DORA & NIS2: The Strategic IT Roadmap
The C-level roadmap for mapping ICT risk, scope, third-party concentration, incident reporting and resilience testing to a 90/180/365-day operating plan, in the language each reviewer expects.
Stripe checkout. The personalised PDF is delivered only after payment confirmation. Digital content terms.
- 29
- pages
- 12
- chapters
- 3
- named sources
€99, VAT included. Refundable in full before the download link is generated, and non-refundable after it, except where the book materially fails to match this page. Refund Policy, section 03.

Evidence-led field guide
Reviewed 18 July 2026 · PDF edition
Michal Jatczak
Published edition
3 references
Technical guidance, not certification
The operating problem
Written for decisions that must survive review.
DORA and NIS2 move ICT resilience from a technical concern to a management-board responsibility. The question a regulator asks is no longer "do you have a policy" but "can you prove the control runs, who owns it, and how fast you recover".
This briefing maps the obligations to decisions an executive actually makes: scope, framework, incident reporting timelines, resilience testing, third-party concentration and an evidence system that survives an audit.
It is deliberately a roadmap, not a checklist. The output is a sequenced plan with owners and dates, in the language each reviewer expects.
Included working material
More than a manuscript.
The guide ties each topic to decisions, control mappings and evidence that an operator can retain.
12-chapter executive roadmap across DORA and NIS2.
Article-to-reality matrix mapping obligations to operational work.
Incident reporting timeline aid (DORA major-incident path; NIS2 24h / 72h / 1 month).
ICT third-party register and exit-strategy starter structure.
Board briefing and accountability pack outline.
90 / 180 / 365-day prioritised roadmap with a decision matrix.
Real page preview
The publication design and the operator detail.
Previewed chapter: The ICT Risk Management Framework
DORA wants one coherent framework, not a folder of disconnected controls.
The sample is rendered from the same structured source used by the publication engine. It is not a separate marketing mock-up.

Table of contents
Every chapter answers an operating question.
- DORA (Regulation (EU) 2022/2554)NIS2 (Directive (EU) 2022/2555)
The Regulatory Reality
DORA and NIS2 turn ICT resilience into management accountability, not a technical side project.
3 evidence outputs named - DORA Art. 2NIS2 Art. 2-3, Annexes I-II
Are You In Scope?
Scope is the first and most expensive mistake. Get it wrong and you either over-build or sit exposed.
3 evidence outputs named - DORA Art. 5-15ISO/IEC 27001:2022
The ICT Risk Management Framework
DORA wants one coherent framework, not a folder of disconnected controls.
3 evidence outputs named - DORA Art. 17-19NIS2 Art. 23
Incident Management and the Reporting Clock
When an incident hits, the timeline is unforgiving. The runbook has to exist before, not during.
3 evidence outputs named - DORA Art. 24-27NIS2 Art. 21(2)(f)
Proving It: Digital Operational Resilience Testing
Resilience you have not tested is a claim. DORA wants the claim proven on a schedule.
3 evidence outputs named - DORA Art. 28-30NIS2 Art. 21(2)(d)
Third-Party and Concentration Risk
Your resilience is only as strong as the provider you cannot see and cannot leave.
3 evidence outputs named - NIS2 Art. 21(2)(a)-(j)
The NIS2 Risk-Management Measures
NIS2 Article 21 is a baseline of ten measures. Treat it as the floor, evidenced, not aspired to.
3 evidence outputs named - NIS2 Art. 20DORA Art. 5
Governance and Board Accountability
NIS2 makes management personally answerable. The board cannot delegate the obligation, only the work.
3 evidence outputs named - DORA Art. 6, 13NIS2 Art. 21(2)(f)
Building the Evidence System
The programme is judged on what you can show, not what you intended. Engineer the evidence, not just the control.
3 evidence outputs named - DORA Art. 28-30NIS2 Art. 21(2)(d)
Build, Buy or Outsource
Most resilience gaps are sourcing decisions made by default. Decide them on purpose, with the regulator in the room.
3 evidence outputs named - NIS2 Art. 20DORA Art. 5
The Board Briefing Pack
The board cannot govern what it cannot see in ten minutes. Build the pack that makes oversight real and recorded.
3 evidence outputs named - DORA Art. 5-30NIS2 Art. 20-23
The 90 / 180 / 365-Day Roadmap
Sequence beats effort. Bank the high-impact, low-effort controls first, then build the structural ones.
3 evidence outputs named
Source basis
Open the authority behind the claim.
Legal text, standards and vendor guidance are linked directly. Access dates show when the edition last checked each source.
Regulation (EU) 2022/2554 (DORA)
Articles 5-30: ICT risk management, incident reporting, resilience testing, third-party risk.
Accessed 26 June 2026
Directive (EU) 2022/2555 (NIS2)
Articles 20-23 and Annexes I-II: governance, risk-management measures, reporting, in-scope sectors.
Accessed 26 June 2026
ISO/IEC 27001:2022
Information security control families referenced for cross-mapping. Primary legal text and national transposition must be confirmed with qualified counsel.
Accessed 26 June 2026
Scope before claims
Strategic and technical guidance only, not legal advice. DORA is a directly applicable EU Regulation; NIS2 is a Directive transposed into national law, so detail varies by Member State. Confirm scope and obligations with qualified counsel before relying on this roadmap for a regulatory submission.
Written and maintained by
Michal Jatczak
ITSailor is the trading brand. The legal publisher is Michal Jatczak, Malta VAT MT32760411. Each edition carries a review date, named sources and an explicit limitation.
About the publisherNeed the environment-specific version?
Turn the roadmap into a deliverable
Use the book to brief the board and sequence the work. Book the Architecture and Compliance Workshop when you want the register, exit strategies and evidence system built against your own entity.
Start a scoped conversationMicrosoft 365 Tenant Hardening for DORA and NIS2 Operations
A practitioner field guide for regulated EU operators running Microsoft 365. Maps DORA Article 9, NIS2 Article 21, NIST CSF 2.0 and the source-linked ITS-M365 control set to tenant controls, evidence and operating routines.
Review the companion edition