14 NIS2 Directive
Modern economies depend on interconnected digital infrastructure.
Organizations responsible for:
- energy
- transportation
- healthcare
- banking
- digital infrastructure
- cloud services
- managed services
- public administration
- manufacturing
- communications
can no longer treat cybersecurity as simply an internal IT issue.
A major cyber incident affecting one organization can disrupt:
Customers ↓Suppliers ↓Critical Services ↓Industries ↓National InfrastructureThe European Union therefore introduced an expanded cybersecurity framework:
NIS2 DirectiveNIS2 establishes cybersecurity risk-management and incident-reporting obligations for organizations operating in important sectors across the European Union.
The central question is:
Can Essentialand ImportantOrganizationsContinue OperatingDuring SeriousCybersecurity Incidents?Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
explain the purpose of NIS2.
-
understand the evolution from NIS to NIS2.
-
identify essential and important entities.
-
understand NIS2 sector coverage.
-
understand management-body accountability.
-
explain cybersecurity risk-management measures.
-
understand incident handling requirements.
-
understand business continuity and crisis management.
-
understand backup and disaster recovery.
-
understand supply chain security.
-
understand vulnerability management.
-
understand secure development requirements.
-
understand cybersecurity effectiveness assessments.
-
understand cryptography and encryption requirements.
-
understand access-control requirements.
-
understand MFA and secure communications.
-
understand cybersecurity awareness and training.
-
understand significant incident reporting.
-
understand the NIS2 reporting lifecycle.
-
understand supervision and enforcement.
-
understand evidence requirements.
-
build an enterprise NIS2 compliance program.
-
integrate NIS2 with ISO 27001, NIST CSF, DORA, CIS Controls, and enterprise GRC.
1. What Is NIS2?
Section titled “1. What Is NIS2?”NIS2 is the commonly used name for:
Directive (EU)2022/2555It establishes measures intended to achieve a high common level of cybersecurity across the European Union.
NIS2 replaced the earlier:
NIS Directiveand significantly expanded its scope and requirements.
Conceptually:
NIS ↓Expanded Scope ↓Stronger Governance ↓Stronger Risk Management ↓Stronger Reporting ↓NIS22. Why NIS2 Was Introduced
Section titled “2. Why NIS2 Was Introduced”Modern organizations depend on:
Cloud
Networks
Applications
Identity
Data
Suppliers
Managed Services
Digital PlatformsThese dependencies create systemic cybersecurity risk.
For example:
Cloud Provider ↓Healthcare Provider ↓Hospital Systems ↓Patient ServicesA cyber incident can therefore become:
Technology Incident ↓Business Disruption ↓Critical Service Disruption ↓Societal Impact3. NIS2 Objective
Section titled “3. NIS2 Objective”The objective is not merely:
Protect ComputersThe broader objective is:
ProtectEssential Servicesand ImportantEconomic Activitiesthrough stronger cybersecurity governance and resilience.
4. NIS2 Governance Model
Section titled “4. NIS2 Governance Model”A simplified model is:
Management Body ↓Cybersecurity Governance ↓Risk Assessment ↓Security Measures ↓Monitoring ↓Incident Management ↓Reporting ↓Continuous Improvement5. Essential and Important Entities
Section titled “5. Essential and Important Entities”NIS2 generally categorizes in-scope organizations as:
Essential Entitiesor:
Important EntitiesThe classification affects areas such as supervisory approach and enforcement.
6. Essential Entities
Section titled “6. Essential Entities”Depending on sector, size and other applicability criteria, essential entities may include organizations operating in areas such as:
Energy
Transport
Banking
Financial Market Infrastructure
Health
Drinking Water
Wastewater
Digital Infrastructure
ICT Service Management
Public Administration
SpaceApplicability must always be assessed against the Directive and the relevant Member State’s implementing legislation.
7. Important Entities
Section titled “7. Important Entities”Other covered sectors can include:
Postal Services
Waste Management
Chemical Manufacturing
Food
Manufacturing
Digital Providers
Researchagain subject to the applicable classification criteria.
8. Size-Cap Rule
Section titled “8. Size-Cap Rule”NIS2 generally focuses on:
MediumandLarge Organizationswithin covered sectors.
However, certain organizations may fall within scope regardless of normal size thresholds because of factors such as their criticality or specific role.
Therefore:
Small Company≠Automatically Out of Scope9. Applicability Assessment
Section titled “9. Applicability Assessment”A GRC analyst should determine:
Country ↓Sector ↓Entity Type ↓Organization Size ↓Special Applicability Rules ↓Essential / Important ↓Applicable Requirements10. Member State Implementation
Section titled “10. Member State Implementation”An important distinction is that NIS2 is a:
Directiverather than an EU regulation applied identically through a single operational rulebook.
Member States transpose the Directive into national law.
