NIS2 checkContact

Compliance advisory

One assessment for NIS2, DORA, GDPR and the CRA

NIS2, DORA, the GDPR and the Cyber Resilience Act set partly comparable requirements for risk management, security and incident handling. The scope, the registers, the reporting deadlines and the legal responsibilities differ per regulation. We therefore first establish which rules apply to each legal entity, service and product. We then determine which controls can be set up jointly and which obligations have to be handled separately.

The four regimes

Who these regimes apply to

Each of the four regulations has its own scope. An organisation can fall under one of them, but can equally be dealing with several at once.

NIS2, essential and important entities

Eighteen sectors, with size deciding the category. An Annex I sector at 250 staff or more is usually an essential entity; Annex I at 50 to 249, and all of Annex II at 50 or more, is usually an important entity. Both carry the same ten measures under Article 21(2), and an essential entity faces proactive supervision, meaning the regulator may inspect with no incident on record. A far larger group is reached indirectly, because an organisation in scope is responsible for the security of its direct suppliers.

Sector and size tests follow national law, so a group operating in five member states is assessed five times.

In force in the Netherlands since 15 August 2026

DORA, financial entities and their ICT suppliers

Banks, insurers, investment firms, payment and electronic money institutions, crypto-asset service providers, trading venues and more than a dozen other categories, together with the ICT providers they depend on. DORA covers ICT risk management, incident classification and reporting, resilience testing, and contractual control over third parties. ICT providers designated as critical are overseen at European level.

Supervised in the Netherlands by De Nederlandsche Bank or the Autoriteit Financiële Markten, depending on the entity.

Applies since 17 January 2025

GDPR, anyone processing personal data

No size threshold and no sector list. If you hold personal data you need a lawful basis for each purpose, records of processing under Article 30, security appropriate to the risk under Article 32, a breach notification within 72 hours where the risk warrants it, an impact assessment where the processing is high risk, and a workable answer when someone asks what you hold about them.

The oldest of the four, and still the one where documentation most often describes something the organisation no longer does.

Applies since 25 May 2018

Cyber Resilience Act, products with digital elements

If you manufacture, import or distribute hardware or software placed on the European market, the CRA attaches to the product rather than to the organisation. Secure development, a vulnerability-handling process, a software bill of materials, security updates through a defined support period, technical documentation and CE marking. Actively exploited vulnerabilities and severe incidents have to be reported.

The obligations run across the lifecycle, so something you sell in 2027 still carries duties years after the sale.

Reporting duties from 11 September 2026, full application from 11 December 2027

An organisation can be in scope for all four at once. A medical device manufacturer with 300 staff and a bank among its customers is the ordinary case rather than the edge case.

The overlap

One assessment, four sets of obligations

Many technical and organisational controls appear in more than one regulation. We assess those controls once and link the available evidence to the relevant requirements.

Asset inventory. Access control and multi-factor authentication. Logging and monitoring. Patching on a cadence. Encryption. Backup with tested restores. Supplier assessment. An incident process with named roles and a working phone number. Every one sits in NIS2 Article 21(2), in the DORA ICT risk-management framework, in GDPR Article 32 and in the secure-development requirements of the CRA. Build the control once, evidence it once, and it answers in four places.

That holds for the controls. It does not hold for the paperwork, and treating the four as interchangeable surfaces eighteen months later during an audit.

Where they genuinely diverge

  • DORA wants a register of information. Every contractual arrangement with an ICT third party, in a prescribed format, at entity and group level, maintained and reported to the supervisor. Nothing else asks for it.
  • The CRA follows the product. Support periods, a software bill of materials, conformity assessment and CE marking attach to what you sell, and keep attaching for years after you have sold it. A management system does not produce any of that.
  • The GDPR asks a question the others do not. Not whether the data is protected, but whether you are entitled to hold it at all. A lawful basis, a purpose and a retention period are legal positions, and no control fixes a processing activity that should not be happening.
  • NIS2 puts the management body in the text. Article 20 makes approving and supervising the measures a board duty that cannot be delegated, evidenced per director rather than per organisation.

One assessment, one merged control set, four separate evidence packs. Obligations that do not overlap remain separate workstreams inside the same engagement.

The assessment

The assessment in four steps

The assessment produces four concrete outputs: a classification, a combined analysis, a delivery plan and a report for the board.

01

Classification per legal entity

We record which regulations apply to each entity, under which national law, and on the basis of which activities and criteria. For a group with entities in several countries, the outcome can differ per entity.

02

Combined analysis

We assess the organisation against one merged control set. In doing so we distinguish between a control that is genuinely missing and an existing control for which insufficient evidence is available. That distinction matters, because remediating a missing technical control usually takes more work than completing reporting or records.

03

Delivery plan

Every finding gets an owner, a priority, a cost estimate and its dependencies. The order is set by the risk and the practical consequences. Where a control needs additional technology, we include both the implementation and the operating cost.

