OnwynStandards › NIS2 Directive (EU 2022/2555)

Regulation · 2023

NIS2 Directive (EU 2022/2555)

NIS2 is the EU's cybersecurity law for essential and important entities — energy, transport, health, digital infrastructure, manufacturing, digital providers, and more, generally from 50 employees or EUR 10M turnover in the listed sectors. It makes management personally accountable for cybersecurity, mandates a minimum set of risk-management measures, and imposes strict incident reporting deadlines (24 hours, 72 hours, one month). Member states transpose it into national law (e.g. the German NIS2UmsuCG), which is where fines and supervision are anchored.

21
Requirements
6
Areas
16
Recommended documents
2
Mapped frameworks
Start NIS2 Directive free Have us do it instead

What this standard asks for

Every requirement in NIS2 Directive (EU 2022/2555), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Governance & accountability

3 requirements

  • 20.1Management approval and oversight of cybersecurity measures
  • 20.2Cybersecurity training for management
  • 21.4Corrective action on non-compliance

Risk management

3 requirements

  • 21.1Appropriate and proportionate risk-management measures
  • 21.2.aRisk analysis and information system security policies
  • 21.2.fAssessing the effectiveness of measures

Incident handling & reporting

5 requirements

  • 21.2.bIncident handling
  • 23.1Duty to notify significant incidents and affected recipients
  • 23.4.aEarly warning within 24 hours
  • 23.4.bIncident notification within 72 hours
  • 23.4.dFinal report within one month

Business continuity

2 requirements

  • 21.2.cBusiness continuity, backup and crisis management
  • 21.2.c-bcmContinuity plans tested against realistic scenarios

Supply chain security

2 requirements

  • 21.2.dSupply chain security
  • 22Account for coordinated supply chain risk assessments

Technical & operational measures

6 requirements

  • 21.2.eSecurity in acquisition, development and maintenance, including vulnerability handling
  • 21.2.gCyber hygiene and security training
  • 21.2.hCryptography and encryption
  • 21.2.iHuman resources security, access control and asset management
  • 21.2.jMulti-factor and continuous authentication
  • 21.2.j-commsSecured communications, including emergency communication

The documents you will end up with

The recommended document set for NIS2 Directive (EU 2022/2555) — 16 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Information System Security Policy

The top-level security policy and the risk analysis behind it — the first measure Article 21 names.

Risk Management Procedure

How security risks are identified, scored and treated in proportion to your size and exposure, and how you check the measures are working.

Management Approval and Oversight Record

Evidence that the management body approved the security measures and reviews them — the personal accountability NIS2 puts on directors.

Management Training Plan

The cybersecurity training the management body receives, and the record that they attended.

Corrective Action Procedure

What happens when a gap is found: how it is recorded, fixed, and reported upward.

Incident Handling Procedure

How incidents are detected, triaged, contained and closed, and who is on call.

Incident Notification Procedure

The 24-hour early warning, the 72-hour notification and the one-month final report: who decides an incident is significant, who files, and what goes in each.

Business Continuity, Backup and Crisis Management Plan

How the entity keeps operating and recovers when something significant breaks, including backups and who runs the crisis.

Continuity Exercise Programme

The schedule of realistic scenario exercises, what each is meant to prove, and what was learned.

Supply Chain Security Policy

The security you require from direct suppliers and service providers, how it is checked, and how you take account of coordinated EU-level risk assessments.

Secure Acquisition, Development and Vulnerability Policy

Security requirements when you buy or build systems, and how vulnerabilities in them are found, disclosed and fixed.

Cyber Hygiene and Awareness Plan

The basics everyone is expected to follow — updates, passwords, phishing, device rules — and the training that makes them stick.

Cryptography and Encryption Policy

Where encryption is mandatory, which algorithms are acceptable, and how keys are managed.

HR Security, Access Control and Asset Policy

Security in hiring and leaving, who gets access to what, and how you track the assets that matter.

Authentication Standard

Where multi-factor authentication is required and what continuous authentication you apply to sensitive access.

Secured Communications Plan

How voice, video and text communications are protected, and which channel the crisis team uses when the normal ones are down.

Work that counts twice

NIS2 Directive (EU 2022/2555) overlaps with 2 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start NIS2 Directive today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.