Table of Contents
Why Compliance Frameworks Matter – and Why They Confuse
Regulatory compliance in cybersecurity is not primarily about avoiding fines – though the fines are now significant enough to demand attention on their own. It is about providing structured assurance that an organization has implemented the security controls necessary to protect its systems, data, and operations against the threats it actually faces. The problem is that the regulatory landscape has become genuinely complex: different frameworks apply to different organizations, overlap in their technical requirements, and are enforced by different authorities on different timelines. The organizations that manage compliance effectively treat it as a continuous program – not a pre-audit sprint – and manage all applicable frameworks simultaneously through a single, integrated governance structure.
ISO 27001: The Global Standard for Information Security Management
ISO 27001 is the world’s most widely adopted information security management standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). As of 2024, more than 70,000 organizations worldwide hold ISO 27001 certification – a figure that has grown by double digits annually for the past decade, driven by enterprise customer requirements, insurance market pressure, and, increasingly, regulatory expectation.
What ISO 27001 Requires
ISO 27001 is a management system standard: it requires organizations to define the scope of their information security management system (ISMS), assess and treat information security risks, implement a set of security controls drawn from Annex A (which contains 93 controls across 4 themes in the 2022 revision), and continuously monitor, measure, audit, and improve the ISMS. The controls in Annex A cover organizational controls (policies, risk assessment, supplier relationships), people controls (background screening, security awareness), physical controls (perimeter security, secure areas), and technological controls (access management, encryption, vulnerability management).
Certification requires an independent third-party audit by an accredited certification body, conducted in two stages: a documentation review and a physical site assessment. Certification is valid for three years, with annual surveillance audits.
What ISO 27001 Is Not
ISO 27001 is a risk-based standard, not a prescriptive one. It does not specify exactly which technical controls to implement – it requires organizations to assess their risks and implement controls proportionate to those risks. This means that two organizations can both be ISO 27001 certified while implementing very different control sets. This flexibility is a feature for mature organizations; for organizations new to structured security management, it requires expert guidance to apply correctly.
NIS2: The EU’s Network and Information Security Directive
NIS2 – the revised Network and Information Security Directive – became effective across EU member states in October 2024, replacing the original NIS Directive that had applied since 2018. NIS2 represents a fundamental expansion of EU cybersecurity regulation: it applies to a significantly broader range of sectors and organizations, imposes explicit obligations on management bodies, and introduces enforcement powers that are materially more significant than those available under its predecessor.
Who NIS2 Applies To
NIS2 distinguishes between “essential entities” (sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, and public administration) and “important entities” (postal services, waste management, chemical manufacturing, food production, general manufacturing, digital providers, and research). Essential entities face stricter oversight and heavier penalties; important entities face lighter ex-post supervision. The directive also removes the size exception that protected many organizations under NIS1: operators above 50 employees or €10 million in annual turnover in covered sectors are now in scope in most member states.
What NIS2 Requires
NIS2 Article 21 requires in-scope entities to implement “appropriate and proportionate technical, operational and organisational measures” to manage cybersecurity risk. The directive specifies a minimum set of measures including: risk analysis and information system security policies; incident handling; business continuity and crisis management; supply chain security; network and information systems security including vulnerability management; access control; the use of cryptography; multi-factor authentication; and secure communications. Member state transposition laws add further national specifics – organizations with operations in multiple EU countries must track all relevant national implementations.
NIS2 Management Accountability
One of the most significant departures from the original NIS Directive is NIS2’s explicit focus on management accountability. Under Article 20, management bodies of essential and important entities are required to approve the cybersecurity risk management measures, oversee their implementation, and can be held personally liable for non-compliance. This provision makes senior security leadership – whether internal CISO or vCISO – a direct regulatory requirement, not a best practice.
NIS2 Penalties
For essential entities: up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities: up to €7 million or 1.4% of total worldwide annual turnover.
DORA: The Digital Operational Resilience Act for Financial Entities
The Digital Operational Resilience Act – DORA – became directly applicable across all EU member states on January 17, 2025. Unlike NIS2, which is a directive requiring national transposition, DORA is an EU regulation, meaning it applies uniformly without national variation. DORA applies specifically to financial entities and their critical third-party ICT service providers.
Who DORA Applies To
DORA’s scope covers: credit institutions; payment institutions; account information service providers; e-money institutions; investment firms; crypto-asset service providers; central securities depositories; central counterparties; trading venues; trade repositories; alternative investment fund managers; management companies; insurance and reinsurance undertakings; insurance intermediaries; pension funds; rating agencies; administrators of critical benchmarks; crowdfunding service providers; securitisation repositories; and – critically – third-party ICT service providers that are designated as critical by EU supervisory authorities.
