
From the Cyber Resilience Act to the MPDG and NIS2: Regulations and standards as opportunities and drivers of innovation
Three strategic areas of action to improve cybersecurity
The EU strategy for improving cybersecurity comprises three areas of action:
- resilience, technological sovereignty and leadership
- Operational capability for prevention, deterrence and response
- Cooperation to promote a global and open cyberspace
The relevant policy states: “For the transition to digitalisation to be successful, European citizens and businesses must be able to benefit from new technologies without compromising their cybersecurity. The EU’s cybersecurity strategy aims to strengthen our collective cybersecurity and our response to cyberattacks. It will build a stable and secure global internet in which the rule of law, human rights and democratic values are protected. Cybersecurity is also a key area of the Digital Europe Programme. The programme aims to strengthen coordination on cybersecurity between EU countries and to fund the resilience of EU countries against cyberattacks”.1
Similarities & Differences – The Case of NIS2 & DORA

From obligation to opportunity: How NIS2 and DORA drive innovation
The majority of companies have come to regard information security and the associated regulatory requirements as a strategic asset. Regulations such as NIS2 and the Digital Resilience Act are now part of day-to-day business. “Most of our customers are subject to NIS2,” says Thomas Seiler, CISO at CANCOM Austria. “And we at CANCOM, as a service and solutions partner for critical infrastructure, are also NIS2-certified. So, in a sense, we’re in the same boat as our clients and have the expertise to solve the relevant problems.” Regulations and laws may be dry and tedious subject matter, but they’re essential. Dierk Lucyga, Principal Security Architect at CANCOM, is well aware of this: “Regulations and their implementation? We’re not killjoys; we’re not the ‘business-blocking’ department – on the contrary, we’re the business-enabling department.” This is because , for companies and their management, the strategic assets and specialisations embedded in regulations such as NIS2 or DORA present tangible opportunities for innovation and business growth, provided the requirements are implemented appropriately. “This is a top priority, ” says Dierk Lucyga, “Regulations can be effective levers for greater innovation and future-proofing.”
When cybersecurity regulations create real added value
The strategic and technological implementation of regulations within organisations creates genuine added value.
On the subject of costs: shorter response times reduce dwell time and thus lower incident costs; automation and runbooks drive the incident lifecycle forward; and exercises speed up the response and significantly improve its quality.
On efficiency: Regulation is not merely a cost centre, but delivers measurable efficiency gains. Automation lowers OPEX, reduces staff hours spent on repetitive compliance work, makes operational excellence measurable via KPIs, and ensures constant audit readiness through fast-responding, automated controls.
A driver of growth: the Data Act, NIS2, DORA and other regulations create new opportunities. Those who start early will avoid chaos in 2027 and secure competitive advantages through genuine provider choice. Security aspects relating to portability must be taken into account from the outset.
| An overview of EU cybersecurity regulations | Cybersecurity regulations by area of application |
|---|---|
| NIS2 Directive | Critical infrastructure and sectors: Protection through NIS2, CER and sector-specific directives. |
| Digital Operational Resilience Act (DORA) | Supply chains and product security: TheCyber Resilience Act and the EU Cybersecurity Act address the security of products containing digital elements. |
| Cyber Resilience Act (CRA) | Artificial Intelligence: TheAI Act sets out cybersecurity requirements for high-risk AI systems. |
| EU Cybersecurity Act | Certification and harmonisation: Requirement for the certification of ICT products and services by ENISA and EUCC. |
| Critical Entities Resilience Directive (CER) | Securing the workforce: TheEU Cybersecurity Skills Academy aims to train cybersecurity experts. |
| Data Act | Cross-border cooperation: Initiatives such as the Cyber Solidarity Act call for cooperation between Member States. |
| AI Act | |
| eIDAS 2.0 | |
| EU Cybersecurity Certification Scheme (EUCC) | |
| EU Cybersecurity Skills Academy |
