Skip to content
rPResiliencePilot

Resources

Make sense of the regulation

Practical, no-fluff guides on DORA, NIS2, ISO 27001 and building an operational-resilience programme. Not sure where you stand? Start with the 5-minute readiness check.

Topic hubs

Start with a hub

Interactive tools

Get an answer in minutes

Latest guides

Fresh from the team

An aerial view of railway tracks converging and diverging through a junction
Compliance8 min read

Which compliance framework(s) does your business need? DORA, NIS2, ISO 27001, ISO 22301, SOC 2 and Cyber Essentials compared

DORA, NIS2, ISO 27001, ISO 22301, SOC 2, Cyber Essentials. The honest answer to which you need comes down to three things: where you operate, what sector you're in, and who your customers are.

31 July 2026
A modern open-plan office at dusk seen through a glass wall, desks lit by monitor light
SOC 26 min read

What is SOC 2? The Trust Services Criteria and the report, explained

SOC 2 isn't a certificate you pass or fail. It's an independent auditor's report on how well your controls meet the Trust Services Criteria. Here's what that means and what's actually in it.

31 July 2026
A fibre-optic patch panel with rows of green connectors and looms of yellow cabling
Cyber Essentials6 min read

What is Cyber Essentials? The five controls and how certification works

Cyber Essentials is the UK's baseline cyber certification: five technical controls that stop the bulk of common attacks. Here's what it covers, how you certify, and when you'll be asked for it.

31 July 2026
An abstract web of connected black lines and nodes, like a network of dependencies
ISO 223015 min read

What is a Business Impact Analysis (BIA)?

The BIA is the foundation of continuity: it tells you what's critical, how quickly it must come back, and what it relies on. Get it right and the rest of your plan almost writes itself.

31 July 2026
A dark blue printed circuit board with fine gold traces, photographed in macro
Cyber Essentials6 min read

The five Cyber Essentials controls, explained

Cyber Essentials is five technical controls, no more. Here's what each one actually asks for in practice, and the details that most often trip up a first certification.

31 July 2026
A long-exposure night sky showing circular star trails around the pole star
SOC 26 min read

SOC 2 Type I vs Type II: which report do you actually need?

A Type I is a snapshot; a Type II is a film. Type II carries the weight with enterprise buyers, but there's a sensible path between the two, plus the bridge letter that covers the gap.

31 July 2026
A grid of illuminated windows across a dark skyscraper facade at night
SOC 25 min read

SOC 1 vs SOC 2 vs SOC 3: which SOC report do you need?

They sound like versions of the same thing. They aren't. SOC 1 is about your customers' financial reporting, SOC 2 is about security and trust, and SOC 3 is the public summary of a SOC 2.

31 July 2026
A striped coastal lighthouse beneath the Milky Way, its beam sweeping across a starry night sky
ISO 223015 min read

RTO vs RPO: the two recovery objectives, explained (with MTPD)

One is about time, the other about data, and confusing them is one of the most common mistakes in continuity planning. Here's RTO vs RPO in plain English, plus how MTPD fits.

31 July 2026
A vintage physical world globe on a wooden stand, North America facing the camera
ISO 270016 min read

ISO 27001 vs SOC 2: which do you need (or do you need both)?

They cover much of the same ground, which is why buyers confuse them. But one is a certificate and the other is a report, and which you need usually comes down to where your customers are.

31 July 2026
A laptop screen showing a dark analytics dashboard with glowing charts and metrics
Compliance7 min read

How to choose compliance software: a buyer's guide

The pitches all sound identical: automate compliance, save time, get audit-ready. Here's how to tell the tools apart on the things that actually determine whether you succeed.

31 July 2026
A close-up of illuminated fibre-optic network cables fanning out against a dark background
Cyber Essentials5 min read

Cyber Essentials vs Cyber Essentials Plus: which do you need?

The controls are identical; the assurance isn't. Cyber Essentials is self-assessed and reviewed, Plus is independently tested. Which one you need usually comes down to who's asking.

31 July 2026
A lit suspension bridge spanning a river gorge at dusk, city lights in the distance
ISO 223015 min read

Business continuity vs disaster recovery: what's the difference?

