Cybersecurity & Resilience Frameworks
Interactive explorers for key cybersecurity regulations and frameworks. From EU regulations to international standards — choose a framework to dive in.
EU Cybersecurity & Resilience Regulations
Binding EU frameworks shaping digital operational resilience and cybersecurity across Europe.
DORA
Regulation (EU) 2022/2554
The Digital Operational Resilience Act is a binding EU regulation requiring financial entities to withstand, respond to, and recover from ICT-related disruptions and threats. It establishes a comprehensive framework across five pillars: ICT risk management, incident reporting, resilience testing, third-party risk management, and information sharing.
Explore DORANIS2
Directive (EU) 2022/2555
The Network and Information Security Directive is a binding EU directive requiring essential and important entities across 18 critical sectors to implement cybersecurity risk management measures, report significant incidents, and submit to supervisory oversight. It introduces personal liability for management and harmonised penalties across member states.
Explore NIS2DORA vs NIS2 Comparison
Both frameworks share the goal of strengthening Europe's cyber resilience, but they differ in scope, legal instrument, and enforcement approach.
| DORA | NIS2 | |
|---|---|---|
| Legal Instrument | Regulation — directly applicable in all EU member states | Directive — must be transposed into national law by each member state |
| Primary Focus | ICT operational resilience in the financial sector | Cybersecurity across 18 critical sectors economy-wide |
| Who's In Scope | 21 types of financial entities (banks, insurers, investment firms, ICT third-party providers, etc.) | Essential & important entities in energy, transport, health, digital infrastructure, public admin, etc. |
| Key Obligations | ICT risk framework, incident reporting, TLPT testing, third-party oversight, information sharing | Risk management measures, incident notification, supply chain security, governance accountability |
| Incident Reporting | Multi-stage: initial (4h), intermediate (72h), final (1 month) | Early warning (24h), full notification (72h), final report (1 month) |
| Personal Liability | Competent authorities can hold management functions responsible | Explicit: management bodies can be personally liable, suspended from duties |
| Penalties | Member-state penalties; periodic penalty payments for non-compliance | Up to €10M or 2% of global turnover (essential); €7M or 1.4% (important) |
| Application Date | 17 January 2025 | 18 October 2024 |
Cybersecurity Standards & Frameworks
Widely adopted cybersecurity frameworks and standards providing structured approaches to risk management, security controls, and compliance. From high-level outcome frameworks to prescriptive implementation guidance.
NIST CSF 2.0
NIST Cybersecurity Framework
The NIST Cybersecurity Framework is a voluntary, outcome-based framework developed by the U.S. National Institute of Standards and Technology. CSF 2.0 organises cybersecurity risk management into six core functions — Govern, Identify, Protect, Detect, Respond, and Recover — providing a universal taxonomy applicable to any organisation, sector, or maturity level.
Explore NIST CSFISO/IEC 27001
Information Security Management Systems
ISO/IEC 27001:2022 is the internationally recognized standard for Information Security Management Systems (ISMS). It provides a systematic, risk-based approach with 93 Annex A controls organized into 4 themes — Organizational, People, Physical, and Technological. Certification via accredited third-party audit is the global gold standard for information security.
Explore ISO 27001BSI IT-Grundschutz
Federal Office for Information Security (Germany)
The BSI IT-Grundschutz is Germany's comprehensive cybersecurity methodology, providing a compendium of ~100 building blocks (Bausteine) across 10 layers covering processes, systems, and infrastructure. It enables ISO 27001 certification based on IT-Grundschutz and is mandatory for German federal agencies, widely adopted across the DACH region.
Explore BSI IT-GrundschutzCIS Controls v8.1
Center for Internet Security
The CIS Critical Security Controls are a prioritized, prescriptive set of 18 Controls with 153 Safeguards organized into three Implementation Groups (IG1/IG2/IG3). Community-developed and free to use, CIS Controls provide actionable, ordered guidance — start with IG1's 56 essential safeguards to defend against 80%+ of common attacks.
Explore CIS ControlsAll Frameworks at a Glance
How all six frameworks compare across key dimensions.
| DORA | NIS2 | NIST CSF | ISO 27001 | BSI | CIS Controls | |
|---|---|---|---|---|---|---|
| Type | EU Regulation | EU Directive | Voluntary framework | International standard | National methodology | Community best practices |
| Approach | Regulatory (binding) | Directive (transposed) | Outcome-based | Risk-based ISMS | Prescriptive | Prioritised, prescriptive |
| Scope | Financial sector | 18 critical sectors | Any organisation | Any organisation | Any (mandatory DE fed.) | Any organisation |
| Structure | 5 Pillars, 64 Articles | 5 Pillars, 46 Articles | 6 Functions, 106 Subcat. | 93 Controls, 4 Themes | 10 Layers, ~100 Modules | 18 Controls, 153 Safeg. |
| Certification | Supervisory oversight | National supervision | No (self-assessment) | Yes (accredited audit) | Yes (BSI + ISO 27001) | No (CSAT self-assess.) |
| Cost | N/A (regulation) | N/A (directive) | Free | Paid (~$150) | Free (compendium) | Free |
| Penalties | Member-state defined | €10M / 2% turnover | None (voluntary) | None (cert. loss) | None (cert. loss) | None (voluntary) |