Directive · Cybersecurity · European Union

NIS2 compliance: scope, the 10 security measures and incident reporting

NIS2 compliance means meeting the EU cybersecurity directive as your country has transposed it. Medium and large entities in 18 sectors must apply ten risk-management measures, have management approve and oversee them, and report significant incidents within 24 hours, 72 hours and one month.

Key takeaways

What you need to know about NIS2

National lawsYou comply with your country's NIS2 law, so details differ by member state.
Size mattersMedium and large entities in listed sectors are in scope, with some exceptions.
Management liableBoards approve and oversee the measures and must be trained.
Supply chainSupplier security is one of the ten measures, so vendors feel NIS2 too.
Fast reportingThe early warning is due within 24 hours.

Who must comply with NIS2?

NIS2 applies through national laws to entities in listed sectors that meet the size cap.

Digital infrastructureCloud, data centres, DNS, CDNs and trust services.
ICT service managementManaged service and managed security service providers.
Critical servicesEnergy, transport, health, water, banking and public administration.
ManufacturersMakers of critical products such as medical devices, electronics and vehicles.
Digital providersOnline marketplaces, search engines and social networks.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the law requires

What does NIS2 require?

NIS2 requires in-scope entities to apply ten cybersecurity risk-management measures, have their management body approve and oversee them, register with authorities, and report significant incidents on a fixed timeline.

Art. 2–3 Scope

Essential and important entities

Sector plus size decides status and supervision.

In QULDEX: Scoping per legal entity
Art. 20 Govern

Management accountability

Approve, oversee, train; personal liability.

In QULDEX: Board approvals tracked
Art. 21 Protect

Ten security measures

Risk, incidents, continuity, supply chain, crypto, MFA and more.

In QULDEX: Measures mapped to ISO 27001
Art. 23 Report

Incident reporting

24-hour warning, 72-hour notification, one-month report.

In QULDEX: Timers on every incident
Art. 27 Register

Registration

Entity details to the national authority.

In QULDEX: Registration tracked
Art. 34 Enforce

Fines

At least up to €10m or 2% for essential entities.

In QULDEX: Supervision readiness
Article explorer

Which NIS2 articles matter most?

These 23 provisions carry the obligations most entities work on, grouped by theme. Select any one to see what it requires, typical evidence and the matching ISO 27001 or DORA reference.

Jan 2023NIS2 in force
Oct 2024transposition deadline
Dec 2025Germany's law in force
Jan 2026amendments proposed

Showing up to 6 per group. Search, filter, or open a group to see all 23.

Scope 5

  1. Art. 2Scope and size cap

    Applies to medium and large entities in Annex I and II sectors, and to some entities regardless of size, such as DNS and trust service providers.

    In QULDEXEach legal entity records its sector, size and status.

    Typical evidence
    Scoping record

  2. Art. 3Essential and important entities

    Entities are essential or important depending on sector and size; essential entities face proactive supervision.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Classification record

  3. Annex ISectors of high criticality

    Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

  4. Annex IIOther critical sectors

    Postal services, waste management, chemicals, food, manufacturing of critical products, digital providers and research.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

  5. Art. 3(4)Registration with authoritiesRegister

    Entities provide their details to national authorities; digital infrastructure providers register with the single point of contact.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Registration confirmation

Governance 2

  1. Art. 20(1)Management body approval and oversight

    Management bodies approve the cybersecurity risk-management measures, oversee them and can be held liable for breaches.

    In QULDEXApprovals and oversight reviews are recorded per entity.

    Typical evidence
    Board approvals
    Maps to
    DORA Art. 5ISO 27001 5.1

  2. Art. 20(2)Management training

    Members of management bodies must follow training, and staff should be offered similar training regularly.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Training records
    Maps to
    ISO 27001 A.6.3

Security measures 10

  1. Art. 21(2)(a)Risk analysis and security policies

    Policies on risk analysis and information system security.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Risk assessment, policies
    Maps to
    ISO 27001 6.1A.5.1

  2. Art. 21(2)(b)Incident handling

    Processes to prevent, detect and respond to incidents.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Incident procedure
    Maps to
    ISO 27001 A.5.24–A.5.26

  3. Art. 21(2)(c)Business continuity and crisis management

    Backup management, disaster recovery and crisis management.

    In QULDEXContinuity evidence is reused from ISO 22301.

    Typical evidence
    BCP, DR tests
    Maps to
    ISO 22301ISO 27001 A.5.30

  4. Art. 21(2)(d)Supply chain security

    Security of relationships with direct suppliers and service providers.

    In QULDEXSuppliers are assessed and linked to the services they support.

