NIS 2 Directive

Meet NIS 2 without building a security team first.

NIS 2 makes cybersecurity risk management and incident reporting a legal duty for essential and important entities across the EU, with management accountable for both. A dedicated SecureSlate compliance lead confirms your scope, puts the Article 21 measures in place, and gets your 24-hour reporting process ready, while our compliance automation platform keeps evidence current for supervisory requests. One fixed price covers the work.

NIS 2 Directive22 obligations

NIS 2 Directive: 22 obligations, 1 Registration, 2 Governance, 12 Risk-management measures, 7 Incident reporting. 6 highlighted: Evidenced by included security scanning.

Evidenced by included security scanningScoped with your compliance lead
Directive
(EU) 2022/2555, applies since October 2024
Who it covers
Essential and important entities in 18 sectors
Certification
None, supervised by national authorities
The standard

NIS 2 compliance is supervised by national authorities, not proven by a certificate.

NIS 2, Directive (EU) 2022/2555, replaced the original NIS Directive. Each Member State writes it into national law, so the core obligations are shared while registration, supervision, and some details vary by country.

Ten risk-management measures in Article 21

Article 21(2) sets the minimum: risk analysis and security policies, incident handling, business continuity, supply chain security, secure development and vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, HR security with access control and asset management, and multi-factor authentication. Each must be appropriate and proportionate to your risk and size.

Staged incident reporting

A significant incident triggers an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month. The clock starts when you become aware, so classification criteria and decision rights have to be settled before an incident, not during one.

Management accountability and real penalties

Management bodies must approve and oversee the measures, follow training, and can be held liable. Member States must allow maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher.
How it works

We build your NIS 2 program with you, then keep it ready for the supervisor.

Four stages from the scoping call to a program you can evidence, with a named compliance lead accountable at every one.

Confirm scope and registration

We check your sectors, size, and the countries you operate in against the national laws that apply, work out whether you are an essential or important entity, and prepare the details your authority asks for at registration.

Run the gap assessment

Your compliance lead maps what you already run to the Article 21 measures, including ISO 27001 or SOC 2 controls where you have them, and ranks the gaps by risk so the most exposed areas close first.

Put the measures and reporting in place

Policies, supplier security, business continuity, access control, and vulnerability handling are implemented in priority order, along with an incident classification and reporting process tested against the 24-hour, 72-hour, and one-month deadlines.

Stay ready for supervision

Controls are tested continuously, management receives regular reporting and training, and evidence stays organized, so you can answer a supervisory request or security audit without rebuilding the program.
What is included

Everything a NIS 2 supervisor may ask for, prepared before they ask.

NIS 2 compliance software and the expert who runs it arrive together under one fixed price, so the directive does not become a side project for your engineers.

A dedicated compliance lead

One experienced practitioner owns your NIS 2 program end to end. They confirm scope, build the measures, prepare management reporting, and run your incident reporting exercise, so your team approves decisions instead of learning the directive.

Article 21 mapping and a gap assessment

Every Article 21 measure mapped to the policies, controls, and evidence that meet it, with each gap scored, owned, and scheduled, and the work that already counts toward ISO 27001 marked.

Evidence from the stack you already run

Connect your cloud provider, identity provider, code host, and devices once. Controls are tested continuously against live configuration, so evidence for a supervisory request is current instead of assembled in a hurry.

Supply chain security

Direct suppliers and service providers inventoried, risk-tiered, and reviewed on a schedule, with the supplier vulnerabilities and secure development practices that Article 21(3) asks you to consider on record.

Incident reporting readiness

Your compliance lead writes the incident response plan with significant-incident criteria, decision owners, and report templates for each deadline, then tests it with your team in a tabletop exercise.

Training for management and staff

Security awareness training assigned and tracked for employees, with cybersecurity training for management bodies recorded, covering Article 20(2) and the cyber hygiene measure in Article 21(2)(g).
Included security scanning

Six NIS 2 measures come with evidence from included security scanning.

Every engagement includes scanning across code, dependencies, cloud, and your public surface. These are the Article 21 measures it evidences directly, so findings arrive with the evidence attached.
Art. 21(2)(e) Acquisition, development, and maintenance

Code security scanning

Repositories scanned for vulnerable code, with findings ranked by severity and traced to the line, which evidences vulnerability handling in development and maintenance.
Art. 21(2)(d) Supply chain security, Art. 21(2)(e) Acquisition, development, and maintenance

Dependency and license risk

An SBOM for every repository, with vulnerable open source components flagged, so the security of the software you depend on becomes part of supply chain risk.
Art. 21(2)(f) Effectiveness assessment

Public surface monitoring

Your domains and forgotten subdomains scanned on a schedule and when you ship, giving regular, recorded tests of whether your measures hold up from the outside.
Art. 21(2)(i) Access control and assets

Secrets detection

API keys, tokens, and credentials committed to source code, found and pinpointed to the file and line, so access stays controlled rather than exposed in repositories.
Art. 21(2)(g) Cyber hygiene

Dark web monitoring

Company email addresses checked against known breach data, so exposed credentials are reset and cyber hygiene is measured, not only trained.
Art. 21(2)(h) Cryptography, Art. 21(2)(i) Access control and assets

Cloud misconfiguration checks

AWS, Azure, and GCP configurations checked through read-only access for risky settings in encryption, access, logging, and networking.
Beyond NIS 2

One NIS 2 program that also serves your other frameworks.

NIS 2 overlaps with the standards and regulations your buyers and regulators already recognize, so shared controls count more than once.

ISO 27001

The most common way to make Article 21 concrete. An ISMS covers much of the measures, though certification alone does not prove NIS 2 compliance.

DORA

Financial entities follow DORA's ICT risk and reporting rules where DORA applies, because it is the sector-specific act. Groups with financial and non-financial entities often run one program.

GDPR

A significant incident involving personal data can trigger both NIS 2 reporting and a 72-hour GDPR breach notification, so one incident process should handle both.

NIST CSF

Teams outside the EU often start from the CSF. Its Govern, Protect, Detect, and Respond outcomes line up with much of Articles 21 and 23.

SOC 2

Common for SaaS companies selling to both US and EU customers. Access, change, vendor, and incident controls serve both, so the programs share evidence.

ISO 42001

Teams adding AI features in regulated sectors extend the same risk and supplier processes to AI systems instead of starting a separate program.
NIS 2 guides

What NIS 2 actually asks of your team

Three deep dives your team can read before the scoping call, from who is in scope to how far ISO 27001 gets you.

18 sectors
Who needs to comply with NIS 2: scope, entity types, and penalties explained
24 hours
The NIS 2 compliance checklist, from scope to incident reporting
ISO 27001
ISO 27001 and NIS 2: the key differences, and how far one covers the other
Resources

Read up before your scoping call.

Practical guides to NIS 2, from what changed since the original directive to how it compares with DORA.

FAQs

What teams ask before starting NIS 2.

Find out what NIS 2 means for your company

Bring the countries you operate in and the services you provide. You will leave the call with a gap summary, a plan, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?