Regulation

EU NIS2

EU NIS2 Directive

12 requirements · 11 connected unified controls

Open EU NIS2 in the map
Version
Directive (EU) 2022/2555
Published
2022-12-27
Effective
2024-10-18 (transposition deadline 2024-10-17)
Amendments
supplemented by Implementing Regulation (EU) 2024/2690 (digital-sector entities)

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

EU NIS2 Directive

RequirementUnified control and mapping
NIS2-Art20Governance and management body accountability / training
UC-GOV-05 — Ensure board-level oversight of risk and internal controlPartial

Remaining requirement: management body members must approve measures and complete cybersecurity training

NIS2-Art21aPolicies on risk analysis and information system security
NIS2-Art21bIncident handling
UC-GOV-35 — Maintain incident response policy and proceduresPartial

Remaining requirement: operational incident detection, handling, and response capability

NIS2-Art21cBusiness continuity, backup management and disaster recovery, crisis management
UC-GOV-34 — Maintain business continuity and contingency planning policyPartial

Remaining requirement: implemented backup, disaster recovery, and crisis management capabilities

NIS2-Art21dSupply chain security
UC-TPRM-01 — Operate a third-party security risk management programPartial

Remaining requirement: operational supplier security assessments and contractual safeguards per supplier

NIS2-Art21eSecurity in acquisition, development and maintenance of network and information systems (incl. vulnerability handling and disclosure)
UC-GOV-29 — Maintain secure acquisition, development, and maintenance policiesPartial

Remaining requirement: operational vulnerability handling and coordinated disclosure processes

NIS2-Art21fPolicies and procedures to assess the effectiveness of cybersecurity risk-management measures
NIS2-Art21gBasic cyber hygiene practices and cybersecurity training
UC-GOV-32 — Maintain security awareness and cyber-hygiene policiesPartial

Remaining requirement: actual delivery of hygiene practices and training to all personnel

NIS2-Art21hPolicies on the use of cryptography and encryption
NIS2-Art21iHuman resources security, access control policies and asset management
UC-GOV-31 — Maintain access control, identity, and personnel security policiesPartial

Remaining requirement: asset management policy and operational measures

NIS2-Art21jUse of multi-factor authentication, secured communications and emergency communication systems
UC-GOV-36 — Maintain communications security and cryptography policiesPartial

Remaining requirement: actual deployment of MFA and secured emergency communication systems

NIS2-Art23Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)
UC-GOV-24 — Notify regulators of incidents and file required certificationsPartial

Remaining requirement: staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies