Directive · Cybersecurity · European Union
NIS2 compliance means meeting the EU cybersecurity directive as your country has transposed it. Medium and large entities in 18 sectors must apply ten risk-management measures, have management approve and oversee them, and report significant incidents within 24 hours, 72 hours and one month.
NIS2 applies through national laws to entities in listed sectors that meet the size cap.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
NIS2 requires in-scope entities to apply ten cybersecurity risk-management measures, have their management body approve and oversee them, register with authorities, and report significant incidents on a fixed timeline.
Sector plus size decides status and supervision.
In QULDEX: Scoping per legal entityApprove, oversee, train; personal liability.
In QULDEX: Board approvals trackedRisk, incidents, continuity, supply chain, crypto, MFA and more.
In QULDEX: Measures mapped to ISO 2700124-hour warning, 72-hour notification, one-month report.
In QULDEX: Timers on every incidentEntity details to the national authority.
In QULDEX: Registration trackedAt least up to €10m or 2% for essential entities.
In QULDEX: Supervision readinessThese 23 provisions carry the obligations most entities work on, grouped by theme. Select any one to see what it requires, typical evidence and the matching ISO 27001 or DORA reference.
Showing up to 6 per group. Search, filter, or open a group to see all 23.
Art. 2Scope and size capApplies to medium and large entities in Annex I and II sectors, and to some entities regardless of size, such as DNS and trust service providers.
In QULDEXEach legal entity records its sector, size and status.
Art. 3Essential and important entitiesEntities are essential or important depending on sector and size; essential entities face proactive supervision.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Annex ISectors of high criticalityEnergy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Annex IIOther critical sectorsPostal services, waste management, chemicals, food, manufacturing of critical products, digital providers and research.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 3(4)Registration with authoritiesRegisterEntities provide their details to national authorities; digital infrastructure providers register with the single point of contact.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 20(1)Management body approval and oversightManagement bodies approve the cybersecurity risk-management measures, oversee them and can be held liable for breaches.
In QULDEXApprovals and oversight reviews are recorded per entity.
Art. 20(2)Management trainingMembers of management bodies must follow training, and staff should be offered similar training regularly.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(a)Risk analysis and security policiesPolicies on risk analysis and information system security.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(b)Incident handlingProcesses to prevent, detect and respond to incidents.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(c)Business continuity and crisis managementBackup management, disaster recovery and crisis management.
In QULDEXContinuity evidence is reused from ISO 22301.
Art. 21(2)(d)Supply chain securitySecurity of relationships with direct suppliers and service providers.
In QULDEXSuppliers are assessed and linked to the services they support.
Art. 21(2)(e)Secure acquisition, development and maintenanceSecurity in acquisition, development and maintenance, including vulnerability handling and disclosure.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(f)Assessing effectivenessPolicies and procedures to assess whether measures work.
In QULDEXControl tests run on a schedule with results.
Art. 21(2)(g)Cyber hygiene and trainingBasic cyber hygiene practices and cybersecurity training.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(h)Cryptography and encryptionPolicies on cryptography and, where appropriate, encryption.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(i)HR security, access control and assetsHuman resources security, access control policies and asset management.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 21(2)(j)MFA and secured communicationsMulti-factor or continuous authentication, secured voice, video and text, and emergency communications.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 23(4)(a)Early warning within 24 hoursSend an early warning to the CSIRT or authority within 24 hours of becoming aware of a significant incident.
In QULDEXEach significant incident starts 24-hour, 72-hour and one-month timers.
Art. 23(4)(b)Incident notification within 72 hoursUpdate the early warning with an initial assessment of severity, impact and indicators of compromise.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 23(4)(d)Final report within one monthSend a final report with a detailed description, root cause, mitigation and cross-border impact.
In QULDEXFinal reports draw on the post-incident review.
Art. 23(1)Informing service recipientsInform recipients of your services about significant incidents likely to affect them, and about threats and remedies.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 32–33SupervisionEssential entities face proactive supervision; important entities face ex-post supervision after evidence of non-compliance.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Art. 34Administrative finesEssential entities: at least up to €10m or 2% of worldwide turnover; important entities: at least up to €7m or 1.4%.
