Back to Frameworks

NIS2 Directive

European Union
v2022/2555 (Directive (EU) 2022/2555)
12 domains
66 controls

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, covering essential and important entities.

Verified

NIS2 Directive is a compliance framework from European Union with 12 domains and 66 controls that map to 20 other frameworks. The largest domains are NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21) (13 controls), NIS2 Chapter I: General Provisions (7 controls), NIS2 Chapter II: Coordinated Cybersecurity Frameworks (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (12)

NIS2 Chapter I: General Provisions

7 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter I: General Provisions domain of NIS2 Directive1 controls
CodeTitle
nis2-directive::Art.3.4Submit and maintain entity registration information with the competent authority

NIS2 Chapter II: Coordinated Cybersecurity Frameworks

7 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter II: Coordinated Cybersecurity Frameworks domain of NIS2 Directive7 controls
CodeTitle
nis2-directive::Art.10Computer security incident response teams (CSIRTs)
nis2-directive::Art.11Requirements, technical capabilities and tasks of CSIRTs
nis2-directive::Art.12Coordinated vulnerability disclosure and a European vulnerability database
nis2-directive::Art.13Cooperation at national level
nis2-directive::Art.7National cybersecurity strategy
nis2-directive::Art.8Competent authorities and single points of contact
nis2-directive::Art.9National cyber crisis management frameworks

NIS2 Chapter III: Cooperation at Union and International Level

6 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter III: Cooperation at Union and International Level domain of NIS2 Directive6 controls
CodeTitle
nis2-directive::Art.14Cooperation Group
nis2-directive::Art.15CSIRTs network
nis2-directive::Art.16European cyber crisis liaison organisation network (EU-CyCLONe)
nis2-directive::Art.17International cooperation
nis2-directive::Art.18Report on the state of cybersecurity in the Union
nis2-directive::Art.19Peer reviews

NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

13 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21) domain of NIS2 Directive13 controls
CodeTitle
nis2-directive::Art.21.1Take proportionate all-hazards measures calibrated to the entity's own risk exposure
nis2-directive::Art.21.2.aPolicies on risk analysis and on information system security
nis2-directive::Art.21.2.bIncident handling
nis2-directive::Art.21.2.cBusiness continuity, backup management, disaster recovery and crisis management
nis2-directive::Art.21.2.dSupply chain security, covering the relationship with each direct supplier and service provider
nis2-directive::Art.21.2.eSecurity in acquisition, development and maintenance, including vulnerability handling and disclosure
nis2-directive::Art.21.2.fPolicies and procedures to assess the effectiveness of the cybersecurity risk-management measures
nis2-directive::Art.21.2.gBasic cyber hygiene practices and cybersecurity training
nis2-directive::Art.21.2.hPolicies and procedures on the use of cryptography and, where appropriate, encryption
nis2-directive::Art.21.2.iHuman resources security, access control policies and asset management
nis2-directive::Art.21.2.jMulti-factor or continuous authentication, secured communications and secured emergency communications
nis2-directive::Art.21.3Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
nis2-directive::Art.21.4Take corrective measures without undue delay on finding that the measures are not met

NIS2 Chapter IV: Governance (Article 20)

2 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter IV: Governance (Article 20) domain of NIS2 Directive2 controls
CodeTitle
nis2-directive::Art.20.1Management body approves the cybersecurity risk-management measures and oversees their implementation
nis2-directive::Art.20.2Train the management body, and offer equivalent training to staff on a regular basis

NIS2 Chapter IV: Incident Reporting (Article 23)

6 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter IV: Incident Reporting (Article 23) domain of NIS2 Directive6 controls
CodeTitle
nis2-directive::Art.23.1Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
nis2-directive::Art.23.2Tell affected service recipients about significant cyber threats and the remedies open to them
nis2-directive::Art.23.4.aSubmit an early warning within 24 hours of becoming aware of a significant incident
nis2-directive::Art.23.4.bSubmit an incident notification within 72 hours, with an initial assessment and indicators of compromise
nis2-directive::Art.23.4.cProvide an intermediate report on status when the CSIRT or competent authority requests one
nis2-directive::Art.23.4.dSubmit a final report within one month, and a progress report where the incident is still running

NIS2 Chapter IV: Supply Chain Assessment, Certification and Standardisation (Articles 22, 24, 25)

3 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter IV: Supply Chain Assessment, Certification and Standardisation (Articles 22, 24, 25) domain of NIS2 Directive3 controls
CodeTitle
nis2-directive::Art.22Union level coordinated security risk assessments of critical supply chains
nis2-directive::Art.24Use certified ICT products, services and processes where the Member State requires it
nis2-directive::Art.25Standardisation

