
DORA, KRITIS and other reference framework
Clearly distinguish between sets of rules and standards so that measures, responsibilities and evidence fit together.
DORA is relevant for the financial sector and ICT risks, BSIG/NIS2 for the cybersecurity of affected entities and KRITIS-Umbrella Act/CER for the physical and organisational resilience of critical assets. ISO/IEC 27001 is a certifiable ISMS, BSI IT-Grundschutz is a methodology and TISAX is a testing and exchange mechanism for the automotive industry. None of these sets of rules replaces the examination of another.
Relationship to services and technologies

Here we compare application areas and technical reference points of DORA, KRITIS and standards. The binding impact assessment is carried out by the responsible specialist and legal functions; general security services are below IT Security & Compliance described.
Background
When a company considers several requirements in parallel, terms are easily mixed up: a certificate is confused with a legal obligation or a technical control is understood as complete proof. This leads to unclear responsibilities, duplication of work and gaps in operations.
The aim is therefore initially to create a reliable map: which companies, services and supply relationships are being considered? Which set of rules or standards serves which purpose? And which decisions, controls and evidence can be sensibly managed together?
Technical context

DORA (Regulation (EU) 2022/2554) is aimed at the financial companies mentioned in Article 2 as well as certain third-party ICT service providers. It has been applicable since January 17, 2025 and regulates, among other things, governance, ICT risk management, incident management, resilience testing and ICT third-party risks.
BSIG/NIS2 concerns the digital protection of affected institutions. KRITIS Umbrella Act/CER has supplemented this since March 17, 2026 for the physical and organisational resilience of critical systems. Both levels must be checked separately. Threshold values, criticality regulations and implementing regulations can change and must be checked against the current legal status.
NIS2 is an EU cybersecurity directive whose obligations are implemented nationally. It is not a security standard or a general certification. The practical implementation logic explained Implement NIS2 in practice.
ISO/IEC 27001:2022 is an international standard for information security management systems. BSI IT-Grundschutz With BSI standards and the compendium, offers a method and concrete building blocks for information security. TISAX is an audit information exchange mechanism used by the automotive industry. These frames of reference can structure requirements, but do not determine the legal applicability of DORA, NIS2 or KRITIS.
What companies need to clarify specifically
- Which legal roles, companies, services and critical assets or financial services might be relevant.
- Which regulatory obligations, contractual expectations and standards are considered separately by purpose and scope.
- How risk, ICT third parties, identities, endpoints, data, incidents and recovery are managed organisationally.
- Which evidence must be created in the company and who is responsible for it.
- Where legal advice, supervision, auditors or certification bodies need to be involved.
From requirements to implementation

DORA
For what?: Financial sector and digital operational resilience
Practical classification: ICT risks, incidents, testing and ICT third parties
Possible evidence: Risk decisions, testing, operational and incident logs
BSIG/NIS2
For what?: Cybersecurity of affected facilities
Practical classification: Risk management, digital services, reporting and escalation channels
Possible evidence: Registration, control and verification documents
KRITIS Umbrella Act/CER
For what?: Critical assets and physical and organisational resilience
Practical classification: resilience of critical functions; separate from digital BSIG/NIS2 protection
Possible evidence: Planning, practice and evidence documents
ISO/IEC 27001
For what?: Certifiable ISMS
Practical classification: Security objectives, risk and improvement process
Possible evidence: Policy, risk register, internal reviews
BSI IT-Grundschutz
For what?: Methodology and protection
Practical classification: Determination of structural and protection needs, suitable building blocks
Possible evidence: Security concept, implementation status, audit trails
TISAX
For what?: Automotive industry
Practical classification: VDA-ISA based assessment and exchange mechanism
Possible evidence: Assessment information in the intended exchange process
Working with ADIUMENTO
ADIUMENTO supports the structured recording of existing security measures, responsibilities and technical dependencies. This can be followed by a prioritised technical roadmap. You can find information about this at IT Security & Compliance and IT Security & Compliance.
Typical Results

- a delineated overview of systems, services, roles and controls in place;
- a comparison of requirements, risks and packages of measures;
- a prioritised roadmap for security and resilience measures;
- Documentation structures for decisions, controls and operational evidence.
Limitations and dependencies
ADIUMENTO does not provide legal advice, does not determine any involvement and does not promise any certification, testament or conformity. The legal classification and independent checks are carried out by the responsible authorities. The specific scope of proof depends, among other things, on the legal situation, supervision, contract, sector and actual operation.
Further official sources

- Regulation (EU) 2022/2554 (DORA) – EUR-Lex
- BSI: Critical Infrastructures – BSI
- BSI: IT-Grundschutz – BSI
- ISO/IEC 27001:2022 – ISO
- TISAX® – ENX Association
Orientation
Frequently asked questions
Is DORA a replacement for NIS2 or KRITIS?
No. DORA, NIS2 and KRITIS have different legal bases and areas of application. Overlaps in risk management or incident response can be planned together technically and organisationally; the legal assignment remains to be checked separately.
Is ISO 27001 sufficient for regulatory requirements?
An ISMS according to ISO/IEC 27001 can provide a useful structure. However, it does not replace verification of specific legal, regulatory or contractual obligations and is not an automatic proof of compliance.
Is TISAX a certification for every industry?
No. TISAX is aimed at the replacement needs of the automotive industry. Whether it is necessary or useful for a supply relationship depends on its specifications.
Next sensible step

First, organize relevant services, companies, supply relationships and existing security evidence in a defined assessment. This creates a resilient foundation for legal and compliance functions as well as a prioritised technical roadmap.
