European Union

NIS2 Directive

64 controls. 20 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

64 controls 20 frameworks share controls with it European Union verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

EU NIS2 Directive Evidence & Implementation Kit

64 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
Art.1Subject matter0
Art.10Computer security incident response teams (CSIRTs)0
Art.11Requirements, technical capabilities and tasks of CSIRTs0
Art.12Coordinated vulnerability disclosure and a European vulnerability database0
Art.13Cooperation at national level0
Art.14Cooperation Group0
Art.15CSIRTs network0
Art.16European cyber crisis liaison organisation network (EU-CyCLONe)0
Art.17International cooperation0
Art.18Report on the state of cybersecurity in the Union0
Art.19Peer reviews0
Art.20.1Management body approves the cybersecurity risk-management measures and oversees their implementation18
Art.20.2Train the management body, and offer equivalent training to staff on a regular basis18
Art.21.1Take proportionate all-hazards measures calibrated to the entity's own risk exposure18
Art.21.2.aPolicies on risk analysis and on information system security19
Art.21.2.bIncident handling20
Art.21.2.cBusiness continuity, backup management, disaster recovery and crisis management19
Art.21.2.dSupply chain security, covering the relationship with each direct supplier and service provider19
Art.21.2.eSecurity in acquisition, development and maintenance, including vulnerability handling and disclosure20
Art.21.2.fPolicies and procedures to assess the effectiveness of the cybersecurity risk-management measures20
Art.21.2.gBasic cyber hygiene practices and cybersecurity training19
Art.21.2.hPolicies and procedures on the use of cryptography and, where appropriate, encryption19
Art.21.2.iHuman resources security, access control policies and asset management20
Art.21.2.jMulti-factor or continuous authentication, secured communications and secured emergency communications16
Art.21.3Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments18
Art.21.4Take corrective measures without undue delay on finding that the measures are not met20
Art.22Union level coordinated security risk assessments of critical supply chains0
Art.23.1Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients19
Art.23.2Tell affected service recipients about significant cyber threats and the remedies open to them15
Art.23.4.aSubmit an early warning within 24 hours of becoming aware of a significant incident3
Art.23.4.bSubmit an incident notification within 72 hours, with an initial assessment and indicators of compromise8
Art.23.4.cProvide an intermediate report on status when the CSIRT or competent authority requests one6
Art.23.4.dSubmit a final report within one month, and a progress report where the incident is still running7
Art.24Use certified ICT products, services and processes where the Member State requires it12
Art.25Standardisation0
Art.26Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union6
Art.27Registry of entities0
Art.27.2Submit the ENISA registry information required of digital infrastructure and digital service providers1
Art.28Maintain accurate domain name registration data and answer lawful access requests within 72 hours3
Art.29.4Notify the competent authority of entry into and withdrawal from information-sharing arrangements11
Art.3Essential and important entities0
Art.3.4Submit and maintain entity registration information with the competent authority6
Art.30Voluntary notification of relevant information0
Art.31General aspects concerning supervision and enforcement0
Art.32Cooperate with supervision: inspections, security audits, scans and requests for information and evidence18
Art.33Supervisory and enforcement measures in relation to important entities0
Art.34General conditions for imposing administrative fines0
Art.35Infringements entailing a personal data breach0
Art.36Penalties0
Art.37Mutual assistance0
Art.38Exercise of the delegation0
Art.39Committee procedure0
Art.4Sector-specific Union legal acts0
Art.40Review0
Art.41Transposition0
Art.42Amendment of Regulation (EU) No 910/20140
Art.43Amendment of Directive (EU) 2018/19720
Art.44Repeal0
Art.45Entry into force0
Art.46Addressees0
Art.5Minimum harmonisation0
Art.7National cybersecurity strategy0
Art.8Competent authorities and single points of contact0
Art.9National cyber crisis management frameworks0

Tell me when NIS2 Directive files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Annual review
  • Supplier inventory + classification
  • Risk assessments per supplier
  • Contractual cyber clauses
  • ENISA coordinated risk assessment alignment
  • DORA TPRM cross-walk
  • Annual training records
  • DCMI registration
  • RoPA register
  • Board approval of risk measures

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIS2 Directive, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition