Skip to content

NIS2

Miniature hospital, power station, water tower, transport depot and data centre wired by cable-bridges into a central control tower

Directive (EU) 2022/2555: cybersecurity obligations for essential and important entities across 18 sectors. Article 41(1) required member states to adopt and publish their transposing measures by 17 October 2024 and to apply those measures from 18 October 2024. The directive does not bind entities directly — your obligations arise under national law, so in a member state that is late, what applies to you is a question about that state's law and not about the directive. Directive (EU) 2016/1148 (NIS1) was repealed with effect from 18 October 2024. National implementations differ, so always check your own.

Planned branches

Area Planned artefacts
Scoping Am-I-in-scope checklist (essential vs. important entity)
Governance (Art. 20) Management-body accountability matrix
Risk-management measures (Art. 21) The ten measures mapped to concrete controls and documents
Supply chain security (Art. 21(2)(d)) Supplier and third-party risk register — built, with intake form, tiering, stop signals and sanctions screening
Coordinated supply chain assessments (Art. 22) Supplier assessment record
Incident notification (Art. 23) 24h / 72h / one-month reporting timeline reference
Certification and standards (Art. 24 to 25) Standards mapping template
Voluntary notification (Art. 30) Voluntary notification record

Under construction

Only the supply chain row is built so far. The rest of the table is planned. New artefacts are announced on the blog.

From my library

Links from my reading library that help with NIS2 work.

Primary sources