    Typical evidence
    Supplier assessments
    Maps to
    ISO 27001 A.5.19–A.5.22DORA Art. 28

  5. Art. 21(2)(e)Secure acquisition, development and maintenance

    Security in acquisition, development and maintenance, including vulnerability handling and disclosure.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    SDLC policy, vulnerability log
    Maps to
    ISO 27001 A.8.8A.8.25

  6. Art. 21(2)(f)Assessing effectiveness

    Policies and procedures to assess whether measures work.

    In QULDEXControl tests run on a schedule with results.

    Typical evidence
    Control test results
    Maps to
    ISO 27001 9.1

  7. Art. 21(2)(g)Cyber hygiene and training

    Basic cyber hygiene practices and cybersecurity training.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Awareness records
    Maps to
    ISO 27001 A.6.3

  8. Art. 21(2)(h)Cryptography and encryption

    Policies on cryptography and, where appropriate, encryption.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Crypto policy
    Maps to
    ISO 27001 A.8.24

  9. Art. 21(2)(i)HR security, access control and assets

    Human resources security, access control policies and asset management.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Access reviews, asset inventory
    Maps to
    ISO 27001 A.5.9A.5.15

  10. Art. 21(2)(j)MFA and secured communications

    Multi-factor or continuous authentication, secured voice, video and text, and emergency communications.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    MFA settings
    Maps to
    ISO 27001 A.8.5

Incident reporting 4

  1. Art. 23(4)(a)Early warning within 24 hours

    Send an early warning to the CSIRT or authority within 24 hours of becoming aware of a significant incident.

    In QULDEXEach significant incident starts 24-hour, 72-hour and one-month timers.

    Typical evidence
    Early warning record
    Maps to
    DORA Art. 19

  2. Art. 23(4)(b)Incident notification within 72 hours

    Update the early warning with an initial assessment of severity, impact and indicators of compromise.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

    Typical evidence
    Notification

  3. Art. 23(4)(d)Final report within one month

    Send a final report with a detailed description, root cause, mitigation and cross-border impact.

    In QULDEXFinal reports draw on the post-incident review.

    Typical evidence
    Final report

  4. Art. 23(1)Informing service recipients

    Inform recipients of your services about significant incidents likely to affect them, and about threats and remedies.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

Supervision 2

  1. Art. 32–33Supervision

    Essential entities face proactive supervision; important entities face ex-post supervision after evidence of non-compliance.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

  2. Art. 34Administrative fines

    Essential entities: at least up to €10m or 2% of worldwide turnover; important entities: at least up to €7m or 1.4%.

    In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.

Article numbers follow Directive (EU) 2022/2555. National transposition laws can add detail; check your member state's law. Summaries are QULDEX paraphrases, not legal advice.

Compliance path

How do you get NIS2 compliant?

There is no NIS2 certificate. You confirm scope under your national law, register, put the ten measures in place with management approval, and set up incident reporting. Most entities need 6 to 12 months, less with ISO 27001.

  1. Confirm scope per country

    Check sector, size and status in each member state's transposition law.

  2. Register with the authority

    Submit entity details through the national portal or single point of contact.

  3. Gap assessment against Article 21

    Assess the ten measures, reusing ISO 27001 evidence where you have it.

  4. Close the gaps with management approval

    Implement measures, approve them at board level and train management.

  5. Set up incident reporting

    Define "significant", build the 24-hour, 72-hour and one-month workflow, and test it.

  6. Stay supervision-ready

    EssentialProactive audits and inspections
    ImportantEx-post supervision
    Every yearReview measures and training

Check the national law and registration deadlines in each member state where you operate. Durations are QULDEX planning ranges.

Records to keep

Which documents does NIS2 compliance need?

National authorities will ask for evidence of each measure. These records cover most of it.

DocumentArticleWhere it lives in QULDEX
Scoping and status assessmentArt. 2–3Risk register
Registration confirmationArt. 3(4), 27Evidence vault
Management approval and training recordsArt. 20Policy library
Risk assessment and security policiesArt. 21(2)(a)Policy library
Incident response procedureArt. 21(2)(b)Evidence vault
Business continuity and crisis plansArt. 21(2)(c)Evidence vault
Supplier security assessmentsArt. 21(2)(d)Vendor register
Effectiveness assessmentsArt. 21(2)(f)Audit workspace
Incident reports (24 h, 72 h, final)Art. 23CAPA automation

Document names are QULDEX recommendations based on the Directive; national laws may name others.

Time and cost

How long does NIS2 compliance take and what drives the effort?

Most entities need 6 to 12 months. Effort depends on your current security baseline, how many member states you operate in and how many suppliers you rely on.

Where the time goes

Scoping and registration3–6 wk
Gap assessment3–6 wk
Implementing measures3–8 mo
Incident reporting3–6 wk
Supplier assessments2–4 mo

Bars show the upper end of each range on one scale (12 months = full width).

