NIS2 Directive
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, covering essential and important entities.
NIS2 Directive is a compliance framework from European Union with 12 domains and 66 controls that map to 20 other frameworks. The largest domains are NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21) (13 controls), NIS2 Chapter I: General Provisions (7 controls), NIS2 Chapter II: Coordinated Cybersecurity Frameworks (7 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
NIS2 Chapter I: General Provisions
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.3.4 | Submit and maintain entity registration information with the competent authority |
NIS2 Chapter II: Coordinated Cybersecurity Frameworks
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.10 | Computer security incident response teams (CSIRTs) |
| nis2-directive::Art.11 | Requirements, technical capabilities and tasks of CSIRTs |
| nis2-directive::Art.12 | Coordinated vulnerability disclosure and a European vulnerability database |
| nis2-directive::Art.13 | Cooperation at national level |
| nis2-directive::Art.7 | National cybersecurity strategy |
| nis2-directive::Art.8 | Competent authorities and single points of contact |
| nis2-directive::Art.9 | National cyber crisis management frameworks |
NIS2 Chapter III: Cooperation at Union and International Level
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.14 | Cooperation Group |
| nis2-directive::Art.15 | CSIRTs network |
| nis2-directive::Art.16 | European cyber crisis liaison organisation network (EU-CyCLONe) |
| nis2-directive::Art.17 | International cooperation |
| nis2-directive::Art.18 | Report on the state of cybersecurity in the Union |
| nis2-directive::Art.19 | Peer reviews |
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.21.1 | Take proportionate all-hazards measures calibrated to the entity's own risk exposure |
| nis2-directive::Art.21.2.a | Policies on risk analysis and on information system security |
| nis2-directive::Art.21.2.b | Incident handling |
| nis2-directive::Art.21.2.c | Business continuity, backup management, disaster recovery and crisis management |
| nis2-directive::Art.21.2.d | Supply chain security, covering the relationship with each direct supplier and service provider |
| nis2-directive::Art.21.2.e | Security in acquisition, development and maintenance, including vulnerability handling and disclosure |
| nis2-directive::Art.21.2.f | Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures |
| nis2-directive::Art.21.2.g | Basic cyber hygiene practices and cybersecurity training |
| nis2-directive::Art.21.2.h | Policies and procedures on the use of cryptography and, where appropriate, encryption |
| nis2-directive::Art.21.2.i | Human resources security, access control policies and asset management |
| nis2-directive::Art.21.2.j | Multi-factor or continuous authentication, secured communications and secured emergency communications |
| nis2-directive::Art.21.3 | Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments |
| nis2-directive::Art.21.4 | Take corrective measures without undue delay on finding that the measures are not met |
NIS2 Chapter IV: Governance (Article 20)
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.20.1 | Management body approves the cybersecurity risk-management measures and oversees their implementation |
| nis2-directive::Art.20.2 | Train the management body, and offer equivalent training to staff on a regular basis |
NIS2 Chapter IV: Incident Reporting (Article 23)
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.23.1 | Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients |
| nis2-directive::Art.23.2 | Tell affected service recipients about significant cyber threats and the remedies open to them |
| nis2-directive::Art.23.4.a | Submit an early warning within 24 hours of becoming aware of a significant incident |
| nis2-directive::Art.23.4.b | Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise |
| nis2-directive::Art.23.4.c | Provide an intermediate report on status when the CSIRT or competent authority requests one |
| nis2-directive::Art.23.4.d | Submit a final report within one month, and a progress report where the incident is still running |
NIS2 Chapter IV: Supply Chain Assessment, Certification and Standardisation (Articles 22, 24, 25)
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.22 | Union level coordinated security risk assessments of critical supply chains |
| nis2-directive::Art.24 | Use certified ICT products, services and processes where the Member State requires it |
| nis2-directive::Art.25 | Standardisation |
NIS2 Chapter IX: Final Provisions
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.40 | Review |
| nis2-directive::Art.41 | Transposition |
| nis2-directive::Art.42 | Amendment of Regulation (EU) No 910/2014 |
| nis2-directive::Art.43 | Amendment of Directive (EU) 2018/1972 |
| nis2-directive::Art.44 | Repeal |
| nis2-directive::Art.45 | Entry into force |
| nis2-directive::Art.46 | Addressees |
NIS2 Chapter V: Jurisdiction and Registration
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.26 | Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union |
| nis2-directive::Art.27.2 | Submit the ENISA registry information required of digital infrastructure and digital service providers |
| nis2-directive::Art.28 | Maintain accurate domain name registration data and answer lawful access requests within 72 hours |
NIS2 Chapter VI: Information Sharing
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.29.4 | Notify the competent authority of entry into and withdrawal from information-sharing arrangements |
| nis2-directive::Art.30 | Voluntary notification of relevant information |
NIS2 Chapter VII: Supervision and Enforcement
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.31 | General aspects concerning supervision and enforcement |
| nis2-directive::Art.32 | Cooperate with supervision: inspections, security audits, scans and requests for information and evidence |
| nis2-directive::Art.33 | Supervisory and enforcement measures in relation to important entities |
| nis2-directive::Art.34 | General conditions for imposing administrative fines |
| nis2-directive::Art.35 | Infringements entailing a personal data breach |
| nis2-directive::Art.36 | Penalties |
| nis2-directive::Art.37 | Mutual assistance |
NIS2 Chapter VIII: Delegated and Implementing Acts
Chapter grouping of Directive (EU) 2022/2555 as modelled 2026-08-20.
| Code | Title |
|---|---|
| nis2-directive::Art.38 | Exercise of the delegation |
| nis2-directive::Art.39 | Committee procedure |
Your Compliance Coverage
If you comply with NIS2 Directive, you already cover:
Maps to 20 other frameworks
What is NIS2 Directive and who does it apply to?
NIS2 Directive is a compliance framework from European Union with 12 domains and 66 controls. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, covering essential and important entities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIS2 Directive actually require?
NIS2 Directive has 66 controls organised across 12 domains. The largest domains are NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21) (13 controls), NIS2 Chapter I: General Provisions (7 controls), NIS2 Chapter II: Coordinated Cybersecurity Frameworks (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIS2 Directive do I already cover?
NIS2 Directive maps to 20 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (93% coverage), C5 (Germany) (93% coverage), ISO 27002:2022 (93% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIS2 Directive?
Start your NIS2 Directive compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIS2 Directive requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 66 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required