Cybersecurity & Resilience Frameworks

Interactive explorers for key cybersecurity regulations and frameworks. From EU regulations to international standards — choose a framework to dive in.

EU Regulations

EU Cybersecurity & Resilience Regulations

Binding EU frameworks shaping digital operational resilience and cybersecurity across Europe.

🛡

DORA

Regulation (EU) 2022/2554

The Digital Operational Resilience Act is a binding EU regulation requiring financial entities to withstand, respond to, and recover from ICT-related disruptions and threats. It establishes a comprehensive framework across five pillars: ICT risk management, incident reporting, resilience testing, third-party risk management, and information sharing.

Explore DORA
🔒

NIS2

Directive (EU) 2022/2555

The Network and Information Security Directive is a binding EU directive requiring essential and important entities across 18 critical sectors to implement cybersecurity risk management measures, report significant incidents, and submit to supervisory oversight. It introduces personal liability for management and harmonised penalties across member states.

Explore NIS2

DORA vs NIS2 Comparison

Both frameworks share the goal of strengthening Europe's cyber resilience, but they differ in scope, legal instrument, and enforcement approach.

DORANIS2
Legal Instrument Regulation — directly applicable in all EU member states Directive — must be transposed into national law by each member state
Primary Focus ICT operational resilience in the financial sector Cybersecurity across 18 critical sectors economy-wide
Who's In Scope 21 types of financial entities (banks, insurers, investment firms, ICT third-party providers, etc.) Essential & important entities in energy, transport, health, digital infrastructure, public admin, etc.
Key Obligations ICT risk framework, incident reporting, TLPT testing, third-party oversight, information sharing Risk management measures, incident notification, supply chain security, governance accountability
Incident Reporting Multi-stage: initial (4h), intermediate (72h), final (1 month) Early warning (24h), full notification (72h), final report (1 month)
Personal Liability Competent authorities can hold management functions responsible Explicit: management bodies can be personally liable, suspended from duties
Penalties Member-state penalties; periodic penalty payments for non-compliance Up to €10M or 2% of global turnover (essential); €7M or 1.4% (important)
Application Date 17 January 2025 18 October 2024

Cybersecurity Standards & Frameworks

Widely adopted cybersecurity frameworks and standards providing structured approaches to risk management, security controls, and compliance. From high-level outcome frameworks to prescriptive implementation guidance.

🇧

NIST CSF 2.0

NIST Cybersecurity Framework

The NIST Cybersecurity Framework is a voluntary, outcome-based framework developed by the U.S. National Institute of Standards and Technology. CSF 2.0 organises cybersecurity risk management into six core functions — Govern, Identify, Protect, Detect, Respond, and Recover — providing a universal taxonomy applicable to any organisation, sector, or maturity level.

Explore NIST CSF
🌐

ISO/IEC 27001

Information Security Management Systems

ISO/IEC 27001:2022 is the internationally recognized standard for Information Security Management Systems (ISMS). It provides a systematic, risk-based approach with 93 Annex A controls organized into 4 themes — Organizational, People, Physical, and Technological. Certification via accredited third-party audit is the global gold standard for information security.

Explore ISO 27001
📜

BSI IT-Grundschutz

Federal Office for Information Security (Germany)

The BSI IT-Grundschutz is Germany's comprehensive cybersecurity methodology, providing a compendium of ~100 building blocks (Bausteine) across 10 layers covering processes, systems, and infrastructure. It enables ISO 27001 certification based on IT-Grundschutz and is mandatory for German federal agencies, widely adopted across the DACH region.

Explore BSI IT-Grundschutz
🛠

CIS Controls v8.1

Center for Internet Security

The CIS Critical Security Controls are a prioritized, prescriptive set of 18 Controls with 153 Safeguards organized into three Implementation Groups (IG1/IG2/IG3). Community-developed and free to use, CIS Controls provide actionable, ordered guidance — start with IG1's 56 essential safeguards to defend against 80%+ of common attacks.

Explore CIS Controls

All Frameworks at a Glance

How all six frameworks compare across key dimensions.

DORANIS2NIST CSFISO 27001BSICIS Controls
Type EU Regulation EU Directive Voluntary framework International standard National methodology Community best practices
Approach Regulatory (binding) Directive (transposed) Outcome-based Risk-based ISMS Prescriptive Prioritised, prescriptive
Scope Financial sector 18 critical sectors Any organisation Any organisation Any (mandatory DE fed.) Any organisation
Structure 5 Pillars, 64 Articles 5 Pillars, 46 Articles 6 Functions, 106 Subcat. 93 Controls, 4 Themes 10 Layers, ~100 Modules 18 Controls, 153 Safeg.
Certification Supervisory oversight National supervision No (self-assessment) Yes (accredited audit) Yes (BSI + ISO 27001) No (CSAT self-assess.)
Cost N/A (regulation) N/A (directive) Free Paid (~$150) Free (compendium) Free
Penalties Member-state defined €10M / 2% turnover None (voluntary) None (cert. loss) None (cert. loss) None (voluntary)