What changes the effort

  • Member states: each national law can differ
  • Entity status: essential entities face proactive audits
  • Suppliers: supply chain security covers direct suppliers
  • Existing ISO 27001: covers most of Article 21
  • Sector rules: implementing acts add detail for digital providers
Readiness check · 2 minutes

How ready are you for NIS2?

Check these eight things first. Nothing you enter leaves this page.

Art. 2Have you confirmed your status under each national NIS2 law?
Art. 27Are you registered with the national authority?
Art. 20Has management approved the measures and completed training?
Art. 21(2)(a)Do you have a current risk assessment and security policies?
Art. 21(2)(c)Are backups, recovery and crisis plans tested?
Art. 21(2)(d)Have you assessed your direct suppliers' security?
Art. 21(2)(j)Is MFA in place for access to critical systems?
Art. 23Can you send an early warning within 24 hours?
Crosswalk

How NIS2 maps to ISO 27001, DORA and NIST CSF

ISO 27001 covers most of Article 21, and DORA replaces NIS2 duties for financial entities. One security programme can serve all of them.

NIS2 crosswalk

NIS2ISO 27001:2022DORANIST CSF 2.0Shared evidence
Art. 20 Governance5.1, 5.3Art. 5GV.RRBoard approvals
21(2)(a) Risk and policies6.1, A.5.1Art. 6GV.RM, ID.RARisk assessment
21(2)(b) IncidentsA.5.24–A.5.26Art. 17RS.MAIncident procedure
21(2)(c) ContinuityA.5.29–A.5.30Art. 11RC.RPContinuity plans
21(2)(d) Supply chainA.5.19–A.5.22Art. 28GV.SCSupplier assessments
21(2)(e) VulnerabilitiesA.8.8Art. 25ID.RAVulnerability log
21(2)(j) MFAA.8.5Art. 9PR.AAMFA settings
Art. 23 ReportingA.5.26Art. 19RS.COIncident reports

Indicative mapping for planning, not legal advice. DORA vs NIS2 is compared in full on the blog.

Where QULDEX fits

How QULDEX runs NIS2 from scoping to supervision

QULDEX is NIS2 compliance and audit management software built from EGV Group's audit delivery, used by essential and important entities, their advisors and the auditors who check them. Pick your role to see who does what.

For organisations in NIS2 sectors.

  1. ScopeConfirm status per countryScoping record per legal entity
  2. GovernApprove and trainBoard approvals and training records
  3. MeasuresImplement Article 21Ten measures mapped to evidence
  4. SuppliersAssess suppliersVendor register with assessments
  5. IncidentsReport significant incidents24 h, 72 h and final-report timers
  6. SupervisionAnswer the authorityControlled evidence sharing
Without one systemWith QULDEX
Scope decided once for the groupStatus per legal entity and country
Board told about cyber once a yearApprovals and training on record
Incident deadlines tracked by hand24 h, 72 h and final-report timers
ISO 27001 and NIS2 run separatelyOne programme mapped to both
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

NIS2 questions people ask

Does NIS2 apply to my company?

It applies if you operate in an Annex I or Annex II sector and are a medium or large enterprise (generally 50+ staff or over €10m turnover), or fall in a category covered regardless of size. Check the law in each member state where you operate.

What are the NIS2 incident reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.

What are the NIS2 fines?

Member states must allow fines of at least up to €10 million or 2% of worldwide turnover for essential entities, and at least up to €7 million or 1.4% for important entities.

Has every EU country transposed NIS2?

Not all. The deadline was 17 October 2024; most member states have laws in force and the Commission has opened infringement proceedings against late ones. Germany's law has applied since 6 December 2025.

Does ISO 27001 certification cover NIS2?

Much of it. ISO 27001 controls cover most Article 21 measures, but NIS2 adds management liability and training, registration and fixed incident-reporting deadlines.

Sources

References

  1. Directive (EU) 2022/2555 (NIS2). eur-lex.europa.eu
  2. Commission Implementing Regulation (EU) 2024/2690 on technical and methodological requirements. eur-lex.europa.eu
  3. NIS2 Implementation Act, Germany, in force 6 Dec 2025. bsi.bund.de
  4. European Commission NIS2 transposition and infringement updates. digital-strategy.ec.europa.eu
  5. ISO/IEC 27001:2022. iso.org

Reviewed by

Swati Chaturvedi

Framework reviewer · QULDEX

Reviewed this page against Directive (EU) 2022/2555: scope, Article 21 measures, reporting deadlines and fines.

Page history
  • : Page first built: provision explorer, ten measures, reporting timeline and readiness check

Find your NIS2 gaps before your authority does

Answer a short readiness check and get a gap summary across the ten measures. No sales call needed to see the result.

Schedule
Book a Demo