Three Frameworks, One Compliance Programme
If you are a CISO at a financial institution that deploys AI and operates critical infrastructure, you are potentially in scope for NIS2, DORA, and the EU AI Act simultaneously. All three are now in full effect. All three have audit and enforcement mechanisms. All three require documentation, evidence, and ongoing monitoring.
The good news: there is substantial overlap in the technical requirements across all three frameworks. The organisations building their compliance programmes most efficiently are those that have mapped the common technical foundation first - and built once, rather than three times.
The bad news: the overlaps are not obvious, and the gaps between the frameworks are exactly where enforcement gaps tend to appear. Getting the mapping wrong means either duplicating effort or leaving real compliance gaps.
This guide is for the CISO who needs to manage all three without tripling the compliance team.
The Common Technical Foundation
All three frameworks require a common set of technical capabilities. Building these once, robustly, satisfies requirements across all three:
Tamper-evident audit trails. NIS2 Article 21(2)(g) requires audit logging. DORA Article 9(4)(d) requires logging of ICT operations. EU AI Act Article 12 requires logging for high-risk AI systems. One implementation of tamper-evident, integrity-verified logging satisfies all three.
Data integrity verification. NIS2's integrity and authenticity requirements. DORA's data integrity requirements for ICT systems. EU AI Act Article 10's training data governance. All three require the ability to demonstrate that specific data assets have not been modified. One integrity verification infrastructure, applied consistently, covers all three.
Incident detection and response. All three frameworks require incident detection capabilities, documented response procedures, and notification to authorities within specific timeframes. A unified incident management framework with appropriate escalation logic for each framework is more efficient than separate programmes.
Supply chain security assessments. NIS2 Article 21(2)(d) and DORA Chapter V both require supply chain security programmes. The EU AI Act adds AI supply chain considerations. A single supply chain security framework can be extended to cover all three with appropriate documentation.
For a technical implementation of these common capabilities, see the ROOTKey enterprise hub which provides a unified compliance infrastructure across all three frameworks.
The Framework-Specific Requirements You Cannot Consolidate
Some requirements are genuinely framework-specific and require dedicated compliance effort:
DORA-specific:
- TLPT (Threat-Led Penetration Testing) for significant financial entities - mandatory under DORA, not required by NIS2 or EU AI Act
- ICT concentration risk assessment - the systemic risk analysis of third-party dependencies is DORA-specific
- Critical ICT third-party provider (CTPP) register oversight - requirements applying to CTPPs designated by ESAs are DORA-specific
EU AI Act-specific:
- Conformity assessment and EU Declaration of Conformity for high-risk AI systems
- Registration in the EU AI Office database
- Post-market monitoring plan for AI systems
- EU AI Act-specific transparency obligations (Article 52)
NIS2-specific (beyond DORA scope):
- Management body personal liability for cybersecurity measures (Article 20)
- Sector-specific supervisory arrangements under national transpositions
- National registration with competent authority timelines
For Portuguese organisations, the NIS2 Portugal guide covers the national-specific requirements that add to the base NIS2 obligations.
The Compliance Programme Architecture
The most efficient architecture for managing all three frameworks:
Tier 1: Common infrastructure. Tamper-evident audit logging, data integrity verification, incident management, and supply chain security programme. Built once, maintained once, used for all three frameworks.
Tier 2: Framework-specific documentation. The same technical facts, documented in the specific format and language each framework requires. The evidence base is shared; the presentation layer is framework-specific.
Tier 3: Framework-specific processes. TLPT for DORA. Conformity assessment for EU AI Act. Management body training and liability documentation for NIS2. These are genuinely separate processes that cannot be consolidated.
This architecture minimises duplication at the infrastructure level while maintaining the flexibility to satisfy each framework's specific evidence requirements.
ROOTKey's verifiable trust platform is designed specifically for Tier 1 of this architecture - providing the common technical foundation that satisfies integrity, auditability, and monitoring requirements across all three frameworks. Start building your compliance foundation.
在邮箱中获取网络韧性洞见
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。





