Directive NIS2 European Union
Directive (EU) 2022/2555

One directive.
Twenty-seven laws.

NIS2 is not a regulation. It sets a floor, and each member state built its own law on top. What binds you is that national text — its authority, its register, its reporting channel. We track all 27, and we sell what you need to comply with yours.

27
Member states
18
Sectors, annexes I & II
~160k
Entities in scope
24h
Early warning deadline
10M€
Maximum fine, art. 34
Article 21(2)

The ten minimum measures


Every entity in scope must implement all ten. They are the baseline the directive sets — national law may add to them, never subtract.

Art. 21(2)(a)

Risk analysis and security policies

Policies on risk analysis and information system security.

Art. 21(2)(b)

Incident handling

Detection, response and recovery — feeding the article 23 reporting chain.

Art. 21(2)(c)

Business continuity

Backup management, disaster recovery and crisis management.

Art. 21(2)(d)

Supply chain security

Security in relationships with direct suppliers and service providers.

Art. 21(2)(e)

Security in acquisition, development and maintenance

Including vulnerability handling and disclosure.

Art. 21(2)(f)

Assessing the effectiveness of the measures

Policies and procedures to assess whether the measures actually work.

Art. 21(2)(g)

Basic cyber hygiene and cybersecurity training

Basic cyber hygiene practices and cybersecurity training.

Art. 21(2)(h)

Cryptography and encryption

Policies on the use of cryptography and, where appropriate, encryption.

Art. 21(2)(i)

Human resources security, access control and asset management

Human resources security, access control policies and asset management.

Art. 21(2)(j)

Multi-factor authentication and secured communications

Multi-factor authentication or continuous authentication, secured voice, video and text, and secured emergency communication systems.

How to evidence each measure →

Article 23

The reporting clock starts on awareness


24h

Early warning

Indicate whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact.

72h

Incident notification

Update the early warning with an initial assessment, severity, impact and, where available, indicators of compromise.

1month

Final report

Detailed description, threat type, root cause, applied mitigations and any cross-border impact.

Art. 23(1)
Each Member State shall ensure that essential and important entities notify […] without undue delay any incident that has a significant impact on the provision of their services.
Directive (EU) 2022/2555

The full reporting chain →

Products

Start from a document, not a blank page


Best value

Complete Assessment Toolkit Bundle

All five assessment toolkits: risk analysis, incident handling, continuity, supply chain, and access control with MFA.

249 € excl. VAT

Value if bought separately: 395 €

Most popular

NIS2 Complete Implementation Library

Every premium document: policies, board pack, incident templates and gap analysis workbook.

199 € excl. VAT

Value if bought separately: 266 €

Germany Transposition Pack (NIS2UmsuCG)

How NIS2 actually applies in Germany: the BSI as competent authority, registration duties, and where German law goes beyond the directive.

129 € excl. VAT

Browse the catalogue →

Cart 0