Therefore organizations should evaluate:
NIS2 +National Implementation +Regulator Guidance11. Management-Body Accountability
Section titled “11. Management-Body Accountability”NIS2 makes cybersecurity governance a leadership responsibility.
The management body must approve and oversee cybersecurity risk-management measures.
Conceptually:
Board / Management ↓Approve ↓Oversee ↓CybersecurityRisk Management12. Cybersecurity Is Not Only the CISO’s Responsibility
Section titled “12. Cybersecurity Is Not Only the CISO’s Responsibility”Weak governance:
Cybersecurity ↓IT DepartmentMature governance:
Management Body ↓BusinessRiskSecurityTechnologyLegalCompliance13. Management Training
Section titled “13. Management Training”Management should maintain sufficient cybersecurity understanding to:
Understand Risk
Evaluate Controls
Challenge Management
Review Incidents
Make Risk DecisionsTraining should therefore be treated as part of governance.
14. Cybersecurity Risk Management
Section titled “14. Cybersecurity Risk Management”NIS2 requires organizations to implement appropriate and proportionate:
Technical
Operational
Organizationalmeasures for cybersecurity risk.
15. All-Hazards Approach
Section titled “15. All-Hazards Approach”Organizations should consider a broad range of threats.
For example:
Cyberattack
Ransomware
Insider Threat
System Failure
Supplier Failure
Human Error
Physical Event
Natural DisasterCyber resilience cannot be designed around malware alone.
16. Risk Management Lifecycle
Section titled “16. Risk Management Lifecycle”Identify ↓Assess ↓Treat ↓Monitor ↓Review17. Cyber Risk Register
Section titled “17. Cyber Risk Register”Maintain:
Risk ID
Asset / Service
Threat
Vulnerability
Likelihood
Impact
Existing Controls
Residual Risk
Risk Owner
Treatment
Due Date18. Example Risk
Section titled “18. Example Risk”Risk:
Compromise ofprivileged cloudadministrator accountscould disrupt criticalcustomer services.Controls:
MFA
PAM
Conditional Access
Logging
Access Reviews19. Security Policies
Section titled “19. Security Policies”Organizations should establish policies covering relevant areas such as:
Cybersecurity
Risk Management
Access Control
Incident Response
Business Continuity
Supply Chain Security
Vulnerability Management
Cryptography
Secure Development20. Incident Handling
Section titled “20. Incident Handling”NIS2 requires capabilities for:
Preventing
Detecting
Responding
Recoveringfrom cybersecurity incidents.
A mature process:
Detect ↓Triage ↓Classify ↓Contain ↓Eradicate ↓Recover ↓Report ↓Learn21. Incident Response Plan
Section titled “21. Incident Response Plan”Document:
Roles
Responsibilities
Severity
Escalation
Communication
Regulatory Reporting
Recovery
Evidence
Lessons Learned22. Security Operations
Section titled “22. Security Operations”Detection capabilities may include:
SIEM
SOC
EDR
NDR
Cloud Monitoring
Identity Monitoring
Application Monitoring23. Business Continuity
Section titled “23. Business Continuity”NIS2 explicitly connects cybersecurity with continuity.
Organizations should prepare for:
Cyberattack
Infrastructure Failure
Supplier Failure
Data Loss
Service Disruption24. Business Continuity Lifecycle
Section titled “24. Business Continuity Lifecycle”Business Impact Analysis ↓Critical Services ↓Recovery Requirements ↓Continuity Strategy ↓Recovery Plans ↓Testing25. Critical Services
Section titled “25. Critical Services”Identify:
Service
Owner
Supporting Systems
Data
People
Suppliers
RTO
RPO26. Disaster Recovery
Section titled “26. Disaster Recovery”Recovery plans should address:
Applications
Infrastructure
Networks
Cloud
Identity
Data
Third Parties27. Backup Management
Section titled “27. Backup Management”Backups should be:
Available
Protected
Recoverable
TestedA backup existing does not prove:
Recovery Capability28. Crisis Management
Section titled “28. Crisis Management”Some incidents exceed normal technical response.
Example:
Ransomware ↓Production Outage ↓Customer Disruption ↓Regulatory Reporting ↓Media AttentionThis requires:
Crisis Management29. Crisis Management Team
Section titled “29. Crisis Management Team”May include:
Executive Leadership
Security
IT
Business
Legal
Compliance
Communications
HR30. Supply Chain Security
Section titled “30. Supply Chain Security”Supply chain security is a major NIS2 requirement.
