
Criteria catalogs
The criteria that matter when you choose regulated technology
One free catalog per technology category. Each criterion tells you why it counts, what to ask the vendor, and the phrase behind which the problem usually hides. Built for the moment you define requirements under NIS2, DORA and GDPR.
Endpoint Detection and Response
23 criteria
EDR selection: the criteria that matter under NIS2 and DORA
Most EDR evaluations check detection rate and price. Under NIS2 and DORA, that is not enough. These are the criteria that decide whether your choice holds up in an audit, not just in a demo.
Identity and Access Management
23 criteria
IAM selection: the criteria that matter under NIS2 and DORA
Most IAM evaluations check the SSO catalog and the price per user. Under NIS2 and DORA, the questions that matter are different: what happens when the IdP is down, who can prove which account was disabled when, and where the identity store lives.
Privileged Access Management
12 criteria
PAM selection: the criteria that matter under NIS2 and DORA
Most PAM evaluations check whether passwords can be vaulted and sessions recorded. The decision that matters is what happens with the accounts nobody listed, the admins who route around the tool, and the day the PAM itself is down.
Security Information and Event Management
23 criteria
SIEM selection: the criteria that matter under NIS2 and DORA
Most SIEM evaluations compare dashboards and a per-gigabyte price. Under NIS2 and DORA, the questions that matter are who writes the detection rules, how fast you can prove what happened, and what the bill looks like in year three.
Managed Detection and Response
23 criteria
MDR selection: the criteria that matter under NIS2 and DORA
Most MDR evaluations compare dashboards and a price per endpoint. What decides the choice is what the provider is contractually obliged to do in the first hour of an incident, who looks at your data while doing it, and whether the contract survives a DORA or NIS2 audit.
Backup and Disaster Recovery
23 criteria
Backup and DR selection: the criteria that matter under NIS2 and DORA
Most backup evaluations check capacity, price and a green dashboard. Under NIS2 and DORA the question is different: can you restore after an attacker with admin rights has done their worst, how fast, and can you prove it?
Sovereign Cloud and Cloud Platforms
23 criteria
Sovereign cloud selection: the criteria that matter under NIS2, DORA and GDPR
Most cloud evaluations compare service catalogs and list prices. For regulated workloads the decisive questions are who can access your data, who can decrypt it, and how you leave. These are the criteria that hold up in a DORA or NIS2 audit, not just in a pitch deck.
How to use a catalog
- Read the traps first. Each one is a mistake somebody already paid for.
- Put the questions to every vendor in the same words, and write the answers down next to each other.
- Strike what does not apply to your situation, then weight what remains. The list is the input, the weighting is the decision.