LOADING…
Platform  /  Datasheets  /  NIS2 & DORA
NIS2 & DORA ยท operational resilience

Beat the72-hour clock.

Supplier criticality, recovery objectives, dependency maps and incident playbooks live in-platform - so when the regulator clock starts, the evidence pack is already assembled.

All datasheets
72h incident window19 DORA RTS fields13 NIS2 sectors
72h

The DORA major-ICT-incident reporting window. Most resilience evidence is reconstructed from email threads during the incident - by the time the regulator deadline hits, the report is incomplete. In-platform, the pack auto-assembles inside the window.

The challenge

Resilience reporting is a fire drill.

When a major incident hits a critical supplier, the regulator clock starts and the evidence has to follow within hours - not the days it takes to reconstruct it from inboxes and shared drives. The two columns below set the scramble most teams know against the continuous evidence model that replaces it.

The problem
Resilience reporting is a fire drill.

Major incident at a supplier. The 72-hour clock starts. Risk, legal and ops teams scramble. Evidence reconstructed from inboxes. Regulator deadline missed. Penalty assessed.

The approach
Continuous resilience evidence.

Supplier criticality, recovery objectives, dependency maps and incident playbooks all live in-platform. When the clock starts, 90% of the evidence pack is already assembled.

Why E2ERisk

Why teams choose us.

NIS2, DORA and the UK NIS Regulations each demand the same things in different words: a complete register of critical ICT third parties, tested recovery objectives and evidence ready inside the reporting window. The capabilities below are how E2ERisk has those obligations met before an incident ever begins.

DORA-mapped registers

ICT third-party register with all 19 DORA RTS fields, pre-mapped.

NIS2 in-scope tracking

Sector obligations + critical-supplier flagging per Annex I + II.

72-hour evidence pack

Major-incident report auto-assembled within the regulator window.

Recovery objectives tested

RTO / RPO / MTPD per supplier, tested and timestamped with evidence.

Cross-border evidence

GDPR + DPA + NIS + DORA references on every record. No silos.

At a glance

The numbers that matter.

Resilience compliance comes down to a handful of figures that decide whether a report lands on time. The four below - the 72-hour DORA window, the 19 RTS register fields, the NIS2 sector count and a pack assembled ready for the regulator - are the ones this module is built around.

72h
incident window
19
DORA RTS fields
13
NIS2 sectors
100%
regulator-ready
How it works

Five steps, evidence underneath.

Regulator-ready resilience is a continuous loop, not a report written under pressure. The five stages below - scope, register, test, detect and report - run in-platform so that when an incident classification starts the clock, the evidence pack has already been building underneath every prior step.

01
Scope
Identify ICT third parties + critical suppliers
02
Register
Capture RTS-mandated fields, pre-validated
03
Test
Recovery-objective testing + evidence
04
Detect
Incident classification: the 72h clock starts
05
Report
Auto-assembled regulator pack within deadline
Framework alignment

Mapped at the control level.

Resilience evidence only counts if it ties back to the regime holding you to account. Each record in the platform carries its references, so the same work satisfies DORA, NIS2, the UK NIS Regulations, ISO 22301, NCSC CAF v4.0 and BS 65000 at once - the six regimes set out below.

DORADigital Operational Resilience Act - Articles 5-30 + all 13 RTS
NIS2Annex I + II sectors + critical-supplier obligations
UK NIS RegulationsOperators of essential services + relevant DSPs
ISO 22301Business continuity + RTO / RPO / MTPD
NCSC CAF v4.0Resilience objective D1 + D2 - response + recovery
BS 65000Organisational resilience - principles + practice
Deployment

Run it your way.

Resilience obligations do not stop when an incident closes - they run before, during and after it. The three modes below cover the full arc: operational monitoring and drill cadence day to day, the 72-hour incident pack when the clock starts, and lessons-learned with remediation tracking once the regulator follow-up lands.

Operational

Continuous monitoring + drill cadence + auto-evidence.

Incident

72-hour incident pack + escalation runbooks + regulator templates.

Post-incident

Lessons-learned + remediation tracking + regulator follow-up.

Next step

Book a DORA scope review.

We’ll map your top-five ICT third parties against DORA RTS requirements.

All datasheets