Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

EU cyber regulation

NIS2 and DORA obligations, mapped to evidence.

Two EU regimes now set baseline cybersecurity duties for essential services and the financial sector. This is what each one asks for, who it covers, and how the obligations map to testing, assessment and the statutory audit.

NIS2 directive
(EU) 2022/2555
Latvia transposition
Nat. Cybersecurity Law
DORA regulation
(EU) 2022/2554
DORA applies
17 Jan 2025

01

What the two regimes require

NIS2 · DORA

NIS2

Directive (EU) 2022/2555

NIS2 raises the baseline of cybersecurity risk management across essential and important sectors. Entities must adopt technical and organisational measures proportionate to their risk — governance, incident handling, business continuity, supply-chain security, vulnerability handling, and the testing and auditing of those measures — and report significant incidents to the national authority. Management bodies are accountable and can be held liable.

In scope Medium and large organisations in the sectors the directive lists — energy, transport, banking and financial-market infrastructure, health, water, digital infrastructure, ICT service management and public administration as essential entities; postal, waste, chemicals, food, manufacturing, digital providers and research as important entities. In Latvia the duties come from the National Cybersecurity Law, in force since September 2024.

DORA

Regulation (EU) 2022/2554 · applies since 17 Jan 2025

DORA is a directly applicable regulation that sets one operational-resilience rulebook for EU finance. It covers ICT risk management, classification and reporting of major ICT-related incidents, digital operational-resilience testing, management of ICT third-party risk, and information sharing. The most demanding entities must run threat-led penetration testing (TLPT) against live production systems on a multi-year cycle.

In scope Financial entities across the EU — credit institutions, payment and electronic-money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, fund managers and more — together with the critical ICT third-party providers that serve them.

02 Statutory audit authorisation

Qualified to perform the NIS2 audit in Latvia.

Under Latvia’s National Cybersecurity Law, the external cybersecurity audit must be carried out by an independent auditor who has no conflict of interest with the audited entity and who meets the requirements set for cybersecurity auditors in Cabinet of Ministers regulations. The public list of approved auditors was abolished in 2026 — an entity may now engage any auditor who meets those requirements.

SEQ SIA, registration No. 40203410806, meets those requirements and can perform the statutory NIS2 external audit. The audit is led by specialists holding the ISO/IEC 27001 Senior Lead Auditor (PECB) and Certified Information Systems Auditor (ISACA) certifications.

Because the auditor must be free of conflicts of interest, the statutory audit is scoped as an engagement separate from any readiness or remediation work.

likumi.lv · Nacionālās kiberdrošības likums, 44. pants (opens in a new tab)

03

From obligation to evidence

obligation → how we help
  1. 01

    NIS2 — testing and auditing of security measures (Art. 21)

    Authorised penetration testing of infrastructure, applications and processes, reported as prioritised, evidence-backed findings.

    Security Audits
  2. 02

    NIS2 — risk management, governance and evidence

    Applicability scoping (essential vs important), gap analysis against NIS2 and ISO/IEC 27001, a risk-based roadmap and audit-ready evidence packages.

    NIS2 & ISO 27001 Readiness
  3. 03

    NIS2 — statutory external cybersecurity audit

    Performed by SEQ SIA (reg. 40203410806) as an independent auditor meeting the statutory requirements, kept separate from any remediation work.

    The audit authorisation
  4. 04

    DORA — ICT risk management and resilience testing

    Gap assessment across the five DORA pillars, ICT risk-framework support and a resilience-testing programme mapped to your critical functions.

    DORA Compliance & Resilience Testing
  5. 05

    DORA — threat-led penetration testing (TLPT)

    A TIBER-EU-aligned TLPT: threat-intelligence-led, covert red-team testing of live systems with the required purple-team closure and supervisory reporting.

    DORA TLPT
  6. 06

    Detection and response, proven end to end

    Objective-based red teaming and adversary emulation mapped to MITRE ATT&CK — evidence of whether a real attack would be prevented, detected and answered.

    Red Team & Adversary Emulation
7 Essential Steps to Prepare Your Business for NIS2 Compliance
Whitepaper · 11 pages · 6 min read

Start here

Not sure which regime applies?

The NIS2 / DORA scope check walks through a short set of questions and tells you whether — and how — the rules reach your organisation.

04

Common questions

Does NIS2 apply to my organisation?
NIS2 generally reaches medium and large organisations operating in the sectors the directive lists, and some entities regardless of size. In Latvia the specific duties come from the National Cybersecurity Law. The scope check gives a first read; a readiness engagement confirms it formally.
Which financial entities have to run DORA TLPT?
Not every one. Competent authorities identify the entities required to perform threat-led penetration testing based on their size, risk profile and systemic importance. Those in scope test live production systems on a multi-year cycle using the TIBER-EU-aligned method.
Can the same firm do our remediation and our statutory audit?
No. The external cybersecurity audit under the National Cybersecurity Law must be performed by an independent auditor with no conflict of interest, so the statutory audit is kept separate from readiness or remediation work.
What lets SEQ SIA perform the NIS2 audit?
SEQ SIA (reg. 40203410806) meets the requirements set for cybersecurity auditors under Latvia’s National Cybersecurity Law. Since the public auditor list was abolished in 2026, any auditor who meets those requirements — and has no conflict of interest — may carry out the statutory external audit.

Map your NIS2 or DORA obligations to a plan.

[email protected] +371 2256 5353