Why DORA, NIS2 and ISO 27001 make tech risk a legal duty

Why DORA, NIS2 and ISO 27001 make tech risk a legal duty

For EU-regulated firms, technology risk management is no longer simply good operational practice. It is a legal obligation, and DORA, NIS2 and ISO 27001 each impose it differently. Firms that still treat their risk register as a pre-audit spreadsheet exercise may find it no longer holds up.

According to Copla, technology risk, often called IT risk, covers threats to the systems, data and infrastructure a business relies on. Cyber risk is only one part of it. A vendor collapse, an unpatched legacy system or a failed migration may have nothing to do with an attacker, yet each can cause serious damage.

Technology risk itself sits within the broader category of operational risk. The distinction matters in practice, because scoring a supplier failure with a method designed only for cyberattacks produces misleading results.

The core process follows five steps: inventory assets, assess impact and likelihood, treat each risk, monitor continuously, and report and review. The order in which a firm builds the underlying inputs matters just as much.

Assets come first, followed by a business impact analysis, then a risk register, and only then controls. If a firm designs controls before establishing what is critical, it risks protecting whatever was easiest to define rather than what the business cannot afford to lose.

Each regime approaches the obligation differently. DORA, which has applied directly across the EU since 17 January 2025, sets out an ICT risk management framework in Articles 5 to 14. It requires firms to classify assets by criticality, apply proportionate controls and test their continuity plans.

Once an incident is classified as major, the first report to the regulator is due within four hours. NIS2, a directive covering essential and important entities outside finance, requires an early warning within 24 hours, a fuller notification within 72 hours and a final report within a month. Because it is a directive, member states apply it through their own national laws. ISO 27001, a certifiable standard, requires a documented risk assessment and treatment plan under clause 6.1. Its 2022 Annex A contains 93 controls.

The overlap between the three is significant. A single programme mapped across all three regimes typically surfaces around 500 controls, of which roughly 100 are unique. The rest are the same requirement worded differently. A control built once can therefore be reused three times.

Running the programme continuously means updating registers as things change, re-scoring risks after material events and gathering evidence from routine work such as disaster recovery tests. AI can speed up drafting and flag changes, but a named person must remain accountable.

Copla, a RegTech provider, argues that buyers should look for cross-framework mapping, a living asset register, a business impact analysis that feeds directly into the risk register, validated evidence collection and access to compliance expertise.

Read the full Copla post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.