IT, data & continuous
Cybersecurity Audit (DORA/NIS2)
Audit domain focused on risk assessment and compliance testing of cybersecurity under EU regulation. DORA (Digital Operational Resilience Act) has applied to financial entities since 17 January 2025. NIS2 had to be transposed by 17 October 2024; in the Netherlands the Cybersecurity Act (Cyberbeveiligingswet) has applied to essential and important entities since 15 August 2026. A cybersecurity audit assesses, among other things, access management, incident response, business continuity and monitoring against these requirements.
Source: Verordening (EU) 2022/2554 (DORA); Richtlijn (EU) 2022/2555 (NIS2); Cyberbeveiligingswet
Last updated: