Advisory
Regulatory cyber resilience
EU resilience requirements reach across governance, suppliers, incidents, and continuity. We help organizations establish scope, close gaps, and connect regulatory work to the systems already in place.
The mandate
Make regulatory obligations operational.
Translate applicable cyber resilience obligations into accountable governance, tested response, supplier oversight, and resilient operations.
Discuss this workHow we help
- NIS2 applicability and gap assessment
- DORA readiness programs
- Incident response and reporting design
- ICT third-party risk management
- Business continuity and resilience exercises
What the work produces
- A clear view of applicable obligations
- Mapped owners, controls, and evidence
- A prioritized implementation program
Common questions
Clarify the mandate before delivery.
Are NIS2 and DORA interchangeable?
No. They have different legal scopes and duties. A shared risk and resilience program may support both, but the organization must assess each applicable regime and national implementation separately.
Does an ISO/IEC 27001 certificate establish regulatory compliance?
No. An ISMS can support governance, control operation, and evidence, but legal obligations, reporting duties, and covered entities still need their own analysis.
What should an incident exercise test?
Test who recognizes a potentially significant event, who makes the reportability decision, how evidence is gathered, how suppliers are contacted, and whether the service can recover within agreed priorities.
Primary references
Work with Normstone
Let’s build what stands up to scrutiny.
Tell us what you need to achieve. We’ll help define the right first step.