NIS2 / DORA / Cyber Resilience Act: what changes and how to prepare your organisation
Scope, governance, risk, incidents, third parties, digital products and evidence: a practical structure for preparing your organisation without confusing distinct regulatory frameworks.
⏱️ Estimated reading time: 7–8 minutes
NIS2, DORA and the Cyber Resilience Act are transforming how organisations manage risk, incidents, third parties, products with digital elements and evidence. Although they share some concerns, they apply to different contexts and require different responses.
In Portugal, Decree-Law No. 125/2025 established the new Cybersecurity Legal Framework, transposing NIS2, and entered into force on 3 April 2026. Regulation No. 756/2026, in force since 23 June, set out matters such as the operation of the electronic platform, the National Cybersecurity Reference Framework, the risk matrix, minimum measures and verification criteria.
DORA has applied directly since 17 January 2025. Under the Cyber Resilience Act, reporting obligations start to apply on 11 September 2026, while the Regulation applies generally from 11 December 2027.
How should your organisation prepare for NIS2 / DORA / the Cyber Resilience Act?
Preparation should begin by confirming scope: which entities, activities, services, operations and products fall within each framework. The organisation should then assign responsibilities, assess risks and dependencies, identify gaps and organise the required evidence.
The objective is not to create three completely isolated programmes, but to establish a common foundation for governance, risk, incidents, third parties, testing and evidence, supplemented by the specific requirements of each regime.
The critical point
Starting with a generic list of controls can create duplicated work, unclear responsibilities and documentation that does not demonstrate execution.
Scope should be confirmed before implementation begins.
What distinguishes NIS2, DORA and the Cyber Resilience Act?
At a glance, the differences concern the organisations in scope, the subject being protected and the first point that needs to be confirmed:
| Framework | Primarily applies to | Primary focus | First point to confirm |
|---|---|---|---|
| NIS2 / Portuguese framework | Essential entities, important entities and relevant public entities | Entity-level risk management and resilience | Entities, activities and services in scope |
| DORA | Financial-sector entities | Digital operational resilience | Critical functions and ICT dependencies |
| Cyber Resilience Act | Manufacturers, as well as importers and distributors | Security of products with digital elements throughout their lifecycle | Products, role in the supply chain and support period |
NIS2 and Portugal’s cybersecurity framework
NIS2 focuses on the resilience of the entities within its scope. The new Portuguese framework covers 17 sectors and a significant part of the Public Administration, allowing entities to be classified as essential, important or relevant public entities.
It strengthens the accountability of management bodies, the risk-based approach, supply chain security and incident preparedness. The MyCiber platform supports processes such as self-identification, classification, registration of designated responsible persons and incident notification. Organisations that may be in scope should confirm the applicable procedures and deadlines in the official guidance currently in force.
Central question
Can the organisation demonstrate that cybersecurity risks are identified, treated, overseen and reported?
DORA
DORA applies to the financial sector and seeks to ensure that entities can maintain or recover their critical functions when faced with technological disruption.
The Regulation covers ICT risk management, incident management and reporting, digital operational resilience testing and the control of risks associated with third-party ICT service providers.
Central question
Can the entity continue to provide critical services when a technology failure, an incident or a supplier disruption occurs?
Cyber Resilience Act
The Cyber Resilience Act is primarily directed at manufacturers of products with digital elements, including hardware and software, although it also assigns responsibilities to importers and distributors.
Its focus is product security throughout the lifecycle: risk assessment, security by design, vulnerability management, technical documentation, updates and conformity assessment. From 11 September 2026, the Regulation provides for an initial warning within 24 hours and a full notification within 72 hours for actively exploited vulnerabilities and severe incidents affecting product security.
Central question
Can the organisation demonstrate that it has embedded security in the product and continues to manage vulnerabilities throughout the support period?
The same organisation may be affected by more than one framework. A financial entity, for example, may be subject to DORA while also developing or distributing products covered by the Cyber Resilience Act.
The analysis should be conducted by legal entity, activity, service, product and role in the value chain — not merely by the group’s commercial name.
Five priorities for starting your preparation
1. Confirm the scope
Identify the entities, activities, services, products and geographies that may be in scope. Requirements imposed by clients, partners, contracts or sectoral authorities should also be considered. Without this analysis, the organisation may apply controls to the wrong context or leave relevant responsibilities uncovered.
2. Establish governance and responsibilities
Clarify who approves the plan, who coordinates implementation, who maintains external contacts and who makes decisions during an incident. Responsibility should not be concentrated solely within the cybersecurity team: management, IT, risk, compliance, operations, procurement, product and internal audit may have different but complementary roles.
3. Assess risks and dependencies
Map assets, critical services, third-party providers, software components and single points of failure. The assessment should show which dependencies could interrupt a service, affect a product or prevent the organisation from meeting a reporting obligation.
4. Prepare for incidents, vulnerabilities and continuity
Procedures should establish criteria for classification, escalation, decision-making, information gathering and reporting. They should also be tested: a procedure that has never been exercised may reveal weaknesses precisely when the organisation needs it most.
5. Organise capabilities and evidence
The organisation should be able to demonstrate what it decided, who was assigned responsibility, what was implemented and how effectiveness was verified. Regulation No. 756/2026 defines verification criteria as factual, documentary or technical evidence that cybersecurity measures have been applied. Having a policy is not enough: the organisation must prove that it was implemented, monitored and reviewed.
Quick evidence test
- What was decided?
- Who was assigned responsibility?
- What was actually carried out?
- How was effectiveness verified?
Choose training aligned with the applicable framework
NIS 2, DORA and the Cyber Resilience Act share themes such as governance, risk, incidents, third parties and evidence, but each regime requires specific capabilities. Explore the pathway directly aligned with your context and your team’s responsibilities.
