NIS2 Directive (EU) 2022/2555 compliance software
Assess and evidence the NIS2 Directive per group or per legal entity: management-body accountability, the ten Article 21 risk-management measures as detailed by Implementing Regulation (EU) 2024/2690, the Article 23 reporting clock and the transposition law of all 27 Member States.
- Legal instrumentDirective (EU) 2022/2555; transposition deadline 17 October 2024
- Implementing actCommission Implementing Regulation (EU) 2024/2690, with ENISA technical implementation guidance (June 2025)
- Assessable items303 requirements in 14 domains, 160 of them critical
- Domains13 measure domains, from management-body accountability to physical security, plus a 27-Member-State transposition overlay of 115 duties
- Reporting clockEarly warning 24 h, incident notification 72 h, final report within one month (Article 23)
- ScopeGroup or legal entity; profiles Essential, Important and Digital infrastructure
What NIS2 requires
Who it applies to
- Essential entities: large organisations in Annex I sectors, size-independent providers such as trust services, TLD registries and DNS, and entities a Member State designates
- Important entities: medium-sized and larger organisations in Annex I and Annex II sectors that are not essential
- Cloud, data centre, CDN, managed and managed security service providers, marketplaces, search engines and social networks, under Implementing Regulation (EU) 2024/2690
- Groups with entities in several Member States that need one view of every national transposition and competent authority
Directive (EU) 2022/2555, NIS2, replaced the first NIS Directive and sets the EU's common baseline for cybersecurity risk management and incident reporting; Member States had to transpose it by 17 October 2024. It reaches medium-sized and larger organisations in the high-criticality sectors of Annex I (energy, transport, banking, financial market infrastructures, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space) and the other critical sectors of Annex II (postal and courier, waste management, chemicals, food, manufacturing, digital providers and research). Some entities are in scope whatever their size, among them public electronic-communications providers, trust service providers, TLD registries and DNS providers.
Article 20 requires the management body to approve the cybersecurity risk-management measures, oversee their implementation and answer for failures, and its members to follow training. Article 21 sets ten measures: risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition, development and maintenance, effectiveness assessment, cyber hygiene and training, cryptography, HR security with access control and asset management, and multi-factor authentication with secured communications. For digital-infrastructure, ICT-service and digital-provider entities, Commission Implementing Regulation (EU) 2024/2690 turns those measures into detailed technical and methodological requirements, and ENISA's technical implementation guidance of June 2025 adds examples of evidence and mappings to ISO/IEC 27001 and NIST CSF 2.0.
Article 23 sets the clock for a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours and a final report within one month. Entities are essential or important. Essential entities are supervised ex ante and ex post, and Member States must allow maximum fines of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher; important entities are supervised ex post, with maximum fines of at least EUR 7 million or 1.4%. Because NIS2 is a directive, those duties bite through national law, which is why GRCLens carries every Member State's transposition as its own overlay.
How GRCLens supports NIS2
NIS2 runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Group and entity assessment with roll-up
The group is assessed once and each legal entity on its own, as essential or important and, where it applies, as a digital-infrastructure entity under Implementing Regulation (EU) 2024/2690. Every entity rolls up into a group view with a heat map across 15 risk areas, so a board sees which kind of exposure a weak entity carries.
27 national transpositions
Tick the Member States an entity operates in and that country's transposition duties join the questionnaire: the national law and its status, the competent authority and CSIRT, registration and the notification route. The dashboard reports conformity per Member State with the open gaps listed.
Four stakeholder dashboards
The management body sees conformity, critical gaps, the supervision regime, fine exposure and the reporting clock; the CISO and risk team the heat map, domain scores and gaps; operations the control validation and open remediation; third-party and procurement teams supply-chain security and supplier checks.
Continuous assurance from eight EU cyber-resilience connectors
Incident records, backup and restore, vulnerability and patch, identity and MFA, the ICT third-party register, resilience testing, training (LMS) and log monitoring are read against the questionnaire, alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. A failing check whose requirement was answered Implemented is flagged as a contradiction.
Assurance register, remediation and KRIs
Each requirement can carry several owners in the assurance register. Gaps become owned, dated actions in the remediation and risk treatment plan, and key risk indicators name the requirements they measure, so an indicator outside appetite beside an answer of Implemented is a finding.
Baseerah summary, Word and PDF reports
Baseerah, the platform's AI assistant running on a self-hosted language model, writes a one-paragraph executive summary for the management body and the CISO. Entity and group reports export as Word and PDF.
NIS2 frequently asked questions
Who does NIS2 apply to?
Medium-sized and larger organisations (at least 50 staff, or annual turnover and balance sheet above EUR 10 million) in a sector listed in Annex I or Annex II of the Directive, plus some entities whatever their size: public electronic-communications providers, trust service providers, TLD registries, DNS providers, public administration entities and entities a Member State designates. Large Annex I entities and the size-independent categories are essential; the others are important.
What are the NIS2 incident reporting deadlines?
For a significant incident: an early warning to the CSIRT or competent authority within 24 hours of becoming aware of it, an incident notification within 72 hours with an initial assessment of severity and impact, and a final report within one month of that notification. Trust service providers notify within 24 hours, and intermediate reports are due when the authority asks for them.
What does Implementing Regulation (EU) 2024/2690 add?
It sets the technical and methodological requirements of the Article 21 measures for digital-infrastructure, ICT-service and digital-provider entities (DNS, TLD, cloud, data centre, CDN, managed and managed security service providers, trust services, marketplaces, search engines and social networks) and the thresholds that make their incidents significant. GRCLens uses its annex as the item-level detail of the 13 measure domains, and the Digital infrastructure profile marks the entities it binds directly.
What are the fines under NIS2?
Member States must allow maximum administrative fines of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities, and at least EUR 7 million or 1.4% for important entities. Management bodies can be held liable for failing to implement the risk-management measures, and essential entities are also supervised ex ante, through audits, inspections and security scans.
Is NIS2 the same in every Member State?
The measures are common, but the competent authority, CSIRT, registration and notification route are set by each national law, and transposition has been uneven: the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026. GRCLens carries all 27 transpositions as 115 duties, with each law's status and the date it was checked, asked only for the Member States an entity is assessed against.
One platform, many obligations
See all supported frameworks → Every framework that applies in European Union →

Talk to us about NIS2
Security Solution Consultants provides NIS2 readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.