NIS2 Directive
NIS2 Chapter IV: Supply Chain Assessment, Certification and Standardisation (Articles 22, 24, 25)

NIS2 Directive Art.24: Use certified ICT products, services and processes where the Member State requires it

A Member State may require essential and important entities to use particular ICT products, ICT services and ICT processes that are certified under a European cybersecurity certification scheme adopted under Article 49 of Regulation (EU) 2019/881, as a way of demonstrating compliance with particular Article 21 requirements. That requirement can arrive either through national transposition or through a Commission delegated act specifying which categories of entity must use certified products or hold a certificate. Member States must also encourage the use of qualified trust services. What binds the entity is therefore conditional and moving: it has to know whether any such requirement applies to it in each Member State whose jurisdiction it falls under, and to hold the conformity evidence where one does. Delegated acts carry an implementation period, so the practical duty is to watch for them rather than to react once the period has run.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 13 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 2 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-SSO-04 Monitoring of compliance with requirements

FedRAMP High · 2 controls

  • SA-4 Acquisition Process
  • SA-4(10) Use of Approved PIV Products

FedRAMP Moderate · 2 controls

  • SA-4 Acquisition Process
  • SA-4(10) Use of Approved PIV Products

EU AI Act · 1 control

ISO 27001:2022 · 1 control

  • 5.31 Legal, statutory, regulatory and contractual requirements

ISO 27002:2022 · 1 control

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • 7.1.c Article 7(1)(c): public institutions and critical infrastructures buy cybersecurity products and services only from Presidency-authorised providers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.24 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.