NIS2 Directive Implementing Acts
The NIS2 Directive (EU 2022/2555) Implementing Acts specify detailed cybersecurity risk management measures and significant incident reporting criteria for essential and important entities. The implementing regulation (adopted October 2024) defines technical and methodological requirements for network and information security measures, expanding on the NIS2 Directive's Article 21 risk management obligations. Applicable from October 18, 2024.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Access Control and Authentication
FedRAMP-specific access control and identification/authentication requirements
| Code | Title |
|---|---|
| CJIS-4 | Access Control |
| CJIS-5 | Identification and Authentication |
| CJIS-6 | Account Management |
| FEDRAMP-AC-1 | Access Control Policy and Procedures |
| FEDRAMP-AC-17 | Remote Access |
| FEDRAMP-AC-2 | Account Management |
| FEDRAMP-AC-3 | Access Enforcement |
| FEDRAMP-AC-4 | Information Flow Enforcement |
| FEDRAMP-AC-6 | Least Privilege |
| FEDRAMP-IA-1 | Identification and Authentication Policy |
| FEDRAMP-IA-2 | Identification and Authentication (Organizational Users) |
| FEDRAMP-IA-5 | Authenticator Management |
| FEDRAMP-IA-8 | Identification and Authentication (Non-Organizational Users) |
| ICS-AC-1 | Role-based access control |
| ICS-AC-2 | Authentication mechanisms |
| ICS-AC-3 | Account management |
| ICS-AC-4 | Physical access controls |
| NIS2-IA-11 | Access Control Policy |
| NIS2-IA-12 | Multi-Factor Authentication |
Business Continuity and Crisis Management
| Code | Title |
|---|---|
| NIS2-IA-5 | Business Continuity Management |
| NIS2-IA-6 | Crisis Management Procedures |
Human Resources and Awareness
| Code | Title |
|---|---|
| NIS2-IA-15 | HR Security and Training |
| NIS2-IA-16 | Asset Management |
Incident Handling
| Code | Title |
|---|---|
| NIS2-IA-3 | Incident Handling Policy and Procedures |
| NIS2-IA-4 | Incident Reporting Requirements |
Network Security and Architecture
| Code | Title |
|---|---|
| NIS2-IA-10 | System Acquisition and Development |
| NIS2-IA-9 | Network Security Measures |
Security Policy and Risk Management
| Code | Title |
|---|---|
| NIS2-IA-1 | Policy on Security of Network and Information Systems |
| NIS2-IA-2 | Risk Management Framework |
Supply Chain Security
Customs security and risk management
| Code | Title |
|---|---|
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Vulnerability and Cryptography
| Code | Title |
|---|---|
| NIS2-IA-13 | Vulnerability Management and Disclosure |
| NIS2-IA-14 | Cryptography and Encryption |
Your Compliance Coverage
If you comply with NIS2 Directive Implementing Acts, you already cover:
TISAX — Trusted Information Security Assessment Exchange
50%
28 controls mapped
Compare →South Korea ISMS-P
46%
26 controls mapped
Compare →FedRAMP Rev 5
46%
26 controls mapped
Compare →+ 632 more: FAA Cybersecurity Framework for Aviation (46%), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (45%)
See all 635 mapped frameworks ↓Maps to 635 other frameworks
Frequently Asked Questions
What is NIS2 Directive Implementing Acts?
NIS2 Directive Implementing Acts is a compliance framework from European Union with 8 domains and 56 controls. The NIS2 Directive (EU 2022/2555) Implementing Acts specify detailed cybersecurity risk management measures and significant incident reporting criteria for essential and important entities. The implementing regulation (adopted October 2024) defines technical and methodological requirements for network and information security measures, expanding on the NIS2 Directive's Article 21 risk management obligations. Applicable from October 18, 2024. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIS2 Directive Implementing Acts have?
NIS2 Directive Implementing Acts has 56 controls organised across 8 domains. The largest domains are Supply Chain Security (25 controls), Access Control and Authentication (19 controls), Business Continuity and Crisis Management (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIS2 Directive Implementing Acts map to?
NIS2 Directive Implementing Acts maps to 635 other compliance frameworks. The top mapping partners are TISAX — Trusted Information Security Assessment Exchange (50% coverage), South Korea ISMS-P (46% coverage), FedRAMP Rev 5 (46% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIS2 Directive Implementing Acts compliance?
Start your NIS2 Directive Implementing Acts compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIS2 Directive Implementing Acts requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 56 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 693 frameworks.
Get Started Free →Free forever — no credit card required