04

Reporting for the board

The board receives a concise overview of the applicable obligations, the main risks, the open controls, the decisions required and the risks deliberately accepted. The pack is written so that decisions and supervision can be recorded in the board minutes.

A classification and first analysis take two to three weeks per country for a single entity. With several entities or regulations, more time may be needed. Delivering the controls falls outside that lead time. Its planning depends on the existing setup and on the nature of the missing controls.

The difference

We also carry out the plan

You can take the assessment as a separate engagement and have the delivery plan carried out by your own team or your current supplier. Think Smart Europe can also provide the next steps. We record in advance which parts we deliver and which work stays with your organisation or with other suppliers.

A report and a roadmap
  • A scoping study and a classification opinion
  • A gap analysis, usually against each framework separately
  • A policy set, a findings register and a prioritised list
  • A closing presentation and a handover pack

You now own a plan, and you still have to find someone to build it and someone to keep it running.

The Think Smart route
  • The same classification, gap analysis and roadmap, produced by our own CISO
  • Then we build what the roadmap found, identity, logging, patching, backup, supplier assessment
  • Then we operate it from our own European security operations centre
  • Then we produce the evidence a supervisor, an insurer or a customer asks for

One contract and one accountable party, from classification through to operation. If a control we recommended does not hold up, it is still ours.

Where our work stops

What we do not do

Think Smart Europe advises on cyber security, technical controls, processes and evidence. We do not give legal advice and we do not sign off legal opinions.

We can prepare policies, incident procedures, board papers and the technical or organisational parts of the documentation. Your organisation adopts those documents.

A lawyer, privacy counsel or data protection officer remains responsible for legal interpretations, formal conclusions on scope, lawful bases and contract wording. Whether an entity falls inside the Dutch Cyberbeveiligingswet, whether a processing activity has a valid lawful basis, and whether a clause carries the DORA contractual requirements are legal positions. Where you have no counsel, we say so at the start and work alongside the firm you appoint.

We record this division of work before the engagement begins.

What we ownThe control assessment, the gap analysis, the roadmap, the evidence, and the operation of anything we build.
What we draft, you approvePolicies, the ICT risk framework, incident procedures and the board pack. We write them; your organisation adopts them.
What we leave to your counselLegal opinions, formal scope determinations and sign-off on lawful basis. We say when you need a lawyer, early rather than late.

Frequently asked

Frequently asked questions

Do we need four separate assessments?

No. One control set covers most of NIS2, most of the DORA ICT risk requirements and GDPR Article 32, so a single assessment carries all three.

The DORA register of information, the CRA product obligations, and the lawful basis and retention work under the GDPR are scoped as separate workstreams inside the same engagement.

Does the assessment replace our current IT supplier?

Usually not. The assessment can be carried out on top of the existing service. Work your current supplier can do well can stay there.

It does have to be clear who is accountable for the missing parts and the evidence. Where one party runs the endpoints, another the network and a third the cloud, the evidence often belongs to nobody. Have that conversation before an auditor has it for you.

Can DORA apply if we are not a bank?

Yes. DORA also applies to other designated financial organisations, such as insurers and intermediaries, investment firms, payment and electronic money institutions, crypto-asset service providers and trading venues.

DORA can also reach ICT providers through their financial clients. If a financial entity asks you to sign clauses on subcontracting, exit plans, audit rights and incident notification, DORA has arrived at your door.

Is delivery from Bulgaria a transfer outside the EU?

No. Bulgaria is a member of the European Union. Work carried out there is not in itself a transfer to a third country.

Our engineering and monitoring teams work from Sofia, Varna and Stara Zagora under the same GDPR regime, contractual terms and management systems as the Amsterdam office. The precise data flows and any access by other suppliers are assessed per service.

Think Smart Europe is new. Why trust it with compliance work?

Because the engineering organisation behind it is not new. Think Smart Europe is a joint venture between Dutch founders and Think Smart in Bulgaria, registered since December 2019, which carries the ISO certifications, the vendor partnerships and the engineering depth.

The client-facing side is Dutch and named. You hold one contract, with one party answerable for it. Compliance work is delivered under the certified management systems of our parent organisation, and we will show you those certificates and their scope.

Can we take the assessment on its own?

Yes. You can then have the report and the delivery plan carried out by your own team or another supplier.

If the sensible outcome is that you take the delivery plan to the supplier you already have, we will say so.

When can we show a customer or an insurer something?

The classification and the first analysis are usually available within two to three weeks per country. With them you can answer questions factually and state which controls are still being delivered.

A full evidence pack follows once the required improvements have been completed.

Request your assessment

In the intake call we discuss your legal structure, your activities, your products and the countries you operate in. We then say which regulations are likely to be relevant, what the assessment covers and what it is expected to cost.

Cyber Incident