What DORA Requires
DORA establishes five main pillars of digital operational resilience requirements:
- ICT risk management – financial entities must implement a comprehensive ICT risk management framework aligned to the principle of full ICT risk lifecycle management, including continuity of critical functions
- ICT-related incident management – structured classification, reporting, and root cause analysis of ICT incidents, including mandatory reporting to competent authorities within defined timelines
- Digital operational resilience testing – annual threat-led penetration testing (TLPT) for significant entities at minimum every three years, baseline resilience testing for all entities annually
- ICT third-party risk management – comprehensive due diligence, contractual requirements, and ongoing monitoring of all ICT third-party providers
- Information sharing – participation in intelligence-sharing arrangements on cyber threats
DORA’s Threat-Led Penetration Testing (TLPT) requirement – Article 26 – is the most technically demanding pen testing obligation in EU regulatory history. TLPT must be conducted by certified testers, against production systems, using current threat intelligence relevant to the entity’s specific threat landscape, and must cover people, processes, and technology.
DORA Penalties
DORA penalties are set at national level; the regulation empowers supervisory authorities to impose fines on financial entities and suspend or revoke authorizations. For critical third-party ICT providers, the European Supervisory Authorities can impose periodic penalty payments of up to 1% of average daily worldwide turnover, applied for up to six months.
GDPR: The EU’s Data Protection and Privacy Regulation
The General Data Protection Regulation has been directly applicable since May 25, 2018, and remains the most broadly recognized data protection law in the world. GDPR governs the processing of personal data of individuals in the European Economic Area – and its extraterritorial scope means it applies to any organization, anywhere in the world, that processes the personal data of EU residents in connection with offering goods or services to EU residents, or monitoring their behavior.
What GDPR Requires in a Security Context
GDPR Article 32 requires that controllers and processors implement “appropriate technical and organisational measures” to ensure a level of security appropriate to the risk of processing, including: pseudonymisation and encryption of personal data; the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems; the ability to restore availability and access to personal data following a breach; and a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures.
GDPR Article 33 requires notification of a personal data breach to the supervisory authority within 72 hours of discovery. Article 34 requires notification to affected data subjects where the breach is likely to result in high risk to their rights and freedoms.
GDPR Penalties
GDPR penalties operate in two tiers. Less serious infringements (e.g., violations of record-keeping, data protection officer obligations): up to €10 million or 2% of total worldwide annual turnover. More serious infringements (e.g., violations of basic processing principles, data subject rights, international transfer requirements): up to €20 million or 4% of total worldwide annual turnover.
Framework Comparison: ISO 27001 vs. NIS2 vs. DORA vs. GDPR
| Dimension | ISO 27001 | NIS2 | DORA | GDPR |
|---|---|---|---|---|
| Type | International standard (voluntary certification) | EU Directive (national law) | EU Regulation (directly applicable) | EU Regulation (directly applicable) |
| Who it applies to | Any organization seeking certification | Essential and important entities in 18 covered sectors | Financial entities and critical ICT third-party providers | Any organization processing EU residents’ personal data |
| Core focus | Information security management system | Cybersecurity risk management and incident reporting | Digital operational resilience for financial sector | Personal data protection and privacy rights |
| Key requirements | Risk-based ISMS, 93 Annex A controls, continuous improvement | Risk measures, incident handling, supply chain, management accountability | ICT risk framework, TLPT, third-party risk, incident reporting | Lawful processing, data subject rights, security measures, breach notification |
| Effective / Applicable from | Ongoing (2022 revision current) | October 2024 | January 17, 2025 | May 25, 2018 |
| Audit / enforcement | Third-party certification body audit | National competent authority supervision | EU supervisory authorities (EBA, ESMA, EIOPA) + national | National Data Protection Authorities |
| Maximum penalty | No regulatory fine (contractual / market consequence) | €10M or 2% global turnover (essential entities) | Up to 1% daily turnover for ICT providers (6 months) | €20M or 4% global turnover |
| Management liability | No explicit personal liability | Explicit – Article 20 management accountability | Implied through supervisory authority powers | DPO obligations; regulatory guidance on board accountability |
| Penetration testing | Implied under A.8.8 | Required under Article 21 measures | Mandatory TLPT under Article 26 | Required under Article 32 security measures |
| Overlap with others | Supports NIS2, DORA, GDPR compliance | ISO 27001 alignment accelerates compliance | ISO 27001 + NIS2 foundational; GDPR for personal data | Applies alongside all others where personal data is processed |
What Israeli Companies with EU Operations Need to Know
This section is directed at Israeli enterprises – a core segment of IPV Security’s market – that have EU customers, EU data processing operations, or EU-regulated counterparties.
