Skip to content
Back to the Handbook
Executive Briefing - 2026 EditionPublished edition

DORA & NIS2: The Strategic IT Roadmap

The C-level roadmap for mapping ICT risk, scope, third-party concentration, incident reporting and resilience testing to a 90/180/365-day operating plan, in the language each reviewer expects.

Preview a real page

Stripe checkout. The personalised PDF is delivered only after payment confirmation. Digital content terms.

29
pages
12
chapters
3
named sources

99, VAT included. Refundable in full before the download link is generated, and non-refundable after it, except where the book materially fails to match this page. Refund Policy, section 03.

DORA & NIS2: The Strategic IT Roadmap cover

Evidence-led field guide

Reviewed 18 July 2026 · PDF edition

Named publisher

Michal Jatczak

Visible status

Published edition

Source register

3 references

Scope stated

Technical guidance, not certification

The operating problem

Written for decisions that must survive review.

DORA and NIS2 move ICT resilience from a technical concern to a management-board responsibility. The question a regulator asks is no longer "do you have a policy" but "can you prove the control runs, who owns it, and how fast you recover".

This briefing maps the obligations to decisions an executive actually makes: scope, framework, incident reporting timelines, resilience testing, third-party concentration and an evidence system that survives an audit.

It is deliberately a roadmap, not a checklist. The output is a sequenced plan with owners and dates, in the language each reviewer expects.

Included working material

More than a manuscript.

The guide ties each topic to decisions, control mappings and evidence that an operator can retain.

  • 12-chapter executive roadmap across DORA and NIS2.

  • Article-to-reality matrix mapping obligations to operational work.

  • Incident reporting timeline aid (DORA major-incident path; NIS2 24h / 72h / 1 month).

  • ICT third-party register and exit-strategy starter structure.

  • Board briefing and accountability pack outline.

  • 90 / 180 / 365-day prioritised roadmap with a decision matrix.

Real page preview

The publication design and the operator detail.

Previewed chapter: The ICT Risk Management Framework

DORA wants one coherent framework, not a folder of disconnected controls.

DORA Art. 5-15ISO/IEC 27001:2022NIS2 Art. 21(2)(a)

The sample is rendered from the same structured source used by the publication engine. It is not a separate marketing mock-up.

Sample page from DORA & NIS2: The Strategic IT Roadmap

Table of contents

Every chapter answers an operating question.

  1. DORA (Regulation (EU) 2022/2554)NIS2 (Directive (EU) 2022/2555)

    The Regulatory Reality

    DORA and NIS2 turn ICT resilience into management accountability, not a technical side project.

    3 evidence outputs named
  2. DORA Art. 2NIS2 Art. 2-3, Annexes I-II

    Are You In Scope?

    Scope is the first and most expensive mistake. Get it wrong and you either over-build or sit exposed.

    3 evidence outputs named
  3. DORA Art. 5-15ISO/IEC 27001:2022

    The ICT Risk Management Framework

    DORA wants one coherent framework, not a folder of disconnected controls.

    3 evidence outputs named
  4. DORA Art. 17-19NIS2 Art. 23

    Incident Management and the Reporting Clock

    When an incident hits, the timeline is unforgiving. The runbook has to exist before, not during.

    3 evidence outputs named
  5. DORA Art. 24-27NIS2 Art. 21(2)(f)

    Proving It: Digital Operational Resilience Testing

    Resilience you have not tested is a claim. DORA wants the claim proven on a schedule.

    3 evidence outputs named
  6. DORA Art. 28-30NIS2 Art. 21(2)(d)

    Third-Party and Concentration Risk

    Your resilience is only as strong as the provider you cannot see and cannot leave.

    3 evidence outputs named
  7. NIS2 Art. 21(2)(a)-(j)

    The NIS2 Risk-Management Measures

    NIS2 Article 21 is a baseline of ten measures. Treat it as the floor, evidenced, not aspired to.

    3 evidence outputs named
  8. NIS2 Art. 20DORA Art. 5

    Governance and Board Accountability

    NIS2 makes management personally answerable. The board cannot delegate the obligation, only the work.

    3 evidence outputs named
  9. DORA Art. 6, 13NIS2 Art. 21(2)(f)

    Building the Evidence System

    The programme is judged on what you can show, not what you intended. Engineer the evidence, not just the control.

    3 evidence outputs named
  10. DORA Art. 28-30NIS2 Art. 21(2)(d)

    Build, Buy or Outsource

    Most resilience gaps are sourcing decisions made by default. Decide them on purpose, with the regulator in the room.

    3 evidence outputs named
  11. NIS2 Art. 20DORA Art. 5

    The Board Briefing Pack

    The board cannot govern what it cannot see in ten minutes. Build the pack that makes oversight real and recorded.

    3 evidence outputs named
  12. DORA Art. 5-30NIS2 Art. 20-23

    The 90 / 180 / 365-Day Roadmap

    Sequence beats effort. Bank the high-impact, low-effort controls first, then build the structural ones.

    3 evidence outputs named

Scope before claims

Strategic and technical guidance only, not legal advice. DORA is a directly applicable EU Regulation; NIS2 is a Directive transposed into national law, so detail varies by Member State. Confirm scope and obligations with qualified counsel before relying on this roadmap for a regulatory submission.

Written and maintained by

Michal Jatczak

ITSailor is the trading brand. The legal publisher is Michal Jatczak, Malta VAT MT32760411. Each edition carries a review date, named sources and an explicit limitation.

About the publisher

Need the environment-specific version?

Turn the roadmap into a deliverable

Use the book to brief the board and sequence the work. Book the Architecture and Compliance Workshop when you want the register, exit strategies and evidence system built against your own entity.

Start a scoped conversation
The companion field guide

Microsoft 365 Tenant Hardening for DORA and NIS2 Operations

A practitioner field guide for regulated EU operators running Microsoft 365. Maps DORA Article 9, NIS2 Article 21, NIST CSF 2.0 and the source-linked ITS-M365 control set to tenant controls, evidence and operating routines.

Review the companion edition