Organizations increasingly depend on:
Cloud Providers
Software Vendors
MSPs
MSSPs
SaaS Providers
Hardware Vendors
Consultants31. Supply Chain Risk
Section titled “31. Supply Chain Risk”Example:
Organization ↓Software Vendor ↓Compromised Update ↓Organization Compromised32. Supplier Security Lifecycle
Section titled “32. Supplier Security Lifecycle”Identify Supplier ↓Criticality ↓Due Diligence ↓Security Requirements ↓Contract ↓Monitoring ↓Reassessment ↓Exit33. Supplier Criticality
Section titled “33. Supplier Criticality”Assess:
Service Criticality
Data Access
System Access
Business Dependency
Subcontractors
Recovery Dependency34. Supplier Due Diligence
Section titled “34. Supplier Due Diligence”Review:
Security Program
Certifications
Incident History
Access Controls
Encryption
Vulnerability Management
Business Continuity
Incident Response35. Contract Security
Section titled “35. Contract Security”Contracts should establish appropriate requirements for:
Security
Incident Notification
Data Protection
Access
Audit
Continuity
Termination36. Supplier Monitoring
Section titled “36. Supplier Monitoring”Vendor risk does not stop after:
Contract SigningMonitor:
Security Posture
Incidents
Findings
Certifications
Service Changes
Subcontractors37. Vulnerability Management
Section titled “37. Vulnerability Management”Organizations need structured processes for:
Discover ↓Assess ↓Prioritize ↓Remediate ↓Validate38. Vulnerability Prioritization
Section titled “38. Vulnerability Prioritization”Consider:
CVSS
Exploitability
Internet Exposure
Asset Criticality
Threat Intelligence
Business Impact39. Vulnerability Disclosure
Section titled “39. Vulnerability Disclosure”Organizations should establish appropriate processes for handling vulnerability information.
Conceptually:
Vulnerability Reported ↓Validate ↓Assess ↓Remediate ↓Communicate40. Secure Development
Section titled “40. Secure Development”Security should be integrated into:
Design
Development
Testing
Deployment
Maintenance41. Secure SDLC
Section titled “41. Secure SDLC”Requirements ↓Threat Modeling ↓Secure Coding ↓Security Testing ↓Deployment ↓Monitoring42. Application Security Testing
Section titled “42. Application Security Testing”May include:
SAST
DAST
SCA
Secrets Scanning
Container Scanning
Penetration Testing43. Software Supply Chain
Section titled “43. Software Supply Chain”Modern applications depend heavily on:
Libraries
Packages
Containers
APIs
CI/CD
RepositoriesThese dependencies must be governed.
44. Cybersecurity Effectiveness
Section titled “44. Cybersecurity Effectiveness”Organizations should assess whether security measures actually work.
Control Designed ↓Implemented ↓Operating ↓Effective45. Control Testing
Section titled “45. Control Testing”Test areas such as:
MFA
Backups
Logging
EDR
Firewalls
Incident Response
Recovery
Vendor Controls46. Security Metrics
Section titled “46. Security Metrics”Examples:
MFA Coverage
Critical Patch Compliance
EDR Coverage
Logging Coverage
Backup Success
Recovery Test Success
Critical Findings
Incident Response Time47. Cryptography
Section titled “47. Cryptography”NIS2 includes policies and procedures concerning:
Cryptographyand where appropriate:
Encryption48. Encryption
Section titled “48. Encryption”Protect sensitive information:
Data at Rest
Data in Transitusing appropriate cryptographic controls.
49. Key Management
Section titled “49. Key Management”Encryption depends on:
Key Generation
Storage
Rotation
Access
Revocation
Destruction50. Access Control
Section titled “50. Access Control”Organizations should establish:
Identity Governance
Authentication
Authorization
Least Privilege
Privileged Access
Access Reviews51. Identity Lifecycle
Section titled “51. Identity Lifecycle”Joiner ↓Access Provisioning ↓Role Change ↓Access Review ↓Leaver ↓Access Removal52. Privileged Access
Section titled “52. Privileged Access”Administrative access should receive stronger controls.
Privileged Account ↓MFA ↓PAM ↓Approval ↓Monitoring53. Multi-Factor Authentication
Section titled “53. Multi-Factor Authentication”NIS2 includes the use of:
Multi-Factor Authenticationor continuous authentication solutions where appropriate.
54. Secure Communications
Section titled “54. Secure Communications”Organizations should consider secure:
Voice
Video
Text
Emergency Communicationwhere appropriate.
55. Human Security
Section titled “55. Human Security”Technology alone cannot provide resilience.
Employees should understand:
Phishing
Passwords
MFA
Data Handling
Incident Reporting
Social Engineering56. Cybersecurity Training
Section titled “56. Cybersecurity Training”Training should be:
Role Based
Periodic
Relevant
Measured57. Significant Incidents
Section titled “57. Significant Incidents”NIS2 establishes reporting requirements for incidents having significant impact on the provision of services.
The organization therefore needs:
Incident ↓Impact Assessment ↓Significant? / \ No Yes ↓Regulatory Reporting58. Significant Incident Assessment
Section titled “58. Significant Incident Assessment”Consider factors such as:
Service Disruption
Users Affected
Duration
Financial Loss
Operational Impact
Cross-Border Impactusing applicable legal criteria.
