EU directiveEU
NIS2
NIS2 Directive (EU) 2022/2555
NIS2 sets cybersecurity risk-management and incident-reporting obligations for essential and important entities in eighteen sectors, with management bodies personally accountable. Member States had to transpose it by 17 October 2024; national laws differ in detail.
Who it reaches
- Medium and large organisations in the Annex I and II sectors: energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space, postal, waste, chemicals, food, manufacturing, digital providers and research.
- Some entities regardless of size: DNS, TLD registries, trust service providers, public electronic communications providers and others.
- Suppliers of in-scope entities, indirectly, through the supply chain security duty.
What the audit checks
- 01National authorities supervise: essential entities proactively, important entities after the fact.
- 02An audit checks the Article 21 measures, the management body’s approval and training, incident reporting readiness and supply chain controls.
- 03Most organisations evidence NIS2 through an ISO 27001 ISMS mapped to Article 21.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Scope determination and registration | 1 to 3 |
| Gap assessment against Article 21 and national law | 2 to 4 |
| Implement measures and reporting process | 8 to 24 |
| Board approval, training, internal audit | 2 to 6 |
Evidence to have ready
- Scope determination with sector and size reasoning
- Registration with the national authority
- Board approval of the cybersecurity measures and training records
- Risk analysis and information system security policies
- Incident handling procedure with 24h, 72h and one-month reporting steps
- Business continuity, backup and crisis management plans
- Supply chain security assessments and contract terms
- Vulnerability handling and disclosure process
- Multi-factor authentication and cryptography policies
- Effectiveness assessment of the measures
Dates
- Transposition deadline for Member States
Questions people ask
- Essential or important: what is the difference?
- Essential entities are large organisations in Annex I sectors and certain others; they face proactive supervision and higher fines (10 million euro or 2 percent). Important entities are the rest in scope, supervised after the fact, with fines up to 7 million euro or 1.4 percent.
- What are the incident reporting deadlines?
- An early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, and a final report within one month.
- Does ISO 27001 cover NIS2?
- An ISO 27001 ISMS carries most of the Article 21 measures, but NIS2 adds registration, management accountability, specific reporting deadlines and national requirements that the certificate alone does not evidence.