Meet Every Regulation In Scope,
And Prove It To The Board

A single answer to NIS2, DORA, GDPR and the EU AI Act, backed by governance your management body can stand behind. IrisInfosec maps each obligation to a clear control, builds the board reporting and risk register the regulations now expect, and keeps the programme current as the rules and the deadlines move. Lawyer-led, read at source.

4

EU regimes mapped together: NIS2, DORA, GDPR, EU AI Act.

1

Control set answering several regulations at once.

Board

Reporting your management body can approve and own.

Source

Read from EUR-Lex and ENISA, not a competitor blog.

What this covers

Regulation, Translated Into Action And Oversight

Knowing a regulation applies is the easy part. The work is turning its articles into controls your teams can run, evidence an auditor accepts, and reporting a board can approve. That translation is what we do, and it is where a programme led by a lawyer earns its place.

Cyber regulation increasingly names the management body directly: boards are expected to approve cyber risk, oversee it, and in some cases hold personal accountability. Governance is no longer optional housekeeping, it is part of the obligation.

In one line

Regulatory compliance and cyber governance

is the work of mapping your cyber obligations to concrete controls and standing up the oversight, policies and reporting that let a board and a regulator both see they are met.

Regulations we map and meet

Lead With The EU Stack, Extend To The Rest

We start where obligation is sharpest, then carry the same control set into the other
regimes you operate under.

NIS2

Risk management, incident reporting and supply chain duties for essential and important entities, with management accountability built in.

DORA

Digital operational resilience for financial entities: ICT risk, incident classification, resilience testing and third-party oversight.

GDPR

Lawful basis, data subject rights, breach notification and accountability for any organisation handling EU personal data.

EU AI Act

Risk classification and obligations for providers and deployers of AI systems placed on the EU market.

India DPDPA

India’s Digital Personal Data Protection Act: consent, notice, data principal rights and obligations for data fiduciaries.

Sector And US Overlays

CERT-In, RBI, SEBI and IRDAI directions in India, and HIPAA and CCPA in the US, layered onto the core programme.

Common question

NIS2 Vs DORA

They overlap, and many groups fall under both. Here is how they differ, and how we keep
you from doing the work twice.

NIS2 DORA
Type Directive, transposed by each member state Regulation, applies directly across the EU
Who Essential and important entities, many sectors Financial entities and their ICT providers
Focus Cyber risk management and incident reporting Digital operational resilience end to end
Third parties Supply chain security duties Detailed ICT third-party oversight and registers
If both apply DORA generally takes precedence for financial entities on ICT risk; we map the two to one control set so nothing is duplicated

How we work

From Article To Evidence

A measured five-stage approach, scoped to the regulations that actually apply to you.

01

Scope & Applicability

Confirm which regulations apply by entity, sector and jurisdiction, and where the deadlines fall.

02

Gap Assessment

Measure current state against each obligation and rank the gaps by risk and by date.

03

Map To Controls

Translate overlapping articles into one control set, so a single effort satisfies several regimes.

04

Implement & Document

Stand up policies, processes and reporting, and capture the evidence each clause requires.

05

Govern & Report

Board reporting and a maintained register, with a cadence that keeps you current as rules change.

Cyber governance

The Oversight Regulators Now Expect To See

Several regimes have moved governance from the appendix to the front page. We build the
structures that let your board direct and oversee cyber risk with confidence.

Roles And Accountability

Clear ownership from the board down, with a RACI that holds up under scrutiny.

Board-Level Reporting

A risk picture executives can read, approve and act on, not a wall of red and green.

Policy Framework

A coherent set of policies and standards, owned and reviewed on a defined cadence.

A Living Risk Register

Risks tracked, treated and reviewed, so the register reflects reality rather than last year.

Pair Governance With Proof

A control that is documented but never tested is a finding waiting to happen. We pair this programme with independent assessment, so your evidence is verified, not asserted.

Know exactly what applies to you

Get An Obligations Map In Days, Not Months

Tell us your sectors and the markets you operate in. We will confirm which regulations apply and send a prioritised plan with dates.

Questions, answered

Regulatory Compliance FAQ

NIS2 applies to medium and large organisations classed as essential or important entities across sectors including energy, transport, banking, health, digital infrastructure, public administration and manufacturing. It widened the scope of the original NIS Directive, so many organisations are in scope for the first time.

DORA is a regulation focused on digital operational resilience for EU financial entities and their ICT third-party providers. NIS2 is a directive covering cybersecurity across many essential and important sectors. Where both apply, DORA generally takes precedence for financial entities on ICT matters, and we map the two together so controls are not duplicated.

Cyber governance is how an organisation directs and oversees security: defined roles and accountability, a board that receives meaningful risk reporting, documented policies, and a risk register that is actually maintained. Several regulations now expect management bodies to approve and oversee cyber risk, so governance is a compliance requirement, not just good practice.

DORA has applied since January 2025. NIS2 member-state laws are being enforced through 2025 and 2026, with timelines varying by country. Because dates move and enforcement is staged, we work to the transposition status in each country where you operate and prioritise by real exposure.

Yes. Alongside the EU stack we map India’s DPDPA and sector rules from CERT-In, the RBI, SEBI and IRDAI, and US regimes such as HIPAA and CCPA, so a single governance programme carries across the markets you operate in.

Related services

One Programme For Every Regulator You Answer To

Book a call with an advisor who reads the regulation at source. We map your obligations and send a staged plan with dates, no obligation.