NIS2¶

Directive (EU) 2022/2555: cybersecurity obligations for essential and important entities across 18 sectors. Article 41(1) required member states to adopt and publish their transposing measures by 17 October 2024 and to apply those measures from 18 October 2024. The directive does not bind entities directly — your obligations arise under national law, so in a member state that is late, what applies to you is a question about that state's law and not about the directive. Directive (EU) 2016/1148 (NIS1) was repealed with effect from 18 October 2024. National implementations differ, so always check your own.
Planned branches¶
| Area | Planned artefacts |
|---|---|
| Scoping | Am-I-in-scope checklist (essential vs. important entity) |
| Governance (Art. 20) | Management-body accountability matrix |
| Risk-management measures (Art. 21) | The ten measures mapped to concrete controls and documents |
| Supply chain security (Art. 21(2)(d)) | Supplier and third-party risk register — built, with intake form, tiering, stop signals and sanctions screening |
| Coordinated supply chain assessments (Art. 22) | Supplier assessment record |
| Incident notification (Art. 23) | 24h / 72h / one-month reporting timeline reference |
| Certification and standards (Art. 24 to 25) | Standards mapping template |
| Voluntary notification (Art. 30) | Voluntary notification record |
Under construction
Only the supply chain row is built so far. The rest of the table is planned. New artefacts are announced on the blog.
From my library¶
Links from my reading library that help with NIS2 work.
NIS2 posture management (open source)
Open-source platform for tracking NIS2 posture and remediation. Worth a look for how it turns the directive into checkable controls.
enisa.europa.euENISA NIS2 technical implementation guidance
Version 1.0, June 2025. Works through the requirements of Implementing Regulation (EU) 2024/2690 for digital infrastructure, ICT service management and digital providers, with evidence examples and a mapping table. The closest thing to an official control list.
ecs-org.euECSO
The European Cyber Security Organisation. Useful for following the policy side and finding European security vendors and initiatives.
Primary sources¶
- Directive (EU) 2022/2555 on EUR-Lex
- ENISA implementation guidance (linked per artefact)