NIS2 Directive compliance guide
A practical read of Directive (EU) 2022/2555: who is in scope, what Article 21 actually requires, how the 24/72-hour reporting clock works, and how to prove it.
A practical read of Directive (EU) 2022/2555: who is in scope, what Article 21 actually requires, how the 24/72-hour reporting clock works, and how to prove it.
NIS2 applies to essential entities (Annex I: energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration, space) and important entities (Annex II: postal, waste, chemicals, food, manufacturing, digital providers, research) (European Parliament and Council, 2022).
The size-cap rule generally excludes micro and small enterprises, but critical entities (DNS, TLD registries, trust service providers, public administration) are in scope regardless of size (Art. 2(2)).
Each measure maps to controls in ISO/IEC 27001:2022 Annex A, but NIS2 additionally requires the management body to approve and oversee them (Art. 20).
NIS2 is not a management system standard — it's a directive that expects a management system to exist. Running ISO 27001 in the same workspace collapses the evidence burden.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.