59. NIS2 Incident Reporting Lifecycle
Section titled “59. NIS2 Incident Reporting Lifecycle”One of the most important operational requirements is the staged reporting process.
Conceptually:
Significant Incident ↓Early Warning ↓Incident Notification ↓Intermediate Reporting ↓Final Report60. Early Warning
Section titled “60. Early Warning”For a reportable significant incident, NIS2 establishes an:
Early Warninggenerally within:
24 Hoursof becoming aware of the significant incident.
61. Incident Notification
Section titled “61. Incident Notification”A more detailed:
Incident Notificationgenerally follows within:
72 Hoursof becoming aware of the significant incident.
62. Intermediate Report
Section titled “62. Intermediate Report”Competent authorities or CSIRTs may request:
IntermediateStatus Reportsas the incident develops.
63. Final Report
Section titled “63. Final Report”A:
Final Reportis generally required no later than:
One Monthafter the incident notification.
Exact reporting obligations must be implemented according to applicable NIS2 and national requirements.
64. Reporting Workflow
Section titled “64. Reporting Workflow”Organizations should not discover reporting requirements during an incident.
Create:
Incident Detected ↓Security Triage ↓NIS2 Assessment ↓Legal / Compliance ↓Reportable? ↓Regulatory Workflow65. Reporting Matrix
Section titled “65. Reporting Matrix”Maintain:
Incident
Threshold
Regulator
Early Warning
Notification
Final Report
Owner66. Reporting Ownership
Section titled “66. Reporting Ownership”Define who:
Detects
Classifies
Approves
Submits
Tracks
Closesregulatory reports.
67. Incident Evidence
Section titled “67. Incident Evidence”Retain:
Timeline
Logs
Impact Assessment
Decisions
Communications
Notifications
Root Cause
Corrective Actions68. Supervision
Section titled “68. Supervision”NIS2 strengthens supervisory capabilities.
Authorities may use mechanisms such as:
Requests for Information
Security Audits
Inspections
Evidence Reviews
Compliance Ordersdepending on entity classification and national implementation.
69. Essential vs Important Supervision
Section titled “69. Essential vs Important Supervision”A major conceptual distinction is:
Essential Entities ↓More ProactiveSupervisory Regimewhile:
Important Entities ↓Generally MoreReactive SupervisionThe precise supervisory model depends on applicable law.
70. Enforcement
Section titled “70. Enforcement”Failure to comply can result in:
Corrective Orders
Supervisory Measures
Administrative Fines
Management Consequences71. Executive Accountability
Section titled “71. Executive Accountability”This is one of the most important lessons from NIS2:
Cyber Risk=Enterprise Governancenot simply:
Technical Security72. NIS2 Compliance Program
Section titled “72. NIS2 Compliance Program”A practical implementation program:
Determine Scope ↓Establish Governance ↓Assess Risk ↓Map Requirements ↓Implement Controls ↓Manage Suppliers ↓Build Incident Reporting ↓Test Resilience ↓Collect Evidence ↓Monitor ↓Improve73. Phase 1 — Determine Scope
Section titled “73. Phase 1 — Determine Scope”Identify:
Legal Entities
Countries
Sectors
Services
Organization Size
Essential / Important Status74. Phase 2 — Governance
Section titled “74. Phase 2 — Governance”Establish:
Executive Accountability
Cybersecurity Committee
Risk Ownership
Security Policies
Management Reporting75. Phase 3 — Gap Assessment
Section titled “75. Phase 3 — Gap Assessment”Compare:
NIS2 Requirement ↓Current Control ↓Evidence ↓Gap76. Requirement Register
Section titled “76. Requirement Register”Maintain:
Requirement
National Law
Applicability
Control
Owner
Evidence
Status77. Control Mapping
Section titled “77. Control Mapping”Example:
Enterprise ControlIAM-001
Privileged MFA ↓NIS2 ↓ISO 27001 ↓NIST CSF ↓CIS Controls78. Common Control Framework
Section titled “78. Common Control Framework”Avoid creating:
NIS2 MFA Control
ISO MFA Control
SOC 2 MFA Control
NIST MFA ControlCreate:
One EnterpriseMFA Controland map multiple frameworks to it.
79. Evidence Library
Section titled “79. Evidence Library”Maintain evidence such as:
Policies
Risk Registers
Access Reviews
Vulnerability Reports
Training Records
Incident Records
Recovery Tests
Vendor Assessments
Audit Reports80. Evidence Traceability
Section titled “80. Evidence Traceability”Requirement ↓Control ↓Owner ↓Evidence ↓Test ↓Finding81. NIS2 Gap Register
Section titled “81. NIS2 Gap Register”Example:
Gap ID
Requirement
Current State
Risk
Action
Owner
Due Date
Status82. Example Gap
Section titled “82. Example Gap”Requirement:
Supply ChainSecurityCurrent state:
Critical VendorsIdentifiedGap:
No ContinuousVendor Monitoring83. Remediation
Section titled “83. Remediation”Implement VendorMonitoring Process
Assign Owner
Define Review Frequency
Track Findings
Report Exceptions84. NIS2 Dashboard
Section titled “84. NIS2 Dashboard”Example:
NIS2 CYBERSECURITY DASHBOARD
Critical Cyber Risks 12
Risks Above Appetite 4
Critical Vendors 28
Critical Vendor Findings 7
Critical Vulnerabilities 14
Overdue Patches 9
Open Audit Findings 6
Significant Incidents 2Illustrative only.
