Compliance Knowledge Base
European cybersecurity regulation assigns duties by entity, sector, and service. Use this collection to see whether NIS2 or DORA applies to your organization, what each framework requires, how their incident-reporting clocks run, and what evidence supervisors and auditors expect.
NIS2 essentials
-
NIS2 Requirements Guide: What EU Organizations Need to Do
Management duties, Article 21 controls, incident reporting, evidence, and national rules in one guide.
Read the guide → -
NIS2 Essential vs Important Entities: How Classification Works
How sector and size place an organization in scope, and what the classification changes.
Read the guide → -
NIS2 Article 21 Measures: Full Breakdown
The ten minimum security areas and how to evidence each one.
Read the guide →
NIS2 in operation
-
NIS2 Incident Reporting Timeline: 24 Hours, 72 Hours, and Onward
The reporting sequence, what each notification contains, and who receives it.
Read the guide → -
NIS2 Management Responsibility and Liability Under Article 20
What management must approve, oversee, and train for, and where liability sits.
Read the guide → -
NIS2 Supplier Risk Assessment: How to Assess Third-Party Risk
A working supplier-risk process: scoping, assessment, contracts, and evidence.
Read the guide →
DORA essentials
-
What Is DORA? Digital Operational Resilience Act Explained
Who DORA applies to, what it requires, and how its main obligations fit together.
Read the guide → -
DORA vs NIS2: Obligations for Dual-Scope Entities
When DORA replaces equivalent NIS2 duties, where NIS2 still matters, and how to map both.
Read the guide → -
Operational Resilience: What It Means Under DORA
Resilience as an operating model: identify, protect, detect, recover, test, and control dependencies.
Read the guide →
DORA in operation
-
DORA Incident Reporting Timeline and Workflow
Classification, the reporting clocks, templates, and the workflow that meets them.
Read the guide → -
DORA ICT Third-Party Risk Management: Requirements and Process
Contract content, register duties, oversight of critical providers, and exit planning.
Read the guide → -
DORA Register of Information Readiness
Building and maintaining the register: scope, templates, data quality, and submission.
Read the guide → -
DORA RTS and ITS: Complete Technical Standards List
The delegated and implementing standards that specify DORA, and what each one governs.
Read the guide →
Who writes and reviews this
Q-Sec's Security Operations Center writes the knowledge-base material. Named experts review technical, compliance, or commercial claims only after completing the review. Every article shows its publication date and last meaningful update.