Comply and evidence

NIS2 and DORA. From gap assessment to auditable controls.

The regulations are specific about what technical controls are required. Most organisations know the deadline is approaching. Fewer know exactly where they stand against the requirements or what they need to do first. Edge7 Networks assesses your current posture, implements the controls the regulations require, produces the documentation, and provides the ongoing managed services that keep the evidence current.

NIS2 and DORA compliance programme stages 01 Scope and assess Confirm NIS2/DORA applicability and conduct gap analysis Entity classification Controls gap map Prioritised roadmap 02 Implement controls Technical and governance controls aligned to the requirements Access control Incident mgmt Monitoring Supply chain risk 03 Document and evidence Policies, procedures, and audit evidence produced from operations ISMS policies Audit log exports Incident run-books 04 Ongoing compliance posture Managed controls keep evidence current between audits Monthly reporting IR testing annual Regulator ready From gap assessment to auditable controls.
The problem

The regulations are specific. Most organisations are not ready.

NIS2 is not a vague obligation to take security seriously. It requires specific technical measures: network segmentation, access control, multi-factor authentication, patch management, incident detection, and the ability to respond to and report significant incidents within defined timeframes. Many organisations reviewing the text for the first time find that their current controls address some requirements partially and others not at all.

DORA goes further for financial services. ICT risk management, digital operational resilience testing, third-party risk management, and register of information obligations all require demonstrable capability, not just policy documentation. For ICT third-party service providers that are in scope as critical providers, the obligations extend to contractual terms, subcontracting arrangements, and resilience testing programmes.

The gap between policy and practice is where regulatory exposure lives. Organisations that have produced documentation without implementing the underlying controls will not withstand scrutiny. Regulators under NIS2 have supervisory powers to inspect, audit, and issue binding instructions. The penalties for essential entities are significant. Senior management carry personal accountability for decisions made after being informed of non-compliance.

What changes

From uncertain to demonstrably compliant.

You know exactly where you stand.

The programme starts with a structured gap assessment against NIS2 Article 21 requirements and, where applicable, DORA ICT risk management obligations. You receive a clear view of which requirements are met, which are partially met, and which have no current control. The roadmap prioritises by risk and regulatory urgency.

The technical controls required by the regulation are operational.

NIS2 requires access control, network security, encryption, vulnerability management, and supply chain security among other measures. Edge7 Networks implements and manages these controls as part of the compliance programme, not as a separate engagement. The controls are real and running, not described in a policy that nobody reviews.

You have an incident response capability that meets reporting requirements.

NIS2 requires early warning notification within 24 hours and a detailed report within 72 hours of a significant incident. Edge7 Networks provides the detection capability that identifies incidents, the response capability that investigates and contains them, and the documentation that supports the reporting obligation to your national competent authority.

Your documentation reflects what is actually happening.

Policies, procedures, risk assessments, and audit logs are produced as outputs of the managed service, not compiled from scratch before an audit. Monthly reporting provides a running record of your compliance posture. When regulators or auditors ask for evidence, it exists.

Board and senior management have the visibility they are accountable for.

NIS2 places personal accountability on senior management for decisions made in full knowledge of non-compliance. Edge7 Networks provides the reporting and governance framework that ensures the right people have the right information about the organisation's security posture and compliance status.

What is included

Advisory, technical controls, and ongoing operations.

Compliance is not achieved through documentation alone. The technical controls are what the regulations actually require. The documentation evidences them. Both are covered in the programme.

NIS2 and DORA Gap Assessment

Structured assessment against NIS2 Article 21 requirements and DORA ICT risk management obligations. Scoping, classification, gap analysis, and prioritised remediation roadmap. The starting point for any compliance programme.

More on NIS2 and DORA consulting
vCISO

Senior security leadership to govern the compliance programme, advise the board, and maintain the strategic security posture that NIS2 and DORA require at leadership level. Available on a fractional basis without the cost of a full-time hire.

More on vCISO
SOC and SIEM

24/7 security monitoring satisfies the NIS2 requirement for detection capability and supports the incident reporting obligations. Security events are detected, investigated, and documented in a way that supports regulatory reporting.

