
← Implement regulatory requirements securely
Cybersecurity & Resilience
Structure cybersecurity requirements so that responsibility, protection measures and operations fit together.
NIS2, Cyber Resilience Act (CRA), DORA and KRITIS address different starting points: organisations, digital products, financial companies and critical infrastructure. Together they require resilient risk management. The sensible way to start is therefore not a collection of individual controls, but rather a clear impact assessment with legal advice as well as an implementable plan for governance, supply chain, incident response and evidence.
Relationship to services and technologies

This page classifies regulatory security requirements and evidence. For the selection and implementation of specific security services in the Microsoft stack, the entry leads to the solution IT Security & Compliance.
Background
In many companies, security measures grow historically: a new endpoint product, a process for suppliers, an emergency plan. It often remains unclear to management and IT which risk is being addressed, who decides and which evidence is available in the event of an emergency or to auditors. Regulatory requirements make these gaps visible, but do not replace prioritization.
Technical context

NIS2/BSIG concerns the cybersecurity of certain institutions in Germany. DORA has been applicable to the financial sector since January 17, 2025 and concerns digital operational resilience and ICT third-party risks. KRITIS Umbrella Act has also applied to the physical and organisational resilience of critical systems since March 17, 2026; it must be separated from digital protection according to BSIG/NIS2. The CRA On the other hand, it is aimed at manufacturers and other economic actors for products with digital elements.
For product obligations, the page leads Cyber Resilience Act further. The NIS2 implementation logic explained Implement NIS2 in practice; DORA, KRITIS and standards border DORA, KRITIS and Standards from.
What companies need to clarify specifically
- Which companies, services, products and supply relationships are relevant – technically and legally.
- Which decision-making and escalation paths apply to management, IT and information security.
- Which risks from identities, endpoints, cloud, data, vulnerabilities and service providers are prioritised.
- How incidents are recognized, evaluated, communicated and followed up.
- Which documents, tests and operating data clearly demonstrate the implementation.
Which case leads where?

Organisation or Important Service
Relevant in-depth topic: Implement NIS2 in practice
Financial sector or third-party ICT risks
Relevant in-depth topic: DORA, KRITIS and other reference framework
Critical attachment and physical/organisational resilience
Relevant in-depth topic: DORA, KRITIS and other reference framework
Digital product or software component
Relevant in-depth topic: Implement the Cyber Resilience Act in practice
From requirements to implementation
Risk management
Risk: unprioritized gaps
Organisational measure: Risk and measures process
Technical implementation: Security foundation for identities, devices and services
Possible evidence: Risk register, Roadmap
Supply chain
Risk: unknown third party risks
Organisational measure: Supplier assessment and responsibilities
Technical implementation: Access separation, monitoring, secure handovers
Possible evidence: Reviews, contracts, protocols
Incident response
Risk: delayed reaction
Organisational measure: Roles, reporting channels, exercises
Technical implementation: Detection, alerting, recovery
Possible evidence: Playbooks, practice and event logs
Evidence capability
Risk: unprovable controls
Organisational measure: Documentation cycle
Technical implementation: Configuration and operating data
Possible evidence: Approvals, Reports, Review Protocols
Working with ADIUMENTO

Within the confirmed service areas, ADIUMENTO supports the analysis of existing security controls, prioritised action planning and their technical operation. Further information is available from IT Security & Compliance and IT Security & Compliance.
Typical Results
- coordinated overview of risks and measures;
- Target image with responsibilities and implementation stages;
- documented technical and organisational control points;
- Incident response and evidence structure as a working basis.
Limitations and dependencies

ADIUMENTO does not provide legal advice and does not establish any binding impact or compliance. Legal advice, data protection officers, auditors or certification bodies are involved in their respective assessment. The scope and effectiveness of technical measures also depend on architecture, contractual partners and ongoing operations.
Orientation
Frequently asked questions
IS NIS2 the same as KRITIS?
No. There are overlaps in the protection of important services, but the legal basis, scope and specific obligations must be examined separately.
Where does a pragmatic start begin?
With a common picture of business risks, relevant services, responsibilities and the current security level. From this, measures can be prioritised in a comprehensible manner.
Next sensible step

Map out relevant services, risks and existing controls in an initial assessment. The topic overview leads from there Implement regulatory requirements securely to the appropriate in-depth topic.
