NIS2 Directive Implementing Acts
The NIS2 Directive (EU 2022/2555) Implementing Acts specify detailed cybersecurity risk management measures and significant incident reporting criteria for essential and important entities. The implementing regulation (adopted October 2024) defines technical and methodological requirements for network and information security measures, expanding on the NIS2 Directive's Article 21 risk management obligations. Applicable from October 18, 2024.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Access Control and Authentication
FedRAMP-specific access control and identification/authentication requirements
| Code | Title |
|---|---|
| CJIS-4 | Access Control |
| CJIS-5 | Identification and Authentication |
| CJIS-6 | Account Management |
| FEDRAMP-AC-1 | Access Control Policy and Procedures |
| FEDRAMP-AC-17 | Remote Access |
| FEDRAMP-AC-2 | Account Management |
| FEDRAMP-AC-3 | Access Enforcement |
| FEDRAMP-AC-4 | Information Flow Enforcement |
| FEDRAMP-AC-6 | Least Privilege |
| FEDRAMP-IA-1 | Identification and Authentication Policy |
| FEDRAMP-IA-2 | Identification and Authentication (Organizational Users) |
| FEDRAMP-IA-5 | Authenticator Management |
| FEDRAMP-IA-8 | Identification and Authentication (Non-Organizational Users) |
| ICS-AC-1 | Role-based access control |
| ICS-AC-2 | Authentication mechanisms |
| ICS-AC-3 | Account management |
| ICS-AC-4 | Physical access controls |
| NIS2-IA-11 | Access Control Policy |
| NIS2-IA-12 | Multi-Factor Authentication |
Business Continuity and Crisis Management
| Code | Title |
|---|---|
| NIS2-IA-5 | Business Continuity Management |
| NIS2-IA-6 | Crisis Management Procedures |
Human Resources and Awareness
| Code | Title |
|---|---|
| NIS2-IA-15 | HR Security and Training |
| NIS2-IA-16 | Asset Management |
Incident Handling
| Code | Title |
|---|---|
| NIS2-IA-3 | Incident Handling Policy and Procedures |
| NIS2-IA-4 | Incident Reporting Requirements |
Network Security and Architecture
| Code | Title |
|---|---|
| NIS2-IA-10 | System Acquisition and Development |
| NIS2-IA-9 | Network Security Measures |
Security Policy and Risk Management
| Code | Title |
|---|---|
| NIS2-IA-1 | Policy on Security of Network and Information Systems |
| NIS2-IA-2 | Risk Management Framework |
Supply Chain Security
Customs security and risk management
| Code | Title |
|---|---|
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Vulnerability and Cryptography
| Code | Title |
|---|---|
| NIS2-IA-13 | Vulnerability Management and Disclosure |
| NIS2-IA-14 | Cryptography and Encryption |
Maps to 635 other frameworks
Frequently Asked Questions
What is NIS2 Directive Implementing Acts?
NIS2 Directive Implementing Acts is a compliance framework from European Union with 8 domains and 56 controls. The NIS2 Directive (EU 2022/2555) Implementing Acts specify detailed cybersecurity risk management measures and significant incident reporting criteria for essential and important entities. The implementing regulation (adopted October 2024) defines technical and methodological requirements for network and information security measures, expanding on the NIS2 Directive's Article 21 risk management obligations. Applicable from October 18, 2024. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIS2 Directive Implementing Acts have?
NIS2 Directive Implementing Acts has 56 controls organised across 8 domains. The largest domains are Supply Chain Security (25 controls), Access Control and Authentication (19 controls), Business Continuity and Crisis Management (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIS2 Directive Implementing Acts map to?
NIS2 Directive Implementing Acts maps to 635 other compliance frameworks. The top mapping partners are TISAX — Trusted Information Security Assessment Exchange (50% coverage), South Korea ISMS-P (46% coverage), FedRAMP Rev 5 (46% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIS2 Directive Implementing Acts compliance?
Start your NIS2 Directive Implementing Acts compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIS2 Directive Implementing Acts requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 56 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required