85. Executive Reporting
Section titled “85. Executive Reporting”Management needs to know:
What Are OurMaterial Cyber Risks?
Which CriticalServices Are Exposed?
Which ControlsAre Failing?
Which VendorsCreate Material Risk?
Which IncidentsOccurred?
Can We Recover?
What RequiresManagement Action?86. NIS2 and ISO 27001
Section titled “86. NIS2 and ISO 27001”ISO 27001 provides:
Information SecurityManagement SystemNIS2 provides:
Legal CybersecurityObligationsTogether:
ISO 27001 +NIS2 Requirements =Strong ComplianceFoundationBut ISO 27001 certification does not automatically prove full NIS2 compliance.
87. NIS2 and NIST CSF
Section titled “87. NIS2 and NIST CSF”NIST CSF provides:
Govern
Identify
Protect
Detect
Respond
Recoverwhich can help structure many NIS2 cybersecurity capabilities.
88. NIS2 and CIS Controls
Section titled “88. NIS2 and CIS Controls”CIS Controls provide practical technical safeguards such as:
Asset Management
Access Control
Vulnerability Management
Logging
Malware Defenses
Backup
Incident Response89. NIS2 and DORA
Section titled “89. NIS2 and DORA”DORA focuses primarily on:
EU Financial SectorDigital OperationalResilienceNIS2 covers a broader range of:
Essentialand ImportantSectors90. DORA vs NIS2
Section titled “90. DORA vs NIS2”Conceptually:
DORAFinancial SectorOperational ResilienceNIS2Cross-SectorCybersecurityOrganizations must determine which legal regime applies and how sector-specific rules interact.
91. NIS2 and Supply Chain Risk
Section titled “91. NIS2 and Supply Chain Risk”Traditional vendor assessment:
Questionnaire ↓Risk RatingMature NIS2 supply-chain governance:
Criticality ↓Due Diligence ↓Contract ↓Security Monitoring ↓Incident Management ↓Reassessment ↓Exit92. Common Mistake — Treat NIS2 as ISO Certification
Section titled “92. Common Mistake — Treat NIS2 as ISO Certification”NIS2 is:
Legislationnot:
Certification93. Common Mistake — Cybersecurity Owned Only by IT
Section titled “93. Common Mistake — Cybersecurity Owned Only by IT”NIS2 creates:
ManagementAccountability94. Common Mistake — Ignore National Law
Section titled “94. Common Mistake — Ignore National Law”Do not implement:
EU DirectiveOnlywithout reviewing:
Member StateImplementation95. Common Mistake — No Scope Assessment
Section titled “95. Common Mistake — No Scope Assessment”Before implementing controls determine:
Which Entity?
Which Country?
Which Sector?
Essential or Important?
Which Services?96. Common Mistake — Ignore Suppliers
Section titled “96. Common Mistake — Ignore Suppliers”Your strongest internal controls can be undermined by:
Critical SupplierCompromise97. Common Mistake — Questionnaire-Only TPRM
Section titled “97. Common Mistake — Questionnaire-Only TPRM”Supplier security requires:
Assessment+Contracts+Monitoring+Incident Governance+Reassessment98. Common Mistake — No Incident Reporting Playbook
Section titled “98. Common Mistake — No Incident Reporting Playbook”During ransomware is the wrong time to ask:
Do We Needto Notifythe Regulator?99. Common Mistake — Backup Equals Recovery
Section titled “99. Common Mistake — Backup Equals Recovery”Always test:
Can We Restore?
How Long?
How Much DataWill We Lose?100. Common Mistake — Compliance Percentage Only
Section titled “100. Common Mistake — Compliance Percentage Only”Weak reporting:
NIS2 Compliance96%may hide:
Critical ServiceCannot Recoveror:
Privileged AccountsWithout MFA101. End-to-End Example — Healthcare Provider
Section titled “101. End-to-End Example — Healthcare Provider”Organization:
Large EUHealthcare ProviderCritical services:
Patient Records
Clinical Systems
Diagnostic Systems
Identity
Communications102. Step 1 — Scope
Section titled “102. Step 1 — Scope”Determine:
Country
Entity
Sector
Size
NIS2 Applicability103. Step 2 — Critical Services
Section titled “103. Step 2 — Critical Services”Identify:
ElectronicPatient Recordsas a critical service.