In QULDEXQULDEX gives this requirement an owner, evidence requests and a review date, and reuses ISO 27001 evidence where it fits.
Nothing matches that search.
Article numbers follow Directive (EU) 2022/2555. National transposition laws can add detail; check your member state's law. Summaries are QULDEX paraphrases, not legal advice.
There is no NIS2 certificate. You confirm scope under your national law, register, put the ten measures in place with management approval, and set up incident reporting. Most entities need 6 to 12 months, less with ISO 27001.
Check sector, size and status in each member state's transposition law.
Submit entity details through the national portal or single point of contact.
Assess the ten measures, reusing ISO 27001 evidence where you have it.
Implement measures, approve them at board level and train management.
Define "significant", build the 24-hour, 72-hour and one-month workflow, and test it.
Check the national law and registration deadlines in each member state where you operate. Durations are QULDEX planning ranges.
National authorities will ask for evidence of each measure. These records cover most of it.
| Document | Article | Where it lives in QULDEX |
|---|---|---|
| Scoping and status assessment | Art. 2–3 | Risk register |
| Registration confirmation | Art. 3(4), 27 | Evidence vault |
| Management approval and training records | Art. 20 | Policy library |
| Risk assessment and security policies | Art. 21(2)(a) | Policy library |
| Incident response procedure | Art. 21(2)(b) | Evidence vault |
| Business continuity and crisis plans | Art. 21(2)(c) | Evidence vault |
| Supplier security assessments | Art. 21(2)(d) | Vendor register |
| Effectiveness assessments | Art. 21(2)(f) | Audit workspace |
| Incident reports (24 h, 72 h, final) | Art. 23 | CAPA automation |
Document names are QULDEX recommendations based on the Directive; national laws may name others.
Most entities need 6 to 12 months. Effort depends on your current security baseline, how many member states you operate in and how many suppliers you rely on.
Bars show the upper end of each range on one scale (12 months = full width).
Check these eight things first. Nothing you enter leaves this page.
ISO 27001 covers most of Article 21, and DORA replaces NIS2 duties for financial entities. One security programme can serve all of them.
| NIS2 | ISO 27001:2022 | DORA | NIST CSF 2.0 | Shared evidence |
|---|---|---|---|---|
| Art. 20 Governance | 5.1, 5.3 | Art. 5 | GV.RR | Board approvals |
| 21(2)(a) Risk and policies | 6.1, A.5.1 | Art. 6 | GV.RM, ID.RA | Risk assessment |
| 21(2)(b) Incidents | A.5.24–A.5.26 | Art. 17 | RS.MA | Incident procedure |
| 21(2)(c) Continuity | A.5.29–A.5.30 | Art. 11 | RC.RP | Continuity plans |
| 21(2)(d) Supply chain | A.5.19–A.5.22 | Art. 28 | GV.SC | Supplier assessments |
| 21(2)(e) Vulnerabilities | A.8.8 | Art. 25 | ID.RA | Vulnerability log |
| 21(2)(j) MFA | A.8.5 | Art. 9 | PR.AA | MFA settings |
| Art. 23 Reporting | A.5.26 | Art. 19 | RS.CO | Incident reports |
Indicative mapping for planning, not legal advice. DORA vs NIS2 is compared in full on the blog.
QULDEX is NIS2 compliance and audit management software built from EGV Group's audit delivery, used by essential and important entities, their advisors and the auditors who check them. Pick your role to see who does what.
For organisations in NIS2 sectors.
For NIS2 consultants and internal audit.
For security auditors and supervisory inspections.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →It applies if you operate in an Annex I or Annex II sector and are a medium or large enterprise (generally 50+ staff or over €10m turnover), or fall in a category covered regardless of size. Check the law in each member state where you operate.
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.
Member states must allow fines of at least up to €10 million or 2% of worldwide turnover for essential entities, and at least up to €7 million or 1.4% for important entities.
Not all. The deadline was 17 October 2024; most member states have laws in force and the Commission has opened infringement proceedings against late ones. Germany's law has applied since 6 December 2025.
Much of it. ISO 27001 controls cover most Article 21 measures, but NIS2 adds management liability and training, registration and fixed incident-reporting deadlines.
Reviewed by
Answer a short readiness check and get a gap summary across the ten measures. No sales call needed to see the result.