Skip to content
Incredibilis Consulting

Regulatory compliance

Turn DORA & NCCS obligations into proven resilience.

Regulated financial and energy entities must test their digital operational resilience and rehearse their crisis response — on a defined cadence, with evidence. We run the exercises and testing that meet those obligations, and hand you the documentation to prove it.

Book a consultation

Our work aligns to

  • MITRE ATT&CK
  • OWASP
  • NIS2
  • DORA
  • EU NCCS
  • GDPR
  • ISO/IEC 27001
  • CTEM

Why this matters

Compliance isn't a document. It's a test.

Both DORA and the EU Network Code on Cybersecurity move security from policy to proof: you have to actually test your systems and rehearse your people, on a schedule, and be able to show a regulator you did. That's precisely what we deliver — independent, evidence-first, and mapped to your obligations.

DORAFor financial entities

Digital Operational Resilience Act

DORA (Reg. (EU) 2022/2554) has applied since 17 January 2025. Chapter IV requires a digital operational resilience testing programme — and it does not accept theory in place of testing.

Who's in scope

Banks and credit institutions, insurers, investment firms, payment & e-money institutions, crypto-asset service providers, and other financial entities.

Reg. (EU) 2022/2554 · Chapter IV (Art. 24–27)

What it requires

  • A digital operational resilience testing programme (Art. 24–25)
  • Scenario-based testing among the required test types
  • Advanced Threat-Led Penetration Testing (TLPT) at least every 3 years for entities identified as significant (Art. 26–27)
  • Documented results, findings and remediation
NCCSFor the electricity & energy sector

EU Network Code on Cybersecurity

The NCCS (Delegated Reg. (EU) 2024/1366) sets common cybersecurity rules for cross-border electricity flows. It applies to high- and critical-impact entities, identified via the Electricity Cybersecurity Impact Index (ECII).

Who's in scope

Electricity undertakings, nominated electricity market operators (NEMOs) and organised markets classified as high- or critical-impact.

Delegated Reg. (EU) 2024/1366

What it requires

  • Cyber risk management across the high-/critical-impact perimeter, at least every 3 years
  • Crisis management and rehearsal of cyber crisis response
  • Minimum cybersecurity controls, monitoring and reporting

How we help

Your obligation, mapped to what we do

Each requirement lines up with a concrete engagement — combine them into a testing calendar that keeps you continuously ready.

Audit-ready

Evidence your regulator will accept

Documented exercise

The full record: scenario, timeline, participants, decisions and gaps.

Technical findings

Every finding with severity, evidence and reproduction steps.

Prioritised remediation

An owner-assigned action plan — what to fix first and why.

Retest verification

Proof that the exposures are closed, ready for your auditor.

FAQ

DORA & NCCS testing — common questions

Does DORA require tabletop exercises?

DORA requires a digital operational resilience testing programme, and Chapter IV names scenario-based testing among the required test types. Facilitated tabletop exercises are the practical way most financial entities deliver that scenario-based testing and evidence their crisis readiness.

What is scenario-based testing under DORA?

Testing that walks your organisation through a realistic ICT incident to validate detection, response, communication and decision-making — exactly what a facilitated tabletop exercise provides.

Does DORA require penetration testing?

Yes. DORA's testing programme includes vulnerability assessments and, for entities identified as significant, advanced Threat-Led Penetration Testing (TLPT) at least every three years. Our penetration testing and continuous red teaming support these requirements.

Who is in scope for the EU Network Code on Cybersecurity (NCCS)?

High- and critical-impact electricity entities — electricity undertakings, NEMOs and organised markets — as classified by national authorities using the Electricity Cybersecurity Impact Index (ECII).

How often do we need to test?

Cadence depends on the regulation and your classification: DORA requires advanced testing at least every three years for significant entities, and NCCS requires cyber risk management at least every three years. We help you build a testing calendar that keeps you continuously ready.

Do you provide documentation for auditors and regulators?

Yes. Every engagement ends with documented evidence — the exercise record, technical findings, a prioritised remediation plan and retest verification — formatted for your board, auditors and regulator.

Are you independent?

Yes. We're vendor-neutral with no product to upsell. Our only interest is that your defences, and the evidence of them, hold up.

Get compliant — and stay ready.

Tell us your sector and we'll map the fastest path to meeting your DORA or NCCS obligations.

Book a consultation