104. Step 3 — Dependencies
Section titled “104. Step 3 — Dependencies”Patient Records ↓Clinical Application ↓Database ↓Cloud ↓Identity ↓Network105. Step 4 — Risk
Section titled “105. Step 4 — Risk”Scenario:
RansomwareCompromisesClinical SystemsImpact:
Patient CareDisrupted106. Step 5 — Controls
Section titled “106. Step 5 — Controls”Implement:
MFA
EDR
Segmentation
Backup
SIEM
Vulnerability Management107. Step 6 — Supplier Risk
Section titled “107. Step 6 — Supplier Risk”Cloud provider supports:
Patient RecordsPerform:
Due Diligence
Contract Review
Continuity Assessment
Incident Review
Monitoring108. Step 7 — Recovery
Section titled “108. Step 7 — Recovery”Define:
RTO
RPO
Backup
Failover
Recovery Procedure109. Step 8 — Testing
Section titled “109. Step 8 — Testing”Simulate:
Clinical DatabaseUnavailableMeasure:
Detection
Escalation
Recovery
RTO
Communication110. Step 9 — Incident Reporting
Section titled “110. Step 9 — Incident Reporting”If an incident has significant impact:
Incident ↓NIS2 Classification ↓Early Warning ↓Incident Notification ↓Final Report111. Step 10 — Improvement
Section titled “111. Step 10 — Improvement”Incident / Test ↓Finding ↓Corrective Action ↓Owner ↓Retest112. NIS2 Operating Model
Section titled “112. NIS2 Operating Model”Management Body ↓Cybersecurity Governance ↓Enterprise Risk ↓Critical Services ↓Technology & Suppliers ↓Security Controls ↓Detection ↓Incident Management ↓Continuity ↓Regulatory Reporting ↓Continuous Assurance113. Three Lines Model
Section titled “113. Three Lines Model”First Line
BusinessTechnologySecurity Operations
Own and OperateControlsSecond Line
RiskComplianceGRC
Monitor andChallengeThird Line
Internal Audit
IndependentAssuranceNIS2 Readiness Checklist
Section titled “NIS2 Readiness Checklist”-
legal entities identified.
-
countries identified.
-
sectors identified.
-
size criteria assessed.
-
essential/important classification assessed.
-
national implementation reviewed.
-
applicable regulators identified.
Governance
Section titled “Governance”-
management accountability established.
-
cybersecurity governance defined.
-
policies approved.
-
risk owners assigned.
-
management training established.
-
executive reporting implemented.
Risk Management
Section titled “Risk Management”-
cybersecurity risk methodology established.
-
critical services identified.
-
risks assessed.
-
controls mapped.
-
residual risks calculated.
-
risks above appetite escalated.
Incident Handling
Section titled “Incident Handling”-
incident response plan maintained.
-
severity model established.
-
escalation process established.
-
incident roles assigned.
-
evidence retention established.
-
lessons learned performed.
Business Continuity
Section titled “Business Continuity”-
BIA completed.
-
critical services mapped.
-
RTO established.
-
RPO established.
-
backups protected.
-
recovery procedures maintained.
-
recovery tested.
-
crisis management established.
Supply Chain
Section titled “Supply Chain”-
critical suppliers identified.
-
supplier criticality assessed.
-
due diligence performed.
-
security requirements contractualized.
-
supplier incidents monitored.
-
reassessments performed.
-
findings tracked.
Vulnerability Management
Section titled “Vulnerability Management”-
vulnerability scanning established.
-
prioritization methodology defined.
-
patch SLAs established.
-
critical vulnerabilities tracked.
-
remediation validated.
-
disclosure processes established.
Secure Development
Section titled “Secure Development”-
secure SDLC established.
-
security requirements defined.
-
threat modeling performed where appropriate.
-
code security testing established.
-
dependency scanning implemented.
-
secrets scanning implemented.
Access Control
Section titled “Access Control”-
IAM established.
-
least privilege enforced.
-
MFA implemented.
-
privileged access controlled.
-
access reviews performed.
-
leaver access removed.
Cryptography
Section titled “Cryptography”-
cryptography policy established.
-
encryption requirements defined.
-
key management established.
-
certificate management established.
Incident Reporting
Section titled “Incident Reporting”-
significant-incident criteria documented.
-
24-hour early-warning process established.
-
72-hour notification process established.
-
final-report process established.
-
regulator contacts maintained.
-
reporting ownership assigned.
-
reporting workflow tested.
Assurance
Section titled “Assurance”-
requirement register maintained.
-
controls mapped.
-
evidence retained.
-
controls tested.
-
findings tracked.
-
remediation verified.
-
management reporting established.
