Onwyn › Standards › NIS2 Directive (EU 2022/2555)
Regulation · 2023NIS2 Directive (EU 2022/2555)
NIS2 is the EU's cybersecurity law for essential and important entities — energy, transport, health, digital infrastructure, manufacturing, digital providers, and more, generally from 50 employees or EUR 10M turnover in the listed sectors. It makes management personally accountable for cybersecurity, mandates a minimum set of risk-management measures, and imposes strict incident reporting deadlines (24 hours, 72 hours, one month). Member states transpose it into national law (e.g. the German NIS2UmsuCG), which is where fines and supervision are anchored.
What this standard asks for
Every requirement in NIS2 Directive (EU 2022/2555), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
Governance & accountability
3 requirements
- 20.1Management approval and oversight of cybersecurity measures
- 20.2Cybersecurity training for management
- 21.4Corrective action on non-compliance
Risk management
3 requirements
- 21.1Appropriate and proportionate risk-management measures
- 21.2.aRisk analysis and information system security policies
- 21.2.fAssessing the effectiveness of measures
Incident handling & reporting
5 requirements
- 21.2.bIncident handling
- 23.1Duty to notify significant incidents and affected recipients
- 23.4.aEarly warning within 24 hours
- 23.4.bIncident notification within 72 hours
- 23.4.dFinal report within one month
Business continuity
2 requirements
- 21.2.cBusiness continuity, backup and crisis management
- 21.2.c-bcmContinuity plans tested against realistic scenarios
Supply chain security
2 requirements
- 21.2.dSupply chain security
- 22Account for coordinated supply chain risk assessments
Technical & operational measures
6 requirements
- 21.2.eSecurity in acquisition, development and maintenance, including vulnerability handling
- 21.2.gCyber hygiene and security training
- 21.2.hCryptography and encryption
- 21.2.iHuman resources security, access control and asset management
- 21.2.jMulti-factor and continuous authentication
- 21.2.j-commsSecured communications, including emergency communication
The documents you will end up with
The recommended document set for NIS2 Directive (EU 2022/2555) — 16 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The top-level security policy and the risk analysis behind it — the first measure Article 21 names.
How security risks are identified, scored and treated in proportion to your size and exposure, and how you check the measures are working.
Evidence that the management body approved the security measures and reviews them — the personal accountability NIS2 puts on directors.
The cybersecurity training the management body receives, and the record that they attended.
What happens when a gap is found: how it is recorded, fixed, and reported upward.
How incidents are detected, triaged, contained and closed, and who is on call.
The 24-hour early warning, the 72-hour notification and the one-month final report: who decides an incident is significant, who files, and what goes in each.
How the entity keeps operating and recovers when something significant breaks, including backups and who runs the crisis.
The schedule of realistic scenario exercises, what each is meant to prove, and what was learned.
The security you require from direct suppliers and service providers, how it is checked, and how you take account of coordinated EU-level risk assessments.
Security requirements when you buy or build systems, and how vulnerabilities in them are found, disclosed and fixed.
The basics everyone is expected to follow — updates, passwords, phishing, device rules — and the training that makes them stick.
Where encryption is mandatory, which algorithms are acceptable, and how keys are managed.
Security in hiring and leaving, who gets access to what, and how you track the assets that matter.
Where multi-factor authentication is required and what continuous authentication you apply to sensitive access.
How voice, video and text communications are protected, and which channel the crisis team uses when the normal ones are down.
Work that counts twice
NIS2 Directive (EU 2022/2555) overlaps with 2 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.
Start NIS2 Directive today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.