They're used interchangeably, but they aren't the same. Disaster recovery is the IT-restoration part of the much broader discipline of business continuity. Here's how they fit together.

31 July 2026
A wide view of an illuminated motorway interchange at night, forming a network of light trails
NIS27 min read

Is your organisation in scope for NIS2? A plain-English scope test

NIS2 comes down to two questions: what sector are you in, and how big are you. Work through both and you'll know whether you're in scope, and whether you're an essential or important entity.

31 July 2026
The Frankfurt financial-district skyline at dusk, its banking towers lit against a grey sky
DORA6 min read

Is your organisation in scope for DORA? Who the regulation actually covers

DORA's scope is broad within finance but precise about it. Here's how to tell whether you're a covered financial entity, what the exemptions actually cover, and why plenty of technology companies are pulled in as ICT providers.

31 July 2026
Blue network cables connected to a server rack in a dark data centre
ISO 270015 min read

ISO 27001:2022 vs 2013: what changed, and the deadline that's now passed

The 2022 revision restructured Annex A to 93 controls in four themes and added 11 new ones. The transition deadline was 31 October 2025; 2013 certificates are no longer valid.

18 June 2026
A faceted blue glass building facade forming a geometric grid
ISO 270015 min read

What is a Statement of Applicability? The ISO 27001 document auditors open first

The SoA lists every Annex A control, whether it applies, why, and its status. It's the map between your risk treatment and your controls, and it's where an auditor starts.

16 June 2026
A row of European Union flags outside the European Commission building in Brussels
DORA6 min read

DORA Article 30 explained: the contractual provisions you actually need

What Article 30 requires in your ICT supplier contracts: the standard provisions, the enhanced set for critical functions, and how to keep them evidenced.

15 June 2026
A container shipping port with gantry cranes at dusk
ISO 223015 min read

What is ISO 22301? Business continuity management, explained

ISO 22301 is the international standard for business continuity management. At its heart: a business impact analysis, recovery objectives, tested plans, and a management system that stays current.

14 June 2026
High-voltage electricity transmission towers silhouetted at dusk
ISO 223015 min read

Using one ISO 22301 BCMS to satisfy DORA and NIS2

DORA Article 11 and NIS2 Article 21 both expect tested continuity and recovery. ISO 22301 is the ready-made framework, so you build it once and evidence it against both.

12 June 2026
Rows of servers in a data centre, dense with orange and teal network cabling
DORA5 min read

Building a DORA Register of Information that survives a supervisor

The Register of Information is one of DORA's most concrete deliverables. Here's how to build one that stays accurate and export-ready.

12 June 2026
Overhead power and cabling infrastructure inside a modern data centre
NIS25 min read

NIS2 incident reporting: the timelines that catch teams out

NIS2 reporting happens in stages, on the clock. Here's what each stage asks for and how to avoid scrambling when an incident hits.

10 June 2026
The empty debating chamber of the European Parliament
Operational resilience6 min read

DORA vs NIS2: what's the difference, and can one platform cover both?

DORA and NIS2 are often mentioned in the same breath. They overlap, but they're aimed at different things. Here's how they differ, and where they reinforce each other.

8 June 2026

Free templates & checklists

Working starters, not blank pages

DORA Register of Information starter

A simplified single-sheet starter to gather the core data the DORA RoI needs: providers (with LEI), contracts, function criticality and data locations. The official RoI is a multi-table xBRL-CSV submission; this helps you collect, not file.

DORA Article 30 contract checklist

A working checklist of the mandatory contractual provisions: the standard set for all ICT services and the enhanced set for critical or important functions.

NIS2 incident-reporting timeline

A one-page reference to the NIS2 Article 23 clock: 24-hour early warning, 72-hour notification, intermediate report on request, and the 1-month final report.

Business impact analysis starter

A starting BIA template aligned to ISO 22301 clause 8.2: process criticality, MTPD, RTO/RPO, dependencies and single points of failure.

Stay in the loop

New DORA, NIS2 and ISO guidance as we publish it

Occasional and practical, no spam. The odd template or checklist too.