The extraterritorial reality. All four frameworks can apply to Israeli companies without an EU legal entity. GDPR applies explicitly: if your company offers goods or services to EU residents, or monitors their behavior, you are a controller or processor under GDPR regardless of where you are incorporated. The NIS2 Directive, while structured around EU member state implementation, applies to entities providing digital services into the EU market – Israeli cloud providers, digital service providers, and managed service providers with EU customers are likely in scope in at least some member states. DORA applies to any financial entity operating in the EU financial market, including Israeli-headquartered fintech companies with EU regulatory authorization.
The INCD framework alignment. Israel’s National Cyber Directorate (INCD) has issued sector-specific cyber directives – particularly for critical infrastructure and financial services – that share structural similarities with NIS2 and DORA. Organizations already compliant with INCD requirements will find significant overlap with EU frameworks, particularly around risk management, incident reporting, and supply chain security. However, the INCD framework does not substitute for EU regulatory compliance and should be managed as a parallel obligation.
Practical implications for Israeli companies:
- If you process personal data of EU residents for any purpose – customer data, HR data for EU employees, analytics – you are subject to GDPR and must appoint an EU representative if you have no EU establishment.
- If you provide ICT services to EU financial entities, you may be designated as a critical third-party provider under DORA, triggering direct supervisory authority oversight.
- If you provide digital services (cloud, online marketplace, search engine) to EU customers above the NIS2 thresholds, you are subject to NIS2 in each member state where you operate.
- ISO 27001 certification, while voluntary, has become a de facto market requirement for Israeli technology companies seeking enterprise customers in EU markets — particularly in financial services, healthcare, and public sector procurement.
How to Build an Integrated Compliance Program
The worst approach to multi-framework compliance is to manage each framework independently – running a separate project for ISO 27001 certification, a separate engagement for NIS2 compliance, and a separate exercise for GDPR data mapping. This creates duplicated effort, inconsistent evidence, control gaps between frameworks, and a governance structure that collapses under audit pressure.
An integrated compliance program is built around four principles:
1. Common control framework as the backbone. ISO 27001’s Annex A controls serve as an effective common baseline: implementing them correctly provides substantial coverage of NIS2 Article 21 requirements, DORA’s ICT risk management obligations, and GDPR Article 32 security measures. The framework gaps that remain are specific and manageable.
2. Single evidence repository. Every control implementation produces evidence – policies, configurations, test results, training records, audit logs. A single, organized repository (not a folder on a SharePoint that three people have access to) makes it possible to answer any auditor’s question quickly, accurately, and without panic. CISOteria Cyber OS™ serves this function for IPV Security clients.
3. Continuous monitoring rather than annual snapshots. All four frameworks assume ongoing compliance, not point-in-time compliance. Organizations that treat compliance as an annual audit cycle have a compliance program that works for three weeks per year. A genuine program monitors control effectiveness continuously, tracks changes to systems and processes that could create gaps, and maintains the evidence base as a living record.
4. Management accountability structure. NIS2’s management accountability provisions (and DORA’s parallel requirements) have made board and C-suite engagement in security governance a legal obligation, not a cultural aspiration. The compliance program must include formal board reporting, documented management approvals of security policies, and clear accountability for remediation.
How IPV Security Approaches Compliance
IPV Security’s compliance practice is built around the recognition that organizations subject to NIS2, DORA, GDPR, and ISO 27001 simultaneously cannot manage those obligations in isolation. Every compliance engagement begins with a multi-framework gap assessment that identifies the organization’s current control posture against all applicable frameworks simultaneously, maps the overlaps (where one control satisfies multiple requirements), and identifies the genuine gaps – the controls that must be built or improved to achieve compliance across the full regulatory footprint.
The program is then delivered through CISOteria Cyber OS™, which tracks compliance status across all four frameworks in real time. Every control has an owner, a status, a target completion date, and a link to the evidence that demonstrates it. When a regulator or auditor asks for evidence that a specific requirement is met, the answer is available immediately – not assembled under pressure in the days before an audit. For Israeli companies navigating both INCD requirements and EU regulatory obligations, IPV Security brings direct experience managing both frameworks simultaneously, including cross-border incident reporting protocols and the jurisdictional nuances that arise when a single security incident triggers reporting obligations in multiple regulatory regimes.
