Which compliance framework(s) does your business need? DORA, NIS2, ISO 27001, ISO 22301, SOC 2 and Cyber Essentials compared
A decision guide to the main resilience and security frameworks: which are legally required, which are market-driven, how they map by region, and how to pick without doing the same work twice.

Somewhere between winning your first enterprise deal and your first regulator letter, the acronyms start arriving: DORA, NIS2, ISO 27001, ISO 22301, SOC 2, Cyber Essentials. They overlap, they sound similar, and it's genuinely hard to tell which actually apply to you.
The honest answer comes down to three questions: where do you operate, what sector are you in, and who are your customers? Work through those and the list narrows fast. The most useful first cut is to split the frameworks into two groups: the ones you have no choice about, and the ones you choose.
Group 1: the ones the law decides (regulatory)
These apply because of who you are and where you operate, not because a customer asked. If you're in scope, they're mandatory.
- DORA: the EU Digital Operational Resilience Act. Applies to a defined list of financial entities (and reaches their ICT providers), and has applied since January 2025. If you're a bank, insurer, investment firm, payment or crypto business in the EU, or you sell technology to one, this is likely in scope. See are you in scope for DORA.
- NIS2: the EU cybersecurity directive. Applies to medium-and-larger organisations in 18 sectors (energy, transport, health, digital infrastructure, manufacturing and more), as transposed into each member state's law. See are you in scope for NIS2.
If either applies, it isn't optional, and you'll also feel them second-hand through customers who are in scope and must manage their supply chain. The two overlap but aren't the same, as we cover in DORA vs NIS2.
Group 2: the ones the market decides (voluntary, but expected)
Nobody legally requires these, but your customers, partners and procurement teams often do. They're how you prove you can be trusted.
- ISO 27001: the international standard for an information security management system. A recognised certification, expected by international and European customers.
- SOC 2: the North American security attestation report, built on the Trust Services Criteria and expected by US buyers. (Which of these two you need is common enough to have its own guide: ISO 27001 vs SOC 2.)
- Cyber Essentials: the UK's baseline certification. Voluntary in general, but frequently mandatory for UK government and public-sector contracts, and a fast, cheap first credential. See what is Cyber Essentials.
- ISO 22301: the international standard for business continuity. Chosen where customers or your own board want assurance you can keep operating and recover, and increasingly used to evidence the continuity parts of DORA and NIS2. See using one ISO 22301 system for DORA and NIS2.
A quick map by region
- Selling to the EU? Check DORA (if financial) and NIS2 (if in a covered sector) first, because those are legal duties. Add ISO 27001 for market trust.
- Selling in the UK? Cyber Essentials is the baseline (and often required for public-sector work); ISO 27001 for larger customers.
- Selling in the US? SOC 2 is the expectation, usually Type II.
- Selling internationally? ISO 27001 travels furthest, often alongside SOC 2 for US accounts.
- Care about staying operational and can prove it? ISO 22301 underpins continuity across all of the above.
The point most people miss: do them on one foundation
Here's what turns this from a nightmare into a manageable programme. These frameworks share most of their underlying controls. Access control, risk management, incident handling, change management, continuity, evidence, they recur across almost all of them. ISO 27001 and SOC 2 alone overlap by well over half.
So the expensive mistake is running each framework as a separate project with its own evidence pile. The efficient approach is one well-run set of controls, mapped to whichever frameworks your market and regulators demand. You maintain the control once and evidence DORA, NIS2, ISO 27001, ISO 22301, SOC 2 and Cyber Essentials from the same foundation.
Your decision, in five questions
- Are you an EU financial entity (or sell to one)? Then DORA.
- Are you a medium-plus organisation in an EU NIS2 sector? Then NIS2.
- Do your customers ask for a security credential, and are they US (SOC 2) or international/European (ISO 27001)?
- Do you bid for UK public-sector work? Then Cyber Essentials.
- Do you need to prove you can keep operating and recover? Then ISO 22301.
Most organisations end up with two or three of these, not one, which is exactly why doing them together matters. ResiliencePilot maps a single control set across all of them, so each obligation is evidenced from the same source of truth. See the platform, the solutions by framework, or book a demo.