
Compliance Mapping Now Covers NIS2 and DORA, Not Just SOC 2 and ISO 27001
Decloak's compliance control mapping started with SOC 2 and ISO 27001, tagging every finding a scan detects to the relevant control in each framework, so a missing header or an exposed credential shows up not just as "fix this" but as "fix this, it maps to control X." That's now expanded to two more frameworks: NIS2 and DORA.
What shipped
Every one of the 36 finding categories Decloak detects, missing headers, JavaScript CVEs, exposed credentials, third-party domain risk, and the rest, is now tagged to the relevant control across all four frameworks: SOC 2, ISO 27001, NIS2 (Article 21(2) risk-management measures), and DORA (the ICT risk-management and third-party-risk articles).
To be clear about what this is and isn't: it's not a new scanning capability. Decloak is finding the same things it already found. This is a labelling layer on top of that, mapping each finding to where it lands in four regulatory and audit frameworks instead of two.
Why now
DORA has been fully applicable across the EU since January 2025, so this closes a gap for anyone already operating under it. NIS2 is the more time-sensitive one: the compliance deadline lands this October, and the directive now covers roughly 160,000 EU entities, up from around 10,000 under the original NIS directive. If your organization wasn't in scope for the old NIS rules, there's a real chance it is now. Both additions are squarely "get ahead of the deadline" work rather than a response to anything that's already overdue.
A caveat worth being upfront about
NIS2 and DORA are structurally coarser than ISO 27001. NIS2 has only ten lettered measures under Article 21(2). DORA's relevant articles (9, 10, 13, and 28) number a handful. ISO 27001, by comparison, has well over 90 individual controls. That means several finding categories that get distinct, separate ISO controls will intentionally land on the same single NIS2 or DORA control. That's not a gap in how we built the mapping, it's a property of how much less granular those two frameworks are by design.
The same disclaimer that's always applied to compliance mapping still applies here: this is indicative mapping to help you understand where a finding sits, not a certified audit, and not a substitute for checking against your actual auditor's specific requirements. Treat it as a starting point for the conversation with your compliance team, not the final word.
Where this shows up
- Report page: the Compliance Mapping section now has four framework tabs, SOC 2, ISO 27001, NIS2, DORA, instead of two. This works retroactively on scans you've already run, no re-scan required.
- PDF exports: the Active Testing DAST PDF's control badges and caption now include NIS2 and DORA references.
- Evidence packages: the CSV finding log inside exported evidence ZIPs automatically includes NIS2 and DORA in the compliance-controls column.
- Help docs: the compliance mapping guide now includes a worked example, plus a new glossary entry covering NIS2 and DORA for anyone unfamiliar with either.
Availability
Full compliance control mapping across all four frameworks requires a Decloak Pro account, same as the existing SOC 2 and ISO 27001 mapping.
If you're already on Pro, there's nothing to do, your existing scans will show the new tabs the next time you open a report. If NIS2 applies to your organization and October is on your radar, this is a reasonable moment to check where your current findings actually sit against Article 21(2) before the deadline rather than after it.
NIS2 and DORA control mapping is available on Decloak Pro alongside SOC 2 and ISO 27001. See plans and upgrade →