NIS2 Deliverables
Section titled “NIS2 Deliverables”After completing this lesson, you should be able to create:
01 NIS2 Applicability Assessment
02 Essential / Important Entity Assessment
03 NIS2 Requirement Register
04 NIS2 Governance Model
05 NIS2 RACI
06 Cybersecurity Risk Register
07 Critical Service Register
08 Critical Service Dependency Map
09 NIS2 Control Framework
10 NIS2 Control Mapping Matrix
11 Cybersecurity Policy Framework
12 Incident Response Plan
13 Significant Incident Assessment Matrix
14 NIS2 Regulatory Reporting Matrix
15 Business Continuity Plan
16 Disaster Recovery Plan
17 Crisis Management Plan
18 Recovery Test Register
19 Critical Supplier Register
20 Supplier Security Assessment
21 Supplier Contract Security Matrix
22 Supplier Monitoring Register
23 Vulnerability Management Standard
24 Secure SDLC Standard
25 Cryptography Standard
26 Identity & Access Control Standard
27 Security Awareness Program
28 NIS2 Evidence Register
29 NIS2 Gap Register
30 NIS2 Executive DashboardPractical Activity — NIS2 Applicability Assessment
Section titled “Practical Activity — NIS2 Applicability Assessment”Scenario:
Organization:European CloudService Provider
Employees:800
Customers:Financial ServicesHealthcareManufacturingDetermine:
Sector
Entity Type
Size
Country
Potential NIS2 Scope
Essential / ImportantClassificationDocument assumptions requiring legal validation.
Practical Activity — Build a Cyber Risk Register
Section titled “Practical Activity — Build a Cyber Risk Register”Create risks for:
Ransomware
Cloud AdministratorCompromise
Critical SupplierFailure
Customer DataBreach
DDoSFor each record:
Likelihood
Impact
Controls
Residual Risk
Owner
TreatmentPractical Activity — Supplier Risk Assessment
Section titled “Practical Activity — Supplier Risk Assessment”Critical provider:
Managed CloudService ProviderAssess:
Security
Access
Data
Incident Response
BCP
Vulnerability Management
Subcontractors
Contract
MonitoringPractical Activity — Incident Reporting Exercise
Section titled “Practical Activity — Incident Reporting Exercise”Scenario:
08:00Ransomware Detected
09:30Customer ServicesUnavailable
12:0010,000 CustomersAffected
14:00Incident DeclaredSignificantBuild the reporting workflow for:
Early Warning
Incident Notification
Intermediate Updates
Final ReportIdentify:
Owner
Approver
Authority
Evidence
TimelinePractical Activity — Recovery Test
Section titled “Practical Activity — Recovery Test”Critical service:
Customer PortalScenario:
Primary DatabaseUnavailableTest:
Detection
Escalation
Failover
Data Recovery
RTO
RPO
Customer CommunicationRecord:
Expected Result
Actual Result
Gap
Owner
Remediation
RetestNIS2 GRC Mindset
Section titled “NIS2 GRC Mindset”When working with NIS2, ask:
Does NIS2Apply to Us?
Which LegalEntities Arein Scope?
Which CountriesDo We Operate In?
Which NationalLaws Apply?
Which SectorAre We In?
Are We anEssential Entity?
Are We anImportant Entity?
Which ServicesAre Critical?
Who OwnsCybersecurity Risk?
Has ManagementApproved theSecurity Measures?
Does ManagementUnderstand the Risk?
Are Cyber RisksDocumented?
Which Risks AreAbove Appetite?
Do We HaveEffective IncidentHandling?
Can We DetectCyberattacks?
Can We Containan Incident?
Can We Recover?
Are BackupsActually Tested?
What HappensDuring a Crisis?
Which SuppliersSupport CriticalServices?
Have We AssessedThose Suppliers?
Do ContractsContain SecurityRequirements?
Are SuppliersContinuouslyMonitored?
How Do WeManage Vulnerabilities?
Are CriticalPatches Applied?
Is SoftwareDeveloped Securely?
Are DependenciesScanned?
Are CryptographicControls Appropriate?
Is MFAImplemented?
Is PrivilegedAccess Controlled?
Are EmployeesTrained?
What Makesan IncidentSignificant?
Who Performsthe NIS2 Assessment?
Who Sendsthe Early Warning?
Can We Meetthe 24-HourRequirement?
Can We Meetthe 72-HourRequirement?
Who Preparesthe Final Report?
Do We RetainEvidence?
Can EveryRequirement Mapto a Control?
Can EveryControl Mapto Evidence?
Are ControlsActually Effective?
Which FindingsAre Overdue?
What DoesManagement Needto Know?
What DecisionIs Required?
Are We SimplyCompliant?
Or Can WeActually Protectand Recoverthe EssentialServices SocietyDepends On?That is the mindset of a GRC professional working with the NIS2 Directive.
Key Takeaways
Section titled “Key Takeaways”-
NIS2 is Directive (EU) 2022/2555.
-
It establishes a higher common level of cybersecurity across the EU.
-
NIS2 significantly expanded the original NIS framework.
-
Organizations can be classified as essential or important entities.
-
Applicability depends on factors including sector, entity type, size, and national implementation.
