GRC Oversight

NIS2

NIS2 is the EU directive that strengthens cybersecurity requirements and expands the scope of regulated sectors, applying to designated essential and important entities.

Governed by European Union (Directive 2022/2555)
What it is

What NIS2 is, in plain terms

NIS2 is the EU's updated directive on the security of network and information systems. It significantly broadens the sectors in scope compared with the original NIS Directive, sets baseline cybersecurity risk-management measures, imposes incident-reporting obligations, and introduces direct accountability for management bodies. Because it is a directive, its specific requirements are transposed into the national law of each member state.

Typical effort & timeline

Obligations apply as member states transpose the directive into national law, so exact requirements and timing vary by country. Programs typically build on existing risk-management and incident-handling capabilities.

Who needs it

Is this framework for you?

  • Designated essential and important entities across expanded EU sectors.
  • Organizations operating critical infrastructure or key digital services in the EU.
  • Suppliers whose customers are subject to NIS2 supply-chain security expectations.
About the framework

Key facts about NIS2

  • Expands sector coverage compared with the original NIS Directive.
  • Requires risk-management measures and incident-reporting obligations.
  • Introduces management accountability for cybersecurity governance.
  • Transposed into national law by EU member states.

Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.

With this platform

How we help with NIS2

  • Map risk-management measures to tests and evidence.
  • Track incident-handling processes and documentation.
  • Support governance and accountability reporting.
  • Reuse overlapping evidence from ISO 27001 and other frameworks.
Step by step

Get and stay compliant

How the platform supports your NIS2 program, from first scope to ongoing monitoring.

Confirm scope

Determine whether you qualify as an essential or important entity in the relevant member state.

Implement risk measures

Map the required risk-management measures to tests and evidence.

Operationalize reporting

Build and document incident-handling and notification processes.

Govern & report

Support management accountability and governance reporting on an ongoing basis.

Representative areas

What NIS2 covers

Public, high-level control or requirement areas, for orientation, not a complete control list.

Risk management measures
Incident handling & reporting
Supply-chain security
Business continuity
Governance & accountability
Do it once

Reuse evidence across frameworks

NIS2 shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.

FAQ

Common questions about NIS2

NIS2 expands the sectors and entities in scope, strengthens risk-management and reporting requirements, and adds management accountability.

It is a directive, so each member state transposes it into national law, which can lead to differences in detail.

Yes. Much of NIS2's risk-management expectations overlap with ISO 27001, so evidence can be reused.

Get audit-ready for NIS2

Get a guided demo, or start by scanning any domain for free.