More on SOC/SIEM
Identity and Access Control

MFA, conditional access, SSO, and PAM address the NIS2 and DORA requirements for access control and user authentication. Privileged access is auditable. Access is managed on the principle of least privilege.

More on identity and PAM
Incident Response

A tested IR capability that supports the NIS2 incident reporting obligation. Incident classification, investigation, containment, and regulatory notification documentation. IR plans are tested and updated annually.

More on incident response
Cyber Essentials

Cyber Essentials certification addresses the foundational technical controls that NIS2 also requires: boundary firewalls, secure configuration, access control, malware protection, and patch management. Certification produces independently verified evidence.

More on Cyber Essentials
How an engagement works

From compliance uncertainty to regulated and evidenced.

01

NIS2 readiness assessment

Edge7 Networks scopes your obligations under NIS2 and DORA, assesses your current controls against each requirement, and produces a gap analysis with a prioritised remediation roadmap. You leave with a clear picture of where you stand and what needs to change first.

02

Control design and implementation

The technical controls required by the regulation are implemented in phases. Access controls, network security, monitoring, incident management, and any additional gaps identified in the assessment are addressed. Existing controls that already satisfy requirements are documented and evidenced.

03

Documentation and governance

Policies, procedures, risk assessments, and governance frameworks are produced and aligned to the regulatory requirements. The vCISO function provides the senior leadership visibility and board reporting that NIS2 requires at management level.

04

Ongoing managed compliance posture

Monthly reporting keeps your compliance posture current. Incident response plans are tested annually. Changes to the regulatory landscape or your infrastructure are reflected in the documentation and controls. Audit evidence is maintained as a natural output of operations.

Who this is for

For organisations where compliance is a board-level obligation, not just an IT task.

Board / Senior Management

NIS2 makes you personally accountable. You need to know the organisation is compliant.

Edge7 Networks provides the governance framework, board reporting, and compliance evidence that demonstrates you have exercised due diligence on your NIS2 and DORA obligations.

CISO / Head of Compliance

You need to deliver a compliance programme against a deadline, with limited internal resource.

Edge7 Networks provides the assessment, the engineering, and the ongoing managed controls. You lead the programme. We execute it.

IT Director / IT Manager

You have been handed a NIS2 requirement and a deadline. You need to know what to do and in what order.

The readiness assessment gives you a clear view of where you stand. The programme gives you a defined path to compliance with the technical controls managed by Edge7 Networks.

Trusted by organisations across Ireland, the UK, and Europe

Organisations that trust Edge7 Networks.

Rehab Group
Medite Smartply
Mills & Reeve
Scot JCB
Moore Kingston Smith
Mullinahome Co-op
Commissioners of Irish Lights
Guinness Enterprise Centre
Yaskawa
Learn more

Resources and tools.

Guides and assessments to help you understand your NIS2 and DORA obligations and plan a compliance programme.

Assessments and tools — coming soon

We are building a NIS2 readiness self-assessment tool and a DORA ICT risk maturity assessment. Available here when released.

Coming soon
Why Edge7 Networks

Compliance built on controls that actually run.

We hold the standards we advise you to achieve.

Edge7 Networks is ISO 27001:2022 and ISO 9001:2015 certified and Cyber Essentials certified. We went through the same process we guide clients through. We know where the evidence requirements are, what auditors actually check, and which controls require operational rigour rather than just documentation.

Technical controls, not just advisory.

Many compliance consultants produce policies and gap reports. Edge7 Networks also implements and manages the underlying controls. The firewall policy, the SOC monitoring, the access controls, and the incident response capability are managed by the same team advising on compliance. There is no gap between the recommendation and the execution.

Evidence maintained between audits.

Compliance is not a project you complete. The managed service produces monthly reports, maintains audit logs, reviews access rights, tests incident response plans, and keeps the documentation current. When regulators or auditors ask for evidence of your ongoing compliance posture, it exists.

Talk to us

Start with a NIS2 readiness assessment. Know where you actually stand.

A structured gap assessment against NIS2 Article 21 requirements gives you a clear view of your current posture, what is missing, and what to address first. Two to four weeks. No commitment to a full programme required.