NIS2 Directive Implementing Acts
The NIS2 Directive (EU 2022/2555) Implementing Acts specify detailed cybersecurity risk management measures and significant incident reporting criteria for essential and important entities. The implementing regulation (adopted October 2024) defines technical and methodological requirements for network and information security measures, expanding on the NIS2 Directive's Article 21 risk management obligations. Applicable from October 18, 2024.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Access and Assets
| Code | Title |
|---|---|
| NIS2I-6 | Access Control, Asset Management, and Physical Security |
Governance and Risk
| Code | Title |
|---|---|
| NIS2I-2 | Policy, Risk Management, and Roles + Responsibilities |
Incident Response and Continuity
| Code | Title |
|---|---|
| NIS2I-3 | Incident Handling Policy, Reporting Significance Criteria, and Business Continuity |
Network and Monitoring
| Code | Title |
|---|---|
| NIS2I-7 | Network Security, Logging, Monitoring, and Vulnerability Handling |
Personnel and Cryptography
| Code | Title |
|---|---|
| NIS2I-5 | Cyber Hygiene, Training, Cryptography, and Human Resources Security |
Regulatory Framework
| Code | Title |
|---|---|
| NIS2I-1 | Implementing Regulation 2024/2690 Scope, Annex I Measures, and ENISA Technical Guidance |
Sector-Specific
| Code | Title |
|---|---|
| NIS2I-8 | Sector-Specific Requirements - Cloud Providers and Managed Service Providers (Articles 7, 10) |
Supply Chain and Development
| Code | Title |
|---|---|
| NIS2I-4 | Supply Chain Security, Acquisition Development, and Effectiveness Assessment |
Your Compliance Coverage
If you comply with NIS2 Directive Implementing Acts, you already cover:
OWASP Top 10:2025
50%
4 controls mapped
Compare →OWASP MASVS
50%
4 controls mapped
Compare →OWASP ASVS
50%
4 controls mapped
Compare →+ 158 more: ISO/IEC 27011:2024 (50%), NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) (50%)
See all 161 mapped frameworks ↓Maps to 161 other frameworks
Frequently Asked Questions
What is NIS2 Directive Implementing Acts?
NIS2 Directive Implementing Acts is a compliance framework from European Union with 8 domains and 8 controls. The NIS2 Directive (EU 2022/2555) Implementing Acts specify detailed cybersecurity risk management measures and significant incident reporting criteria for essential and important entities. The implementing regulation (adopted October 2024) defines technical and methodological requirements for network and information security measures, expanding on the NIS2 Directive's Article 21 risk management obligations. Applicable from October 18, 2024. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIS2 Directive Implementing Acts have?
NIS2 Directive Implementing Acts has 8 controls organised across 8 domains. The largest domains are Access and Assets (1 controls), Governance and Risk (1 controls), Incident Response and Continuity (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIS2 Directive Implementing Acts map to?
NIS2 Directive Implementing Acts maps to 161 other compliance frameworks. The top mapping partners are OWASP Top 10:2025 (50% coverage), OWASP MASVS (50% coverage), OWASP ASVS (50% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIS2 Directive Implementing Acts compliance?
Start your NIS2 Directive Implementing Acts compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIS2 Directive Implementing Acts requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required