Compare NIS2, DORA, GDPR, and ISO 27001 on proving security works

The same demand, in three regulations — plus the standard behind them

Comparison of NIS2, DORA, GDPR, and ISO 27001 requirements for proving security effectiveness
Regulation What it requires What it applies to What counts as proof
NIS2Test the effectiveness of awareness and training; run a documented process that assesses whether risk-management measures workEssential and important entities across 18 sectorsBehavioral evidence of change over time, not completion records
DORAMonitor the effectiveness of your resilience strategy; make awareness and resilience training compulsory for all staff and the boardEU financial entitiesA defensible trend in workforce behavior, not attendance logs
GDPRA process for regularly testing, assessing, and evaluating the effectiveness of your security measuresAny organization processing personal dataOngoing evidence the organizational measures work, not a one-off training record
ISO 27001Evidence that controls, including awareness and training, are operating effectivelyAny certified or certifying organizationBehavioral data auditors accept beyond policy documents

Different regulators, different words, one gap: none of them are satisfied by proof that you delivered something. They want proof it worked. For the human layer, that proof is behavioral — and it's the one thing a training platform can't give you.

NIS2 requires you to test whether your awareness and training are effective, and to run a documented process that assesses whether your risk-management measures work. Applies to essential and important entities across 18 sectors.

DORA requires financial entities to monitor the effectiveness of their digital operational resilience strategy, and makes security awareness and resilience training compulsory for every employee and board member. Applies to EU financial entities.

GDPR Article 32 requires a process for regularly testing, assessing and evaluating the effectiveness of your security measures. Applies to any organization processing personal data.