A practical phased plan
The five priorities show what should be assessed. The following three phases show how to sequence the work, adapting the order to the organisation’s size, maturity and exposure.
Some activities may take place in parallel, provided that priorities, accountable owners and completion criteria are clearly defined.
Phase 1 — Confirm scope and establish governance
During this phase, the organisation should:
- map the entities, activities, services and products that may be in scope;
- define accountable owners, points of contact and decision-making channels;
- establish management oversight and a central evidence repository.
Expected outcome: a formally approved scope map identifying accountable owners, entities and services in scope.
Phase 2 — Assess gaps and set priorities
The organisation should compare applicable requirements with existing practices and evidence, identify dependencies and gaps, and prioritise work according to risk, criticality and the potential impact on clients and operations.
Expected outcome: a gap matrix showing the requirement, existing practice, available evidence, accountable owner and priority.
Phase 3 — Implement, test and demonstrate
The third phase turns decisions into verifiable practices. The organisation should implement or strengthen priority controls, update policies and contracts, test incident, vulnerability and continuity procedures, and monitor corrective actions.
Evidence should be reviewed to confirm that it demonstrates not only the existence of controls, but also their implementation and effectiveness.
Expected outcome: priority controls in operation, a test report, corrective actions and an evidence dossier reviewed by management.
This model does not, by itself, represent full compliance. It provides a structure for organising capability development, implementation, advisory support or internal audit.
What capabilities should be developed?
Preparation should be adapted to the functions performed. Management bodies need to understand risk, approve priorities and monitor deviations. Security, IT and operations teams should implement controls and carry out response procedures.
Procurement and supplier management need to assess dependencies and contracts. Product and engineering teams should integrate security into development and manage components, updates and vulnerabilities. Internal audit, risk and compliance should be able to assess controls and link conclusions to verifiable criteria and evidence.
The organisation should therefore identify not only who needs awareness, but also who requires decision-making, implementation, reporting, testing and verification capabilities.
How Behaviour can support you
Behaviour can support you through framework-specific training, advisory services and internal audit/readiness assessment.
Framework-specific training
NIS 2 Compliance Lead Manager
For designing, leading and improving a NIS 2 compliance framework that connects governance, risk, measures, incidents, reporting, supervision and evidence.
DORA Compliance Lead Manager
For operationalising DORA through governance, ICT risk, incidents, digital operational resilience testing, third parties and evidence.
Cyber Resilience Act Foundation
For understanding the scope and cybersecurity requirements applicable to products with digital elements throughout their lifecycle.
View all Digital Compliance and Operational Resilience pathways
Advisory
Helps clarify scope, set priorities and turn the diagnosis into an executable path.
Internal audit / readiness assessment
Provides an independent assessment of implemented controls, available evidence and the monitoring of corrective actions.
The pathway should be selected according to the applicable framework, participant roles and the objective: awareness, foundations, governance, implementation, management or verification.
Frequently asked questions about NIS2, DORA and the Cyber Resilience Act
Why should I prepare my team for NIS2 / DORA / the Cyber Resilience Act?
Is training enough?
Which course should I choose?
Choose according to the applicable framework, your role and your level of responsibility:
- NIS 2 Compliance Lead Manager: for professionals who need to lead a NIS 2 compliance framework, from scope and governance to measures, reporting, supervision and evidence.
- DORA Compliance Lead Manager: for professionals who need to operationalise governance, ICT risk, incidents, resilience testing, third parties and evidence in the DORA context.
- Cyber Resilience Act Foundation: for professionals who need to understand the scope and security requirements applicable to products with digital elements throughout their lifecycle.
When the objective is awareness, foundation-level knowledge or executive governance, explore the other pathways available in Digital Compliance and Operational Resilience.
Conclusion
NIS2, DORA and the Cyber Resilience Act may share a common foundation of governance, risk, incidents, third parties, testing, capabilities and evidence. However, the scope, addressees, reporting processes and specific obligations of each regime remain distinct and should be managed accordingly.
Knowing each framework is no longer enough. Organisations need to demonstrate — through prepared people and verifiable evidence — their ability to decide, implement, respond and improve.
Next step
Select the pathway directly aligned with the framework applicable to your organisation, or speak to the Behaviour team to frame training, advisory and internal audit support.
Recommended resource
NIS2 / DORA / Cyber Resilience Act checklist: 10 evidence areas to start preparing
A practical, editable checklist to support an internal diagnosis and organise the first evidence related to NIS2, DORA and the Cyber Resilience Act.
The document enables you to record, across ten essential areas:
- the evidence to be confirmed;
- the applicable framework;
- the implementation status;
- the accountable owner;
- the next action.
Use the checklist to identify dispersed documentation, priority gaps and responsibilities that need to be clarified. The linked checklist is currently available in Portuguese.
Note: this article and the checklist are for information purposes only and do not replace a legal, regulatory or technical assessment of the specific circumstances. Confirmation of scope and applicable obligations should take account of the organisation’s activities and the official sources currently in force.
Official sources consulted
Decree-Law No. 125/2025 — Diário da República.
Regulation No. 756/2026 — Diário da República.
NIS2 Directive and the new Portuguese Cybersecurity Legal Framework — CNCS.
Regulation (EU) 2022/2554 — DORA — EUR-Lex.
Cyber Resilience Act and reporting obligations — European Commission.
Would you like to explore this topic further?
Explore training, advisory and audit services related to cybersecurity, risk, compliance and resilience.
View Digital Compliance and Operational Resilience
View Advisory
View Internal Audit
View the Training Catalogue
Date: 20 July 2026
Author: Behaviour
Copying or reproduction of this article is not authorised.