Directive · CELEX 32022L2555
Directive (EU) 2022/2555 — cybersecurity
Directive — takes legal effect through national transposition, which may be stricter than the base EU text.
View official text on EUR-Lex →8 obligations
NIS2-021-2a · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(a)
Risk analysis and information security policy
Maintain documented policies on risk analysis and information system security.
Applicable now
NIS2-021-2a · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(a)
Risk analysis and information security policy
Maintain documented policies on risk analysis and information system security.
- Applies to
- Essential & important entities
- Severity if failed
- High
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1709
How this is verified
A management-approved risk analysis and information-security policy exists and has been reviewed within a defined interval
Article 21(2)(a) states the duty but not a review cadence or threshold — the specific interval here is a draft placeholder pending compliance-expert definition, not something the primary text specifies.
Last verified against primary law 23 Jul 2026
NIS2-021-2b · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(b)
Incident handling
Maintain a documented incident-handling capability covering detection, response and post-incident review.
Applicable now
NIS2-021-2b · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(b)
Incident handling
Maintain a documented incident-handling capability covering detection, response and post-incident review.
- Applies to
- Essential & important entities
- Severity if failed
- Critical
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1713
How this is verified
Incidents are logged with detection/assessment/response timestamps, and NIS2 Art 23 reporting deadlines are met for qualifying incidents
Art 23's clock (24h early warning / 72h notification / 1 month final report) is the concrete, quotable threshold here — see the Incident Notification Commitments section. The incident register itself is §3.15, Phase 3 scope.
Last verified against primary law 23 Jul 2026
NIS2-021-2c · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(c)
Business continuity, backup and disaster recovery
Maintain business continuity arrangements, including backup management, disaster recovery, and crisis management procedures.
Applicable now
NIS2-021-2c · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(c)
Business continuity, backup and disaster recovery
Maintain business continuity arrangements, including backup management, disaster recovery, and crisis management procedures.
- Applies to
- Essential & important entities
- Severity if failed
- Critical
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1717
How this is verified
A documented business continuity and disaster recovery plan exists, backups run on a defined schedule, and restores have been tested
Restore-test cadence and RTO/RPO thresholds aren't specified in the primary text — draft placeholder pending compliance-expert input. Backup APIs can automate the schedule/completion evidence; the restore test itself stays a human process (§3.1).
Last verified against primary law 23 Jul 2026
NIS2-021-2d · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(d)
Supply chain security
Address security-related aspects of relationships with direct suppliers and service providers, including their vulnerabilities and security practices.
Applicable now
NIS2-021-2d · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(d)
Supply chain security
Address security-related aspects of relationships with direct suppliers and service providers, including their vulnerabilities and security practices.
- Applies to
- Essential & important entities
- Severity if failed
- High
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1721
How this is verified
A current supplier/vendor register exists with a security assessment on file for each direct supplier and service provider
Art 21(3) also requires considering the coordinated supply-chain risk assessments under Article 22(1) — not yet modelled; the Vendor module (§3.14, Phase 3) is where this becomes automatable.
Last verified against primary law 23 Jul 2026
NIS2-021-2e · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(e)
Secure development and vulnerability handling
Apply security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.
Applicable now
NIS2-021-2e · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(e)
Secure development and vulnerability handling
Apply security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.
- Applies to
- Essential & important entities
- Severity if failed
- High
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1725
How this is verified
A vulnerability handling and disclosure process exists, with vulnerabilities tracked from discovery to remediation
Scanner/patch-state automation (README: scanner APIs, GitHub/GitLab, patch state) is the intended evidence source — specific remediation SLAs are a draft placeholder pending expert input.
Last verified against primary law 23 Jul 2026
NIS2-021-2h · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(h)
Cryptography and encryption policy
Maintain policies and procedures on the use of cryptography and, where appropriate, encryption.
Applicable now
NIS2-021-2h · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(h)
Cryptography and encryption policy
Maintain policies and procedures on the use of cryptography and, where appropriate, encryption.
- Applies to
- Essential & important entities
- Severity if failed
- High
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1737
How this is verified
A documented cryptography/encryption policy exists and encryption is enforced for data classified as requiring it
Which data classes require encryption depends on the entity's own asset classification (the Asset model is Phase 3 scope) — draft placeholder pending that and expert input.
Last verified against primary law 23 Jul 2026
NIS2-021-2i · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(i)
HR security, access control policy and asset management
Maintain human resources security measures, access control policies, and asset management practices.
Applicable now
NIS2-021-2i · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(i)
HR security, access control policy and asset management
Maintain human resources security measures, access control policies, and asset management practices.
- Applies to
- Essential & important entities
- Severity if failed
- High
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1741
How this is verified
An access control policy exists, staff access is provisioned/deprovisioned against HR records, and an asset inventory is maintained
Deprovisioning-latency threshold and inventory completeness criteria are draft placeholders pending expert input.
Last verified against primary law 23 Jul 2026
NIS2-021-2j · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(j)
Access control & multi-factor authentication
Staff access must be controlled; MFA for privileged/remote access
Applicable now
NIS2-021-2j · Directive (EU) 2022/2555 — cybersecurity, Article 21(2)(j)
Access control & multi-factor authentication
Staff access must be controlled; MFA for privileged/remote access
- Applies to
- Essential & important entities
- Severity if failed
- High
- Applies from
- 18 Oct 2024
- Source
- NIS2.txt:1745
Pending legislative change: COM(2026) 13 (52026PC0013, proposal only) may add a certification-based compliance pathway — not adopted, does not change this obligation's requirements yet.
How this is verified
>= 95% of active users MFA-enabled AND 0 unprotected admin accounts
Single band only — NIS2 Art 21(1) proportionality (micro/small/medium bands) not yet split out, pending compliance expert input. Also see Implementing Reg §11.7.2: authentication strength should scale with asset classification, which this threshold alone doesn't express (Asset model is Phase 3).
Last verified against primary law 23 Jul 2026