DORA & NIS2
DORA & NIS2 Compliance Decisions for Australian Organisations
If you sell to EU financial services or operate essential / important entities in the EU, DORA and NIS2 now apply. Decide your obligations, gaps and uplift plan with structured AI decision support.
WHY AUSTRALIAN ORGANISATIONS SELLING INTO EU AND UK MARKETS CHOOSE FORTE/CYBERx
Decisions that hold up under scrutiny.
Scope decision in one mission
Are we in scope as a financial entity, an ICT third-party provider or an essential / important entity? A defensible answer in minutes.
Gap analysis against your existing controls
Cross-walk to ISO 27001, APRA CPS 230 / 234 and SOCI to reuse what you already have.
Reporting playbook
DORA 4-hour and 24-hour incident reporting thresholds operationalised against your existing IR plan.
TRY IT NOW
Bring one real decision. Get three defensible options.
The council returns a board-ready BLUF and three strategic options in under 60 seconds.
DECISIONS THE COUNCIL HANDLES
Sized for the conversation you're already having.
Pick a starting point or describe your decision in your own words. FORTE/CYBERx returns three strategic options with trade-offs, framework anchors and an execution-ready plan.
Are we in scope of DORA as an ICT third-party?
A defensible position with the contract clauses regulators expect to see.
How does NIS2 apply if we have an EU subsidiary?
Sector classification, member-state nuance and the management-body accountability test.
What changes vs APRA CPS 230?
A side-by-side delta you can take to your existing operational-resilience programme.
How do we run the digital operational resilience tests?
TLPT scoping, vendor inclusion and remediation sequencing.
What does the supervisor / regulator see?
A documentation pack ready for the lead overseer or competent authority.
QUESTIONS
FAQ
We are Australian — does DORA actually apply to us?
DORA applies extraterritorially to ICT third-party service providers supporting in-scope EU financial entities. If you sell SaaS, cloud, managed services or critical ICT services into EU banks, insurers or investment firms, you can be designated and brought into the regime — directly or via contractual flow-down.
How does NIS2 differ from DORA?
NIS2 is a horizontal cyber directive across essential and important entities in many sectors. DORA is sector-specific to financial services and explicitly preempts NIS2 for in-scope entities. Many groups have to deal with both.
What about the management-body accountability provisions?
Both DORA and NIS2 put cyber and ICT risk accountability on the management body. Our outputs include the board-grade structure and approval log regulators look for.
Can we reuse our CPS 230 and ISO 27001 work?
Yes — most of it. Our gap analysis flags the deltas (e.g., DORA threat-led penetration testing, NIS2 reporting timeframes) so you do not re-do work you have already completed.
Run your first mission free.
Two free missions. No credit card. Average mission resolves in under 60 seconds.