-
NIS2 makes cybersecurity an executive governance responsibility.
-
Management bodies must approve and oversee cybersecurity risk-management measures.
-
Cybersecurity risk management should address technical, operational, and organizational risk.
-
Incident handling is a core NIS2 requirement.
-
Business continuity, backup, disaster recovery, and crisis management support cyber resilience.
-
Supply chain security is a major NIS2 focus.
-
Critical suppliers should be assessed before and throughout the relationship.
-
Vulnerability handling and disclosure require structured governance.
-
Secure development and software supply-chain security should be integrated into the technology lifecycle.
-
Organizations should assess the effectiveness of cybersecurity controls.
-
Cryptography, access control, MFA, and secure communications form important protective measures.
-
Human security and cybersecurity training remain critical.
-
Significant incidents trigger structured regulatory-reporting obligations.
-
The reporting process can include a 24-hour early warning, 72-hour incident notification, intermediate reporting, and a final report.
-
Organizations should build reporting requirements directly into incident-response procedures.
-
NIS2 strengthens regulatory supervision and enforcement.
-
Essential and important entities can face different supervisory approaches.
-
NIS2 should be mapped into an enterprise control framework rather than creating duplicate compliance controls.
-
ISO 27001, NIST CSF, CIS Controls, and other frameworks can support NIS2 implementation.
-
NIS2 and DORA overlap in cybersecurity and resilience objectives but have different scopes and legal structures.
-
Mature NIS2 programs focus on the resilience of critical services rather than compliance percentages alone.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is NIS2?
-
What EU directive established NIS2?
-
Why was NIS2 introduced?
-
How does NIS2 differ from the original NIS Directive?
-
What is an essential entity?
-
What is an important entity?
-
Which sectors can fall within NIS2?
-
How does organization size affect applicability?
-
Why must national implementation be reviewed?
-
What responsibilities does the management body have?
-
Why is management cybersecurity training important?
-
What are cybersecurity risk-management measures?
-
What does an all-hazards approach mean?
-
What is a cybersecurity risk register?
-
What capabilities support incident handling?
-
Why is business continuity part of cybersecurity resilience?
-
What is RTO?
-
What is RPO?
-
Why should backup restoration be tested?
-
What is crisis management?
-
Why is supply chain security important?
-
How should critical suppliers be identified?
-
What should supplier due diligence evaluate?
-
Why should security requirements appear in contracts?
-
Why is continuous supplier monitoring necessary?
-
What is vulnerability management?
-
What is coordinated vulnerability disclosure?
-
What is secure SDLC?
-
Why does software supply-chain security matter?
-
How should cybersecurity-control effectiveness be evaluated?
-
Why is cryptography important?
-
Why is key management important?
-
What is least privilege?
-
Why should privileged accounts receive stronger controls?
-
How does MFA support NIS2?
-
Why is cybersecurity awareness important?
-
What is a significant incident?
-
What is the NIS2 early warning?
-
What is the general early-warning timeline?
-
What is the incident-notification timeline?
-
What is the purpose of the final report?
-
Why should regulatory reporting be built into incident-response procedures?
-
How does supervision differ between essential and important entities?
-
Why is executive accountability important?
-
What evidence supports NIS2 compliance?
-
How can ISO 27001 support NIS2?
-
How can NIST CSF support NIS2?
-
How can CIS Controls support NIS2?
-
How does NIS2 differ from DORA?
-
What makes an effective NIS2 compliance program?
What’s Next?
Section titled “What’s Next?”➡️ Next: 15 — Framework Selection & Compliance Strategy
You have now examined major enterprise cybersecurity, risk, resilience, privacy, and compliance frameworks individually.
The next challenge is not learning another framework.
It is learning:
Which FrameworkShould We Use?Organizations rarely operate under only one requirement.
A modern enterprise may need to address:
NIST CSF
NIST RMF
CIS Controls
COBIT
ISO 31000
ISO 22301
ISO 27701
HITRUST
FedRAMP
CSA CCM
SWIFT CSCF
RBI / SEBI / IRDAI
DORA
NIS2Implementing each independently creates:
Duplicate Controls
Duplicate Evidence
Duplicate Testing
Compliance Silos
Higher CostInstead, you will learn to build:
Business Requirements ↓Regulatory Obligations ↓Framework Selection ↓Common Control Framework ↓Control Mapping ↓Shared Evidence ↓Continuous AssuranceYou will learn how GRC professionals determine:
Which Framework Applies?
Which Framework ShouldBe Primary?
Which RequirementsOverlap?
Which ControlsCan Be Shared?
Which RequirementsAre Unique?
How Should EvidenceBe Reused?
How Do We AvoidCompliance Duplication?
How Do We BuildOne EnterpriseCompliance Strategy?This brings the entire Enterprise Compliance Frameworks Overview module together.
➡️ Next: 15 — Framework Selection & Compliance Strategy