NIS2 Chapter IX: Final Provisions

7 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter IX: Final Provisions domain of NIS2 Directive7 controls
CodeTitle
nis2-directive::Art.40Review
nis2-directive::Art.41Transposition
nis2-directive::Art.42Amendment of Regulation (EU) No 910/2014
nis2-directive::Art.43Amendment of Directive (EU) 2018/1972
nis2-directive::Art.44Repeal
nis2-directive::Art.45Entry into force
nis2-directive::Art.46Addressees

NIS2 Chapter V: Jurisdiction and Registration

4 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter V: Jurisdiction and Registration domain of NIS2 Directive3 controls
CodeTitle
nis2-directive::Art.26Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union
nis2-directive::Art.27.2Submit the ENISA registry information required of digital infrastructure and digital service providers
nis2-directive::Art.28Maintain accurate domain name registration data and answer lawful access requests within 72 hours

NIS2 Chapter VI: Information Sharing

2 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter VI: Information Sharing domain of NIS2 Directive2 controls
CodeTitle
nis2-directive::Art.29.4Notify the competent authority of entry into and withdrawal from information-sharing arrangements
nis2-directive::Art.30Voluntary notification of relevant information

NIS2 Chapter VII: Supervision and Enforcement

7 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter VII: Supervision and Enforcement domain of NIS2 Directive7 controls
CodeTitle
nis2-directive::Art.31General aspects concerning supervision and enforcement
nis2-directive::Art.32Cooperate with supervision: inspections, security audits, scans and requests for information and evidence
nis2-directive::Art.33Supervisory and enforcement measures in relation to important entities
nis2-directive::Art.34General conditions for imposing administrative fines
nis2-directive::Art.35Infringements entailing a personal data breach
nis2-directive::Art.36Penalties
nis2-directive::Art.37Mutual assistance

NIS2 Chapter VIII: Delegated and Implementing Acts

2 controls

Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.

Controls in the NIS2 Chapter VIII: Delegated and Implementing Acts domain of NIS2 Directive2 controls
CodeTitle
nis2-directive::Art.38Exercise of the delegation
nis2-directive::Art.39Committee procedure

Maps to 20 other frameworks

28 total controls
NIST Cybersecurity Framework 2.0
26 source controls mapped|101 target controls covered
93%
C5 (Germany)
26 source controls mapped|89 target controls covered
93%
ISO 27002:2022
26 source controls mapped|63 target controls covered
93%
ISO 27001:2022
26 source controls mapped|62 target controls covered
93%
DORA
24 source controls mapped|24 target controls covered
86%
FedRAMP High
20 source controls mapped|54 target controls covered
71%
FedRAMP Moderate
20 source controls mapped|54 target controls covered
71%
NIST SP 800-53 Rev 5 MODERATE
20 source controls mapped|44 target controls covered
71%
NIST SP 800-53 Revision 5.1 HIGH
20 source controls mapped|44 target controls covered
71%
NIST SP 800-53 Rev 5
20 source controls mapped|56 target controls covered
71%
APRA CPS 234
20 source controls mapped|24 target controls covered
71%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
19 source controls mapped|51 target controls covered
68%
NIST SP 800-171 Rev 3
18 source controls mapped|37 target controls covered
64%
NIST SP 800-53 Rev 5 LOW
18 source controls mapped|36 target controls covered
64%
CMMC 2.0
17 source controls mapped|31 target controls covered
61%
PCI DSS 4.0
17 source controls mapped|48 target controls covered
61%
SOC 2
17 source controls mapped|33 target controls covered
61%
GDPR
16 source controls mapped|12 target controls covered
57%
EU AI Act
14 source controls mapped|12 target controls covered
50%
CIS Controls v8
13 source controls mapped|43 target controls covered
46%

What is NIS2 Directive and who does it apply to?

NIS2 Directive is a compliance framework from European Union with 12 domains and 66 controls. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, covering essential and important entities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIS2 Directive actually require?

NIS2 Directive has 66 controls organised across 12 domains. The largest domains are NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21) (13 controls), NIS2 Chapter I: General Provisions (7 controls), NIS2 Chapter II: Coordinated Cybersecurity Frameworks (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIS2 Directive do I already cover?

NIS2 Directive maps to 20 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (93% coverage), C5 (Germany) (93% coverage), ISO 27002:2022 (93% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIS2 Directive?

Start your NIS2 Directive compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIS2 Directive requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 66 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required