Skip to content

Framework template

NIS2

The EU directive that sets cybersecurity obligations for essential and important entities in critical sectors, including energy, transport, health, water and digital infrastructure.

Network and Information Security Directive 2

Bundled template

In practice

NIS2 widens the sectors in scope, sets minimum risk-management measures, requires an early warning within 24 hours and an incident notification within 72 hours of a significant incident, and makes management accountable for oversight. Member states transpose it into national law.

Requirements

What NIS2 asks of you.

01

Risk-management measures

Policies on risk analysis, incident handling, business continuity, supply chain security and network security.

02

Incident reporting

Early warning within 24 hours, notification within 72 hours and a final report within a month of a significant incident.

03

Supply chain security

Assessment of cybersecurity risk in suppliers and service providers, with security requirements in the contracts.

04

Management accountability

Management approves and oversees the measures and can be held liable for failures.

How the Desk helps

The NIS2 programme, run on the Compliance Desk.

Each step below is shipped: the template import in Compliance Studio, and workflows that run over the documents you choose, record their sources and hold for approval before export.

Obligations from the directive and the national law

Run Extract obligations over the directive and your national transposition. The run records every source it read and holds for approval.

Measures reviewed against the obligations

Run Review controls over your security policies, continuity plans and supplier terms; a control memo in Compliance Studio names the measures with gaps.

Evidence and the incident file

Evidence is held per measure with its status. Find missing evidence and Prepare audit checklist run over the evidence documents you select, with every source on record.

Security

GDPR and CCPA compliant, ISO 27001 aligned, SOC 2 Type II in progress. Encrypted at rest and in transit. Your data never trains a model.

Security page

Next step

Start from the NIS2 template on your own files.

Bring the policies you have and the last audit's request list. We will import the template, run the workflows with you and hand back the controls, the evidence on file and each run's sources.