Skip to content
Blog · Jul 2, 2026 · 2 min read

What NIS 2 and DORA Actually Ask You to Prove

What NIS 2 and DORA Actually Ask You to Prove

NIS 2 and DORA both start from the same assumption: you already have security controls. What they add is a duty to show those controls were working on a particular day, on a particular system, and that someone acted when they were not.

That is a different problem from buying tools. Most organizations can describe their controls. Fewer can produce the record on request.

The reporting clock is a data problem

NIS 2 gives in-scope entities 24 hours to send an early warning after becoming aware of a significant incident, and 72 hours for a fuller notification. Those windows sound like a paperwork exercise until you try to meet them. If reconstructing who accessed what takes two days of pulling logs from separate systems, the first report goes out thin and the second one contradicts it.

Teams that meet the clock are not faster writers. They already had the activity record in one place before the incident.

DORA asks about resilience, and asks for records

DORA has applied to EU financial entities since January 2025. It covers ICT risk management, major incident reporting, resilience testing, and third-party dependencies. Supervisors reviewing any of those areas ask for the same underlying material: records of access, records of change, and evidence that detection worked.

Third-party dependency is where this gets awkward. When a provider touches your systems, you are expected to account for what they did inside your environment, not point at a contract.

What an examiner actually requests

Requests tend to be narrow and specific. Access to a named system over a named period. Every change to privileged group membership in a quarter. Evidence that a flagged event was reviewed, and by whom. Proof that the monitoring itself was running during the window in question, which is the request most organizations are least ready for.

Summaries do not satisfy these. A report stating that access was controlled is an assertion. A record showing each account that touched the system, when, and what changed is evidence.

Closing the distance

The gap for most teams is not detection. It is that the record lives across several systems with different retention windows and no common format, so assembling it becomes a project every time someone asks.

LT AuditorMP® collects user, file, identity and system activity across Windows, Linux, macOS and hybrid cloud into one place, and ships reporting templates aligned to NIS 2, DORA, ISO 27001, GDPR and other frameworks. The reporting engine is customizable, which matters because supervisors rarely ask for exactly the shape a template assumes.

Request a demo or start a free trial and see what that record looks like in your environment.

All posts

Secure your network. Prove it.

Start a free assessment