NIS2 Directive

NIS2 is the EU's expanded cybersecurity directive — replacing NIS from October 2024. It brings tens of thousands of new entities into scope, mandates board-level accountability, and sets tight incident reporting timelines (24 hours for early warning).

Who it applies to

Essential and Important entities across 15 sectors, plus certain digital service providers. Applies to organisations with 50+ employees or €10M+ turnover.

How ISO-STANDARD.app helps with NIS2

Pre-loaded NIS2 control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current NIS2 posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to NIS2 clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

NIS2: how to work out if you're in scope

The 15 sectors and the size thresholds — plus the 'critical' carve-outs that bring smaller entities in.

The 15 sectors

Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal/courier services, waste management, chemicals, food, and manufacturing of critical products. If you're upstream or downstream of any of these, you're likely in scope.

Size thresholds

Medium (50+ employees, €10M+ turnover) = Important entity. Large (250+ employees, €50M+ turnover) = Essential entity. Different obligations and supervision regimes apply.

Critical entities regardless of size

Sole providers of essential services, providers where disruption would significantly impact public safety, and any entity the Member State designates. Size doesn't save you.

Cross-border footprint

Main establishment rules apply — you're supervised where your main EU establishment is, but obligations apply across every Member State you operate in.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

The 10 NIS2 security measures explained

Article 21 sets a floor of 10 measures. Every Essential and Important entity must have them.

The list

Risk analysis and information systems security, incident handling, business continuity, supply chain security, network and information system security in acquisition/development/maintenance, policies for assessing effectiveness, cyber hygiene and training, cryptography, HR security/access control/asset management, MFA and secured communications.

Proportionality

Measures scale with the risk. A small municipal water utility isn't held to the same operational depth as a national grid operator — but each must be documented and defensible.

Board accountability

Boards must approve the measures, oversee their implementation, and undergo training themselves. Non-compliance can lead to personal liability for management.

Evidence

Regulators will ask for policies, test results, training records, incident logs and third-party assurance. Have them ready and versioned.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 incident reporting: 24 hours, 72 hours, 1 month

Three deadlines. Miss any and you're non-compliant even if the incident was handled well.

Early warning: 24 hours

Within 24 hours of becoming aware of a significant incident, submit an early warning to your CSIRT/competent authority — including whether malicious action is suspected and if it could have cross-border impact.

Incident notification: 72 hours

Within 72 hours, a fuller notification: initial assessment of severity and impact, indicators of compromise. Update the early warning with what you now know.

Final report: 1 month

Within one month, a detailed final report: root cause, mitigation applied and planned, cross-border impact. This report can be shared across CSIRTs to help other entities defend.

Practise the timings

The only way to hit 24 hours reliably is to have run the drill. Tabletop it quarterly and time yourself.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 supply chain security: what changes

NIS2 makes you responsible for your suppliers' security, not just your own.

Direct suppliers of ICT services

You must assess and manage the cybersecurity risk of direct suppliers — especially ICT and MSP providers. Contracts must reflect this.

Coordinated risk assessments

The Cooperation Group can carry out coordinated Union-level risk assessments of specific critical supply chains. If your supplier lands on the list, you inherit obligations.

Documentation

Keep a register of critical suppliers with their risk assessment outcomes, contractual security commitments, and evidence of ongoing monitoring.

Substitutability

Regulators are increasingly interested in what happens if a critical supplier is compromised. Have an exit plan for the top three.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 management body training obligations

NIS2 is one of the first EU laws to require board members to actually receive cybersecurity training.

What the law says

Members of management bodies must follow training regularly to acquire sufficient knowledge to identify and assess cybersecurity risks and management practices.

Frequency and content

'Regularly' is not defined but a good default is annual. Content should cover risk landscape, own organisation's exposure, and how to challenge management on cyber posture.

Evidence

Attendance records, materials used, and evidence of updates when the threat landscape changes. Regulators will ask.

Beyond the letter

The point is genuine board oversight, not certificate collection. Some boards now dedicate one meeting a year to a scenario exercise led by external counsel.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 registration: who to tell and when

Registration is your first NIS2 obligation. Miss it and you're already non-compliant.

Registration

Essential and Important entities must register with their competent authority: name, address, sector, main services, contact for cybersecurity matters, list of Member States where services are provided.

Updates

Notify any changes to registration details within two weeks — this is not a one-off filing.

Digital infrastructure entities

Cloud, data centre, CDN, DNS and TLD registries have specific registration obligations and shorter timelines. Check the delegated act for your sub-sector.

Cross-border

You register in your main establishment Member State but authorities from other affected Member States can also engage. Nominate a single contact person.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 vs ISO 27001: how to reuse your ISMS

If you have ISO 27001, you're 70% of the way to NIS2 evidence. Here's the crosswalk that saves the most time.

Where they overlap

Risk management, incident handling, business continuity, supply chain, HR security, access control, cryptography, and training all map cleanly. Your Statement of Applicability becomes an evidence pack.

Where NIS2 goes further

Board training obligations, mandatory reporting timelines, cross-border coordination, and personal liability for management. These are process/governance additions, not new technical controls.

A practical mapping

Anchor NIS2 measures to Annex A controls 1:1 where possible. For each NIS2-only requirement, add a control statement with its own evidence trail.

Audit efficiency

Combining ISO 27001 surveillance audits with NIS2 self-assessment saves weeks of effort each year. Use a shared control library.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 fines and enforcement: the numbers

€10M or 2% of global turnover for Essential entities. €7M or 1.4% for Important. Personal liability on top.

The maxima

Essential entities face administrative fines up to €10M or 2% of global annual turnover (whichever is higher). Important entities: €7M or 1.4%. National regimes may add more.

Personal liability

Member States can hold management personally liable — including temporary bans from managerial functions. This is new for cybersecurity law in most jurisdictions.

Supervision differs by tier

Essential entities are supervised proactively (audits, inspections). Important entities are supervised reactively — after an incident or complaint. Both face fines.

Beyond fines

Public naming, mandatory external audit, temporary suspension of authorisations — regulators have a toolkit beyond monetary penalties.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 business continuity: what regulators expect

NIS2 explicitly requires BC and disaster recovery — not just data backup.

Backup and recovery

Not the same thing. Backups without tested restore are not evidence of recovery capability. Test at least annually.

Crisis management

A named crisis team, decision-making authority in a crisis, and communications plans (internal, customer, regulator, media) form the minimum documented shape.

Alternative arrangements

For essential services, you need alternatives that keep the service running — degraded modes, failover sites, manual workarounds.

Exercise and improve

Every exercise produces findings. Track them like corrective actions with owners and dates — regulators want to see improvement over time, not perfect first attempts.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

NIS2 national transposition: what varies

The Directive sets a floor; Member States have added detail. Multi-country operations need a per-country matrix.

Registration portals

Each Member State runs its own registration portal. Some are English-friendly; some are not. Some accept a single group registration; some don't.

Sector-specific supervisors

Finance often falls under the central bank; energy under the energy regulator. Know who your primary supervisor is in each Member State.

Reporting channels

The 24/72/one-month reports may go to different bodies depending on Member State. Have the channel documented and tested before you need it.

National fines

Some Member States have raised the maxima above the Directive floor. Check the specific national law, not just NIS2 itself.

How ISO-STANDARD.app helps with NIS2

Inside the workspace, this topic maps to concrete artefacts: pre-loaded NIS2 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the NIS2 shape.

Ready to evidence NIS2?

Load the pre-mapped controls, capture evidence continuously, and publish your NIS2 posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.