← All regulations

Directive · CELEX 32022L2555

Directive (EU) 2022/2555 — cybersecurity

Directive — takes legal effect through national transposition, which may be stricter than the base EU text.

View official text on EUR-Lex →

8 obligations

NIS2-021-2a · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(a)

Risk analysis and information security policy

Maintain documented policies on risk analysis and information system security.

Applicable now
Applies to
Essential & important entities
Severity if failed
High
Applies from
18 Oct 2024
Source
NIS2.txt:1709

How this is verified

  • A management-approved risk analysis and information-security policy exists and has been reviewed within a defined interval

    Article 21(2)(a) states the duty but not a review cadence or threshold — the specific interval here is a draft placeholder pending compliance-expert definition, not something the primary text specifies.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2b · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(b)

Incident handling

Maintain a documented incident-handling capability covering detection, response and post-incident review.

Applicable now
Applies to
Essential & important entities
Severity if failed
Critical
Applies from
18 Oct 2024
Source
NIS2.txt:1713

How this is verified

  • Incidents are logged with detection/assessment/response timestamps, and NIS2 Art 23 reporting deadlines are met for qualifying incidents

    Art 23's clock (24h early warning / 72h notification / 1 month final report) is the concrete, quotable threshold here — see the Incident Notification Commitments section. The incident register itself is §3.15, Phase 3 scope.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2c · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(c)

Business continuity, backup and disaster recovery

Maintain business continuity arrangements, including backup management, disaster recovery, and crisis management procedures.

Applicable now
Applies to
Essential & important entities
Severity if failed
Critical
Applies from
18 Oct 2024
Source
NIS2.txt:1717

How this is verified

  • A documented business continuity and disaster recovery plan exists, backups run on a defined schedule, and restores have been tested

    Restore-test cadence and RTO/RPO thresholds aren't specified in the primary text — draft placeholder pending compliance-expert input. Backup APIs can automate the schedule/completion evidence; the restore test itself stays a human process (§3.1).

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2d · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(d)

Supply chain security

Address security-related aspects of relationships with direct suppliers and service providers, including their vulnerabilities and security practices.

Applicable now
Applies to
Essential & important entities
Severity if failed
High
Applies from
18 Oct 2024
Source
NIS2.txt:1721

How this is verified

  • A current supplier/vendor register exists with a security assessment on file for each direct supplier and service provider

    Art 21(3) also requires considering the coordinated supply-chain risk assessments under Article 22(1) — not yet modelled; the Vendor module (§3.14, Phase 3) is where this becomes automatable.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2e · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(e)

Secure development and vulnerability handling

Apply security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.

Applicable now
Applies to
Essential & important entities
Severity if failed
High
Applies from
18 Oct 2024
Source
NIS2.txt:1725

How this is verified

  • A vulnerability handling and disclosure process exists, with vulnerabilities tracked from discovery to remediation

    Scanner/patch-state automation (README: scanner APIs, GitHub/GitLab, patch state) is the intended evidence source — specific remediation SLAs are a draft placeholder pending expert input.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2h · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(h)

Cryptography and encryption policy

Maintain policies and procedures on the use of cryptography and, where appropriate, encryption.

Applicable now
Applies to
Essential & important entities
Severity if failed
High
Applies from
18 Oct 2024
Source
NIS2.txt:1737

How this is verified

  • A documented cryptography/encryption policy exists and encryption is enforced for data classified as requiring it

    Which data classes require encryption depends on the entity's own asset classification (the Asset model is Phase 3 scope) — draft placeholder pending that and expert input.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2i · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(i)

HR security, access control policy and asset management

Maintain human resources security measures, access control policies, and asset management practices.

Applicable now
Applies to
Essential & important entities
Severity if failed
High
Applies from
18 Oct 2024
Source
NIS2.txt:1741

How this is verified

  • An access control policy exists, staff access is provisioned/deprovisioned against HR records, and an asset inventory is maintained

    Deprovisioning-latency threshold and inventory completeness criteria are draft placeholders pending expert input.

Draft — pending expert review

Last verified against primary law 23 Jul 2026

NIS2-021-2j · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(j)

Access control & multi-factor authentication

Staff access must be controlled; MFA for privileged/remote access

Applicable now
Applies to
Essential & important entities
Severity if failed
High
Applies from
18 Oct 2024
Source
NIS2.txt:1745

Pending legislative change: COM(2026) 13 (52026PC0013, proposal only) may add a certification-based compliance pathway — not adopted, does not change this obligation's requirements yet.

How this is verified

  • >= 95% of active users MFA-enabled AND 0 unprotected admin accounts

    Single band only — NIS2 Art 21(1) proportionality (micro/small/medium bands) not yet split out, pending compliance expert input. Also see Implementing Reg §11.7.2: authentication strength should scale with asset classification, which this threshold alone doesn't express (Asset model is Phase 3).

Draft — pending expert review

Last verified against primary law 23 Jul 2026