Regulatory compliance
Turn DORA & NCCS obligations into proven resilience.
Regulated financial and energy entities must test their digital operational resilience and rehearse their crisis response — on a defined cadence, with evidence. We run the exercises and testing that meet those obligations, and hand you the documentation to prove it.
Book a consultationOur work aligns to
- MITRE ATT&CK
- OWASP
- NIS2
- DORA
- EU NCCS
- GDPR
- ISO/IEC 27001
- CTEM
Why this matters
Compliance isn't a document. It's a test.
Both DORA and the EU Network Code on Cybersecurity move security from policy to proof: you have to actually test your systems and rehearse your people, on a schedule, and be able to show a regulator you did. That's precisely what we deliver — independent, evidence-first, and mapped to your obligations.
Digital Operational Resilience Act
DORA (Reg. (EU) 2022/2554) has applied since 17 January 2025. Chapter IV requires a digital operational resilience testing programme — and it does not accept theory in place of testing.
Who's in scope
Banks and credit institutions, insurers, investment firms, payment & e-money institutions, crypto-asset service providers, and other financial entities.
Reg. (EU) 2022/2554 · Chapter IV (Art. 24–27)
What it requires
- A digital operational resilience testing programme (Art. 24–25)
- Scenario-based testing among the required test types
- Advanced Threat-Led Penetration Testing (TLPT) at least every 3 years for entities identified as significant (Art. 26–27)
- Documented results, findings and remediation
EU Network Code on Cybersecurity
The NCCS (Delegated Reg. (EU) 2024/1366) sets common cybersecurity rules for cross-border electricity flows. It applies to high- and critical-impact entities, identified via the Electricity Cybersecurity Impact Index (ECII).
Who's in scope
Electricity undertakings, nominated electricity market operators (NEMOs) and organised markets classified as high- or critical-impact.
Delegated Reg. (EU) 2024/1366
What it requires
- Cyber risk management across the high-/critical-impact perimeter, at least every 3 years
- Crisis management and rehearsal of cyber crisis response
- Minimum cybersecurity controls, monitoring and reporting
How we help
Your obligation, mapped to what we do
Each requirement lines up with a concrete engagement — combine them into a testing calendar that keeps you continuously ready.
Audit-ready
Evidence your regulator will accept
Documented exercise
The full record: scenario, timeline, participants, decisions and gaps.
Technical findings
Every finding with severity, evidence and reproduction steps.
Prioritised remediation
An owner-assigned action plan — what to fix first and why.
Retest verification
Proof that the exposures are closed, ready for your auditor.
FAQ
DORA & NCCS testing — common questions
Does DORA require tabletop exercises?
DORA requires a digital operational resilience testing programme, and Chapter IV names scenario-based testing among the required test types. Facilitated tabletop exercises are the practical way most financial entities deliver that scenario-based testing and evidence their crisis readiness.
What is scenario-based testing under DORA?
Testing that walks your organisation through a realistic ICT incident to validate detection, response, communication and decision-making — exactly what a facilitated tabletop exercise provides.
Does DORA require penetration testing?
Yes. DORA's testing programme includes vulnerability assessments and, for entities identified as significant, advanced Threat-Led Penetration Testing (TLPT) at least every three years. Our penetration testing and continuous red teaming support these requirements.
Who is in scope for the EU Network Code on Cybersecurity (NCCS)?
High- and critical-impact electricity entities — electricity undertakings, NEMOs and organised markets — as classified by national authorities using the Electricity Cybersecurity Impact Index (ECII).
How often do we need to test?
Cadence depends on the regulation and your classification: DORA requires advanced testing at least every three years for significant entities, and NCCS requires cyber risk management at least every three years. We help you build a testing calendar that keeps you continuously ready.
Do you provide documentation for auditors and regulators?
Yes. Every engagement ends with documented evidence — the exercise record, technical findings, a prioritised remediation plan and retest verification — formatted for your board, auditors and regulator.
Are you independent?
Yes. We're vendor-neutral with no product to upsell. Our only interest is that your defences, and the evidence of them, hold up.
Get compliant — and stay ready.
Tell us your sector and we'll map the fastest path to meeting your DORA or NCCS obligations.
Book a consultation