Compare NIS2, DORA, GDPR, and ISO 27001 on proving security works
The same demand, in three regulations — plus the standard behind them
| Regulation | What it requires | What it applies to | What counts as proof |
|---|---|---|---|
| NIS2 | Test the effectiveness of awareness and training; run a documented process that assesses whether risk-management measures work | Essential and important entities across 18 sectors | Behavioral evidence of change over time, not completion records |
| DORA | Monitor the effectiveness of your resilience strategy; make awareness and resilience training compulsory for all staff and the board | EU financial entities | A defensible trend in workforce behavior, not attendance logs |
| GDPR | A process for regularly testing, assessing, and evaluating the effectiveness of your security measures | Any organization processing personal data | Ongoing evidence the organizational measures work, not a one-off training record |
| ISO 27001 | Evidence that controls, including awareness and training, are operating effectively | Any certified or certifying organization | Behavioral data auditors accept beyond policy documents |
Different regulators, different words, one gap: none of them are satisfied by proof that you delivered something. They want proof it worked. For the human layer, that proof is behavioral — and it's the one thing a training platform can't give you.
NIS2 requires you to test whether your awareness and training are effective, and to run a documented process that assesses whether your risk-management measures work. Applies to essential and important entities across 18 sectors.
DORA requires financial entities to monitor the effectiveness of their digital operational resilience strategy, and makes security awareness and resilience training compulsory for every employee and board member. Applies to EU financial entities.
GDPR Article 32 requires a process for regularly testing, assessing and evaluating the effectiveness of your security measures. Applies to any organization processing personal data.