One resilience program for NIS2, DORA and the CRA
NIS2, DORA and the Cyber Resilience Act all ask the same underlying question: when something breaks, can you keep operating, and can you prove it? Rizzqo runs all three on the systems, providers and products that question is really about.
Built for the laws that demand resilience
Three EU laws, one shared backbone of assets, controls and evidence. Each framework ships pre-loaded and ready to run, and the work you do for one counts toward the others.
NIS2
The EU cybersecurity directive for essential and important entities: management accountability, the ten Article 21 risk-management measures, and incident reporting on a 24-hour clock.
Explore frameworkDORA
Digital operational resilience for EU financial entities: ICT risk management, incident reporting, resilience testing and third-party risk, owned by the management body.
Explore frameworkCRA
The Cyber Resilience Act for products with digital elements: secure by design, vulnerability handling across the support period, and conformity behind the CE mark.
Explore frameworkHow Rizzqo runs resilience
One program from first inventory to regulator-ready proof, anchored to the systems, providers and products that have to stay up.
Map the estate that has to stay up
Resilience starts with knowing what you depend on. Rizzqo keeps one live map of your systems, the providers behind them and the products you ship, so every duty in NIS2, DORA and the CRA lands on something real.
Turn each law's measures into owned controls
The Article 21 measures, the five DORA pillars and the essential requirements of the CRA all become controls with a named owner, applied to the assets they actually govern, not clauses in a policy nobody opens.
Be ready when the clock starts
All three laws put deadlines on a bad day: early warnings within 24 hours under NIS2, major-incident reports under DORA, actively exploited vulnerabilities under the CRA. Rizzqo keeps roles, playbooks and current system information ready before the timer ever starts.
Keep the proof running all year
Resilience is not an annual exercise. Evidence collects continuously on every system, provider and product, so the proof of your program is always current and complete, never assembled for the occasion.
Everything a resilience program needs
From dependency mapping to reporting deadlines, every obligation sits on the real asset it protects, with a named owner and current evidence.
Dependency inventory
One live map of the systems, providers and products your operations stand on, the starting point all three laws assume.
Owned controls
Every measure, pillar and essential requirement becomes a control with a named owner on the asset it governs.
Incident readiness
Roles, escalation paths and report templates prepared against the 24-hour and major-incident clocks, before you need them.
Third-party and ICT provider risk
The providers behind your services carry their own risk, contracts and evidence, visible in the same program.
Vulnerability handling
Track vulnerabilities across your products and the support period the CRA defines, from intake to fix to disclosure.
Continuous evidence
Proof collects as the program runs, so reviews and conformity assessments draw on current answers, not reconstructions.
From three legal texts to one running program
Each law keeps its own requirements and its own reports, but they share one backbone: the same assets, the same owners, the same evidence. Run it once, answer to all three, and see what any failure would actually put at risk.
Frequently asked questions
They target different scopes: NIS2 covers essential and important entities in critical sectors, DORA covers EU financial entities and their ICT providers, and the CRA covers products with digital elements placed on the EU market. Many companies fall under more than one: a bank under DORA may ship software the CRA covers, and a manufacturer under NIS2 sells connected products. Rizzqo lets you run whichever combination applies as one program.
A great deal. All three demand risk management, incident handling, third-party or supply-chain security, and management accountability. In Rizzqo a control you implement once, such as access control or incident response, satisfies every framework that requires it, so the second and third framework cost far less than the first.
NIS2 expects an early warning within 24 hours, DORA sets deadlines for major ICT incident reports, and the CRA requires reporting actively exploited vulnerabilities. Rizzqo keeps the roles, escalation paths and current system information those reports need ready in advance, so the deadline is spent responding, not searching.
Yes, substantially. An ISMS built on ISO 27001 already covers most of the NIS2 Article 21 measures and much of what DORA expects from ICT risk management. Rizzqo maps that overlap explicitly, so existing Annex A work is credited instead of repeated.
Build resilience you can prove
See how Rizzqo runs NIS2, DORA and the CRA on your real systems, providers and products, as one program with one set of evidence.