Compliance with Regulatory Requirements (DORA, NIS2, AI Act)

Compliance with regulatory frameworks such as NIS2, DORA, and the upcoming AI Act is becoming a strategic imperative for organizations that cannot be ignored. These regulations introduce stricter requirements for cyber risk management, the resilience of digital services, and the secure use of artificial intelligence, thereby significantly impacting the operations of entities in both the public and private sectors.

NIS2 Directive (Directive (EU) 2022/2555)

The NIS2 Directive expands the scope of entities subject to its requirements to include multiple sectors (public administration, energy, healthcare, transportation, and IT services) and introduces new obligations in the areas of:

  • cybersecurity risk analysis and management,
  • operational and security management of the supply chain,
  • reporting of cybersecurity incidents within 24 hours,
  • implementation of information and cybersecurity policies,
  • ensuring the independence and expertise of responsible individuals (e.g., CISO).

The NIS2 Directive enters into force in all EU Member States and must be transposed into national legislation (in Slovakia through an amendment to Act No. 69/2018 Coll.).

DORA (Digital Operational Resilience Act – Regulation (EU) 2022/2554)

DORA sets out obligations for financial market entities in the following areas:

  • ICT risk management,
  • digital resilience testing (including red teaming exercises),
  • standardized reporting of ICT incidents,
  • management of outsourcing contracts with ICT providers,
  • record-keeping, auditability, and business continuity.

DORA will take effect in January 2025 and is legally binding without the need for transposition.

AI Act (Regulation on Artificial Intelligence)

The AI Act defines risk categories for AI systems (prohibited, high-risk, restricted, low-risk) and establishes obligations, particularly for high-risk AI:

  • maintaining technical and regulatory documentation,
  • registration in a central system,
  • ensuring transparency, explainability, and human oversight,
  • and implementing mechanisms to manage AI-related risks.

For developers and users of AI technologies, this means the need to implement new compliance processes, conduct conformity assessments, and monitor the development and operation of algorithms.


We also ensure compliance with NIS2 and related regulations from a technical standpoint—you can find more information about this in the Cybersecurity service on TRC: Link

Are you interested in this service?