New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Other frameworks

NIS2: cybersecurity risk management

The NIS2 Directive raises the bar for cybersecurity risk management and incident reporting across essential and important entities in the EU, and puts management bodies personally on the hook for compliance. Support for it in EuroCompliant is complete: every obligation the platform tracks has real, detailed guidance.

Transcript

NIS2 raises the bar for cybersecurity risk management across essential and important entities in the EU, and makes management bodies personally accountable. Support for it here is complete.

One toggle adds all five of the directive's obligations, and every one of them carries real, specific guidance, not a placeholder.

Checklists & Docs can generate a real NIS2 report too: your Article 21 risk-management measures, the Article 23 phased reporting procedure, and where every one of your five obligations actually stands today.

Only NIS2's Article 32 audit readiness is platform managed, evidenced from your audit trail. Article 20's management accountability, Article 21's risk-management measures, and Article 23's incident reporting all need your action.

NIS2's Article 23 sets a phased timeline: an early warning within twenty-four hours, formal notification within seventy-two, and a final report within one month. Know that sequence before you ever need it.

Why this is required

Article 20 makes management bodies accountable: they must approve the cybersecurity risk-management measures and can be held liable for infringements, which is why board-level sign-off and training records matter, not just a policy document nobody read.

Article 21 requires all-hazards risk-management measures covering, among other things, incident handling, supply chain security, and vulnerability disclosure. Article 23 sets a phased incident-reporting timeline: an early warning within 24 hours, a formal notification within 72 hours, and a final report within one month.

Article 24 covers the use of certified ICT products and services where required, and Article 32 concerns supervisory powers: the ability of your competent authority to audit and inspect your compliance directly.

What EuroCompliant does

Enabling NIS2 adds five obligations to your Obligations page, and all five carry real, specific guidance rather than a generic placeholder. Only Article 32 (audit readiness) is platform-managed, auto-evidenced from your audit trail activity.

Article 20, 21, 23 and 24 need your action: management approval and training records, documenting the all-hazards risk-management measures (risk analysis policy, incident handling, business continuity, supply chain security, cryptography, and more) required by Article 21, the phased incident-reporting process itself, and evidence of certified products where you rely on them.

Two document types exist for this framework, a risk-management measures register and a significant-incident notification form, both built to Article 21 and 23's structure.

Walking through it

1

Enable NIS2

Adds all five obligations to your Obligations page with full guidance.

Open /settings/profile?tab=frameworks →
2

Get management approval on record

Article 20 wants evidence the risk-management measures were actually approved at management level, not just written.

Open /obligations →
3

Rehearse the phased reporting timeline

24-hour early warning, 72-hour notification, one-month final report. Know who does what before you need to move fast.

The law

Penalties for non-compliance

NIS2 sets maximum fines of at least €10 million or 2% of total worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher, alongside possible personal liability for management bodies.

Frequently asked

Are we an essential or important entity?

NIS2 sets out sector-based criteria (energy, transport, health, digital infrastructure and others) combined with size thresholds. If you're unsure, that determination is worth getting right early, since it affects both your obligations and your penalty exposure.

How is this different from DORA?

NIS2 is the general EU cybersecurity baseline across many sectors. DORA is financial-sector-specific and more prescriptive about ICT third-party risk. A financial entity can be in scope for both at once.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial