EU Directive 2022/2555

NIS2 Readiness — Mapped to Evidence

EU Directive 2022/2555 — Network and Information Security Directive 2. OneComply supports cybersecurity risk management, incident timelines, and supply-chain evidence for essential and important entities.

What is NIS2?

The NIS2 Directive (EU 2022/2555) is the EU's updated framework for achieving a high common level of cybersecurity across member states. It significantly expands the scope of the original NIS Directive, covering more sectors and imposing stricter requirements.

NIS2 applies to essential entities (energy, transport, banking, health, digital infrastructure) and important entities (postal services, waste management, manufacturing, digital providers). Organizations must implement risk management measures under Article 21 and report significant incidents within strict timelines.

Member states were required to transpose NIS2 into national law by 17 October 2024. Management bodies can be held personally liable for non-compliance, with fines up to EUR 10 million or 2% of global turnover for essential entities.

18

Sectors Covered

24h

Early Warning

72h

Incident Report

Workflow acceleration examples

Before vs After — Operational Lift

From scattered evidence to structured readiness. See how OneComply maps NIS2 security measures, incident readiness, and supply-chain evidence.

WorkflowManual ProcessWith OneComplyTime Saved
Risk Management Assessment2–3 weeks2 hours90%
Incident Reporting (24h/72h)4–8 hours scramble15 minutes95%
Supply Chain Assessment1–2 weeks per supplier30 minutes95%
Cybersecurity Policy Suite2–3 months1 week75%
Board Reporting1–2 days30 minutes85%

What We Automate

Comprehensive NIS2 coverage across all three key compliance areas with 45 pre-mapped controls.

Art. 21

Risk Management

25 mapped controls

  • Risk analysis and policies
  • Business continuity management
  • Vulnerability handling
  • Monitoring and logging
  • Cryptography and access control
Art. 23

Incident Reporting

10 mapped controls

  • 24-hour early warning automation
  • 72-hour incident notification
  • Final report generation
  • Cross-border notification
  • CSIRT communication
Art. 21(2)(d)

Supply Chain Security

10 mapped controls

  • Supplier risk assessment
  • Contractual security requirements
  • Third-party audit tracking
  • Supply chain mapping
  • Vendor security scoring

NIS2 Penalty Framework

NIS2 introduces significant penalties with personal liability for management bodies.

Essential Entities

€10M / 2%

Up to €10 million or 2% of total annual worldwide turnover, whichever is higher.

Important Entities

€7M / 1.4%

Up to €7 million or 1.4% of total annual worldwide turnover, whichever is higher.

Personal Liability

Management

Management bodies can be held personally liable. Board members must approve and oversee cybersecurity measures.

Entity Classification

Essential Entities

Large entities in high-criticality sectors: energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration, and space.

Important Entities

Medium/large entities in other critical sectors: postal services, waste management, chemicals, food, manufacturing, digital providers, and research organisations.

18

Sectors covered

~160K

Entities in scope (est.)

27

EU member states

Start your NIS2 compliance journey

Prepare NIS2 evidence for security measures, incident readiness, and supply-chain oversight while leaving national legal interpretation to your compliance team.