All frameworks
EU directiveEU

NIS2

NIS2 Directive (EU) 2022/2555

NIS2 sets cybersecurity risk-management and incident-reporting obligations for essential and important entities in eighteen sectors, with management bodies personally accountable. Member States had to transpose it by 17 October 2024; national laws differ in detail.

Who it reaches

  • Medium and large organisations in the Annex I and II sectors: energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space, postal, waste, chemicals, food, manufacturing, digital providers and research.
  • Some entities regardless of size: DNS, TLD registries, trust service providers, public electronic communications providers and others.
  • Suppliers of in-scope entities, indirectly, through the supply chain security duty.

What the audit checks

  1. 01National authorities supervise: essential entities proactively, important entities after the fact.
  2. 02An audit checks the Article 21 measures, the management body’s approval and training, incident reporting readiness and supply chain controls.
  3. 03Most organisations evidence NIS2 through an ISO 27001 ISMS mapped to Article 21.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Scope determination and registration1 to 3
Gap assessment against Article 21 and national law2 to 4
Implement measures and reporting process8 to 24
Board approval, training, internal audit2 to 6

Evidence to have ready

  • Scope determination with sector and size reasoning
  • Registration with the national authority
  • Board approval of the cybersecurity measures and training records
  • Risk analysis and information system security policies
  • Incident handling procedure with 24h, 72h and one-month reporting steps
  • Business continuity, backup and crisis management plans
  • Supply chain security assessments and contract terms
  • Vulnerability handling and disclosure process
  • Multi-factor authentication and cryptography policies
  • Effectiveness assessment of the measures

Dates

  • Transposition deadline for Member States
All regulatory deadlines

Questions people ask

Essential or important: what is the difference?
Essential entities are large organisations in Annex I sectors and certain others; they face proactive supervision and higher fines (10 million euro or 2 percent). Important entities are the rest in scope, supervised after the fact, with fines up to 7 million euro or 1.4 percent.
What are the incident reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, and a final report within one month.
Does ISO 27001 cover NIS2?
An ISO 27001 ISMS carries most of the Article 21 measures, but NIS2 adds registration, management accountability, specific reporting deadlines and national requirements that the certificate alone does not evidence.

Go deeper