specific obligations of each regime remain distinct and should be managed accordingly.

Knowing each framework is no longer enough. Organisations need to demonstrate — through prepared people and verifiable evidence — their ability to decide, implement, respond and improve.

Next step

Select the pathway directly aligned with the framework applicable to your organisation, or speak to the Behaviour team to frame training, advisory and internal audit support.

Recommended resource

NIS2 / DORA / Cyber Resilience Act checklist: 10 evidence areas to start preparing

A practical, editable checklist to support an internal diagnosis and organise the first evidence related to NIS2, DORA and the Cyber Resilience Act.

The document enables you to record, across ten essential areas:

  • the evidence to be confirmed;
  • the applicable framework;
  • the implementation status;
  • the accountable owner;
  • the next action.

Use the checklist to identify dispersed documentation, priority gaps and responsibilities that need to be clarified. The linked checklist is currently available in Portuguese.

Note: this article and the checklist are for information purposes only and do not replace a legal, regulatory or technical assessment of the specific circumstances. Confirmation of scope and applicable obligations should take account of the organisation’s activities and the official sources currently in force.

Official sources consulted

Decree-Law No. 125/2025 — Diário da República.

Regulation No. 756/2026 — Diário da República.

NIS2 Directive and the new Portuguese Cybersecurity Legal Framework — CNCS.

Regulation (EU) 2022/2554 — DORA — EUR-Lex.

Cyber Resilience Act and reporting obligations — European Commission.

Would you like to explore this topic further?

Explore training, advisory and audit services related to cybersecurity, risk, compliance and resilience.

View Digital Compliance and Operational Resilience
View Advisory
View Internal Audit
View the Training Catalogue

Date: 20 July 2026
Author: Behaviour
Copying or reproduction of this article is not authorised.