Explore IPV Security’s Compliance as a Service →
Learn about the full vCISO program →
See the 18-Domain Cyber Risk Assessment →
Related Articles
- What Is a vCISO Program? Complete Guide 2026 →
- Outcome-Driven Penetration Testing: Complete Guide →
- The 18-Domain Cyber Risk Assessment →
Need help navigating compliance? ISO 27001, NIS2, DORA, and GDPR each demand a different response – but they share a common control foundation. IPV Security builds integrated compliance programs that satisfy all applicable frameworks without duplicating effort, tracked continuously through the CISOteria Cyber OS™ platform.
Frequently Asked Questions
What is the difference between ISO 27001 and NIS2?
ISO 27001 is an international voluntary standard that organizations can certify against to demonstrate they have implemented a structured information security management system. NIS2 is a mandatory EU directive – it is law, not a standard – that applies to operators in 18 covered sectors above defined size thresholds and requires specific security measures and incident reporting regardless of whether the organization has sought any certification. ISO 27001 certification is highly valuable for demonstrating NIS2 compliance because many of the standard’s controls align directly with NIS2 Article 21 requirements – but certification alone does not equal NIS2 compliance. The key differences are: NIS2 imposes explicit incident reporting timelines; NIS2 creates direct management liability; and NIS2 is enforced by national authorities with binding penalty powers.
Does DORA apply to our company if we are not a bank?
DORA applies to a broad range of financial entities – not just banks. Payment institutions, e-money institutions, investment firms, insurance undertakings, pension funds, crypto-asset service providers, crowdfunding platforms, and many others are all in scope. Critically, DORA also applies to ICT third-party providers – cloud providers, data center operators, software vendors, managed security service providers – that provide services to in-scope financial entities and are designated as “critical” by EU supervisory authorities. If your company provides technology services to EU financial entities, you may be subject to DORA’s third-party provider obligations even if you are not a financial entity yourself.
How does GDPR interact with the other three frameworks?
GDPR operates alongside ISO 27001, NIS2, and DORA rather than replacing any of them. Its scope is defined by the type of data processed (personal data of EU residents) rather than by sector. This means a financial entity subject to DORA and NIS2 is also subject to GDPR if it processes personal data – which virtually all financial entities do. The security measures required under GDPR Article 32 overlap significantly with ISO 27001 controls and NIS2/DORA security requirements, so an integrated compliance program avoids duplicating effort. Where GDPR is distinct is in its data subject rights framework (access, deletion, portability), its data protection by design requirements, its data processing agreement obligations, and its 72-hour breach notification timeline to supervisory authorities.
What is the fastest way to achieve ISO 27001 certification?
Realistic timelines for a first ISO 27001 certification run from six to eighteen months depending on organizational size, the maturity of existing security controls, and the scope of the ISMS. Organizations with no existing formal security program should expect twelve to eighteen months; organizations with mature security practices that have previously operated informally can often achieve certification in six to nine months with focused effort. The fastest path is not to compress the timeline – auditors can identify rushed implementations – but to start with a comprehensive gap assessment that accurately identifies what must be built, avoid scope creep, and use experienced guidance to navigate the documentation and control implementation efficiently. IPV Security has guided clients through ISO 27001 certification while simultaneously managing NIS2 readiness, avoiding the duplication of effort that makes sequential approaches unnecessarily slow.
Are we required to appoint a Data Protection Officer under GDPR?
GDPR Article 37 requires the appointment of a Data Protection Officer (DPO) in three scenarios: the controller or processor is a public authority or body; the core activities of the controller or processor consist of processing operations which, by virtue of their nature, scope, or purposes, require regular and systematic monitoring of data subjects on a large scale; or the core activities consist of processing on a large scale of special categories of data (health data, criminal conviction data, biometric data, etc.). Many mid-market companies fall outside the mandatory DPO threshold but should assess carefully – “large scale” is not defined in the regulation and has been interpreted broadly by data protection authorities. Organizations that are not required to appoint a DPO are still fully subject to all other GDPR obligations, including Article 32 security requirements.
How does CISOteria help manage compliance across multiple frameworks?
CISOteria Cyber OS™ provides a unified compliance tracking environment in which controls are mapped simultaneously against ISO 27001, NIS2, DORA, and GDPR. Rather than maintaining four separate compliance trackers, clients see a single dashboard showing their overall compliance posture, the controls that satisfy multiple frameworks simultaneously, and the specific gaps that must be addressed for each framework. The platform maintains a centralized evidence repository linked to each control, generates board-ready compliance status reports, and provides audit preparation support – giving the client the ability to demonstrate compliance to any regulator or auditor at any time without requiring a pre-audit scramble.