NIS2SecurityEuropean UnionEssential & Important Entities

EU Network and Information Security Directive 2

EU directive establishing cybersecurity obligations for entities operating essential and important services. Effective October 2024 with significant penalties for non-compliance.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

NIS2Article 21(1)Patching, hardening, and exposureA record of access

Risk Management Measures

Essential and important entities MUST take appropriate technical and organizational measures to manage security risks.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

NIS2Article 21(2)(g)Policy, procedure, and documentation

Policies on Use of Cryptography

Entities MUST have policies and procedures regarding use of cryptography and encryption.

This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.

NIS2Article 23Detecting it in time to notify

Incident Reporting

Significant incidents MUST be reported to CSIRT within 24 hours, with full report within 72 hours.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

NIS2Article 21(2)(d)What your suppliers actually reach

Supply Chain Security

Entities MUST address security in supplier relationships and direct suppliers.

A supplier-risk requirement has two halves and they are not equally hard. The register of providers, the contractual clauses, and the assessment of each supplier as an organisation are yours to maintain — nothing in the platform produces them. The half that is usually undocumented is what those suppliers, their tooling, and their service accounts are actually reaching inside your estate. Scanning surfaces the shared and vendor-default accounts, the credentials with no owner, and the standing privileges nobody has exercised; the query trail then shows which of those grants were used, against which classified tables, from which client host. So the review reflects observed third-party access rather than an attestation, and an integrator session that steps outside its usual pattern is scored as it happens rather than found at the next annual review.

What NIS2 covers

This instrument defines no data category of its own. Regulates the security of network and information SYSTEMS. Art. 21 lists measures rather than data classes, and an entity is in scope for its sector and size, not for what it stores.

How NIS2 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The national competent authority designated by each Member State.

Published maximumChargedAs at
EUR 10 million or 2% of worldwide turnoverwhichever is higher, against an essential entity2026-08
EUR 7 million or 1.4% of worldwide turnoverwhichever is higher, against an important entity2026-08

Both ceilings take the higher of the fixed sum and the percentage. The more consequential provision is not the money: Article 20 places the approval and oversight of cybersecurity risk-management measures on the management body itself, and Article 32(6) lets an authority ask a court to bar a named executive from running the business.

Article 34 sets a floor, not a ceiling. Member States may and do set higher maximums when transposing, so the national figure is the one that governs.

Who is personally on the hook

Who can be charged
Any natural person discharging managerial responsibilities at chief executive or legal representative level in an essential entity
For what
failing to approve and oversee the cybersecurity risk-management measures the entity is required to take
Maximum
A temporary prohibition on exercising managerial functions in that entity, lasting until the deficiencies are remedied. Article 20 separately makes the management body accountable for approving and overseeing the measures
Brought by
The national competent authority, through the courts of the Member State
Disqualification

Uncapped exposure that sits outside this instrument

These come from company law rather than from NIS2, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Who the instrument makes accountable

Article 20 requires the management body to approve the cybersecurity risk-management measures and oversee their implementation, and makes it accountable for that. Article 20(2) adds a training obligation on the same people.

The insurance position

Cyber wordings in the EU commonly cover the incident response and the regulatory defence; administrative fines are often excluded where local law makes them uninsurable, and that varies by Member State.

How this class of policy is commonly written. Only your own policy answers what it covers.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for NIS2,
not configured for it afterwards

Policy Template

NIS2 Database Security Policy

Technical measures for database security per Article 21

Report

NIS2 Incident Report

24/72-hour incident report templates with required fields

Classification

Essential Service Data

Identify and classify data supporting essential services

Alert

Significant Incident Detection

Real-time detection to enable 24-hour initial notification

Walk into the NIS2 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment