EU Network and Information Security Directive 2
EU directive establishing cybersecurity obligations for entities operating essential and important services. Effective October 2024 with significant penalties for non-compliance.
What NIS2 draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Risk Management Measures
Essential and important entities MUST take appropriate technical and organizational measures to manage security risks.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Policies on Use of Cryptography
Entities MUST have policies and procedures regarding use of cryptography and encryption.
This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.
Incident Reporting
Significant incidents MUST be reported to CSIRT within 24 hours, with full report within 72 hours.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Supply Chain Security
Entities MUST address security in supplier relationships and direct suppliers.
A supplier-risk requirement has two halves and they are not equally hard. The register of providers, the contractual clauses, and the assessment of each supplier as an organisation are yours to maintain — nothing in the platform produces them. The half that is usually undocumented is what those suppliers, their tooling, and their service accounts are actually reaching inside your estate. Scanning surfaces the shared and vendor-default accounts, the credentials with no owner, and the standing privileges nobody has exercised; the query trail then shows which of those grants were used, against which classified tables, from which client host. So the review reflects observed third-party access rather than an attestation, and an integrator session that steps outside its usual pattern is scored as it happens rather than found at the next annual review.
What NIS2 covers
This instrument defines no data category of its own. Regulates the security of network and information SYSTEMS. Art. 21 lists measures rather than data classes, and an entity is in scope for its sector and size, not for what it stores.
How NIS2 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The national competent authority designated by each Member State.
| Published maximum | Charged | As at |
|---|---|---|
| EUR 10 million or 2% of worldwide turnover | whichever is higher, against an essential entity | 2026-08 |
| EUR 7 million or 1.4% of worldwide turnover | whichever is higher, against an important entity | 2026-08 |
Both ceilings take the higher of the fixed sum and the percentage. The more consequential provision is not the money: Article 20 places the approval and oversight of cybersecurity risk-management measures on the management body itself, and Article 32(6) lets an authority ask a court to bar a named executive from running the business.
Article 34 sets a floor, not a ceiling. Member States may and do set higher maximums when transposing, so the national figure is the one that governs.
Who is personally on the hook
- Who can be charged
- Any natural person discharging managerial responsibilities at chief executive or legal representative level in an essential entity
- For what
- failing to approve and oversee the cybersecurity risk-management measures the entity is required to take
- Maximum
- A temporary prohibition on exercising managerial functions in that entity, lasting until the deficiencies are remedied. Article 20 separately makes the management body accountable for approving and overseeing the measures
- Brought by
- The national competent authority, through the courts of the Member State
Uncapped exposure that sits outside this instrument
These come from company law rather than from NIS2, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Who the instrument makes accountable
Article 20 requires the management body to approve the cybersecurity risk-management measures and oversee their implementation, and makes it accountable for that. Article 20(2) adds a training obligation on the same people.
The insurance position
Cyber wordings in the EU commonly cover the incident response and the regulatory defence; administrative fines are often excluded where local law makes them uninsurable, and that varies by Member State.
How this class of policy is commonly written. Only your own policy answers what it covers.
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for NIS2,
not configured for it afterwards
NIS2 Database Security Policy
Technical measures for database security per Article 21
NIS2 Incident Report
24/72-hour incident report templates with required fields
Essential Service Data
Identify and classify data supporting essential services
Significant Incident Detection
Real-time detection to enable 24-hour initial notification
Other Security frameworks
Walk into the NIS2 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.