Cybersecurity und Resilienz

← Cybersecurity & Resilience

DORA, KRITIS and other reference framework

Clearly distinguish between sets of rules and standards so that measures, responsibilities and evidence fit together.

DORA is relevant for the financial sector and ICT risks, BSIG/NIS2 for the cybersecurity of affected entities and KRITIS-Umbrella Act/CER for the physical and organisational resilience of critical assets. ISO/IEC 27001 is a certifiable ISMS, BSI IT-Grundschutz is a methodology and TISAX is a testing and exchange mechanism for the automotive industry. None of these sets of rules replaces the examination of another.

Relationship to services and technologies

Cybersecurity und Resilienz

Here we compare application areas and technical reference points of DORA, KRITIS and standards. The binding impact assessment is carried out by the responsible specialist and legal functions; general security services are below IT Security & Compliance described.

Background

When a company considers several requirements in parallel, terms are easily mixed up: a certificate is confused with a legal obligation or a technical control is understood as complete proof. This leads to unclear responsibilities, duplication of work and gaps in operations.

The aim is therefore initially to create a reliable map: which companies, services and supply relationships are being considered? Which set of rules or standards serves which purpose? And which decisions, controls and evidence can be sensibly managed together?

Technical context

IT-Security-Spezialistin überwacht Systeme in einem Rechenzentrum.

DORA (Regulation (EU) 2022/2554) is aimed at the financial companies mentioned in Article 2 as well as certain third-party ICT service providers. It has been applicable since January 17, 2025 and regulates, among other things, governance, ICT risk management, incident management, resilience testing and ICT third-party risks.

BSIG/NIS2 concerns the digital protection of affected institutions. KRITIS Umbrella Act/CER has supplemented this since March 17, 2026 for the physical and organisational resilience of critical systems. Both levels must be checked separately. Threshold values, criticality regulations and implementing regulations can change and must be checked against the current legal status.

NIS2 is an EU cybersecurity directive whose obligations are implemented nationally. It is not a security standard or a general certification. The practical implementation logic explained Implement NIS2 in practice.

ISO/IEC 27001:2022 is an international standard for information security management systems. BSI IT-Grundschutz With BSI standards and the compendium, offers a method and concrete building blocks for information security. TISAX is an audit information exchange mechanism used by the automotive industry. These frames of reference can structure requirements, but do not determine the legal applicability of DORA, NIS2 or KRITIS.

What companies need to clarify specifically

  • Which legal roles, companies, services and critical assets or financial services might be relevant.
  • Which regulatory obligations, contractual expectations and standards are considered separately by purpose and scope.
  • How risk, ICT third parties, identities, endpoints, data, incidents and recovery are managed organisationally.
  • Which evidence must be created in the company and who is responsible for it.
  • Where legal advice, supervision, auditors or certification bodies need to be involved.

From requirements to implementation

Abstrakte Illustration: Audit-Checkliste und Shield in Blau.
DORA

For what?: Financial sector and digital operational resilience
Practical classification: ICT risks, incidents, testing and ICT third parties
Possible evidence: Risk decisions, testing, operational and incident logs

BSIG/NIS2

For what?: Cybersecurity of affected facilities
Practical classification: Risk management, digital services, reporting and escalation channels
Possible evidence: Registration, control and verification documents

KRITIS Umbrella Act/CER

For what?: Critical assets and physical and organisational resilience
Practical classification: resilience of critical functions; separate from digital BSIG/NIS2 protection
Possible evidence: Planning, practice and evidence documents

ISO/IEC 27001

For what?: Certifiable ISMS
Practical classification: Security objectives, risk and improvement process
Possible evidence: Policy, risk register, internal reviews

BSI IT-Grundschutz

For what?: Methodology and protection
Practical classification: Determination of structural and protection needs, suitable building blocks
Possible evidence: Security concept, implementation status, audit trails

TISAX

For what?: Automotive industry
Practical classification: VDA-ISA based assessment and exchange mechanism
Possible evidence: Assessment information in the intended exchange process

Working with ADIUMENTO

ADIUMENTO supports the structured recording of existing security measures, responsibilities and technical dependencies. This can be followed by a prioritised technical roadmap. You can find information about this at IT Security & Compliance and IT Security & Compliance.

Typical Results

Cybersecurity und Resilienz
  • a delineated overview of systems, services, roles and controls in place;
  • a comparison of requirements, risks and packages of measures;
  • a prioritised roadmap for security and resilience measures;
  • Documentation structures for decisions, controls and operational evidence.

Limitations and dependencies

ADIUMENTO does not provide legal advice, does not determine any involvement and does not promise any certification, testament or conformity. The legal classification and independent checks are carried out by the responsible authorities. The specific scope of proof depends, among other things, on the legal situation, supervision, contract, sector and actual operation.

Further official sources

Orientation

Frequently asked questions

Is DORA a replacement for NIS2 or KRITIS?

No. DORA, NIS2 and KRITIS have different legal bases and areas of application. Overlaps in risk management or incident response can be planned together technically and organisationally; the legal assignment remains to be checked separately.

Is ISO 27001 sufficient for regulatory requirements?

An ISMS according to ISO/IEC 27001 can provide a useful structure. However, it does not replace verification of specific legal, regulatory or contractual obligations and is not an automatic proof of compliance.

Is TISAX a certification for every industry?

No. TISAX is aimed at the replacement needs of the automotive industry. Whether it is necessary or useful for a supply relationship depends on its specifications.

Next sensible step

Abstrakte Illustration: Threat Detection und Schutzschild in Blau.

First, organize relevant services, companies, supply relationships and existing security evidence in a defined assessment. This creates a resilient foundation for legal and compliance functions as well as a prioritised technical roadmap.