Other frameworks
NIS2: cybersecurity risk management
The NIS2 Directive raises the bar for cybersecurity risk management and incident reporting across essential and important entities in the EU, and puts management bodies personally on the hook for compliance. Support for it in EuroCompliant is complete: every obligation the platform tracks has real, detailed guidance.
Transcript
NIS2 raises the bar for cybersecurity risk management across essential and important entities in the EU, and makes management bodies personally accountable. Support for it here is complete.
One toggle adds all five of the directive's obligations, and every one of them carries real, specific guidance, not a placeholder.
Checklists & Docs can generate a real NIS2 report too: your Article 21 risk-management measures, the Article 23 phased reporting procedure, and where every one of your five obligations actually stands today.
Only NIS2's Article 32 audit readiness is platform managed, evidenced from your audit trail. Article 20's management accountability, Article 21's risk-management measures, and Article 23's incident reporting all need your action.
NIS2's Article 23 sets a phased timeline: an early warning within twenty-four hours, formal notification within seventy-two, and a final report within one month. Know that sequence before you ever need it.
Why this is required
Article 20 makes management bodies accountable: they must approve the cybersecurity risk-management measures and can be held liable for infringements, which is why board-level sign-off and training records matter, not just a policy document nobody read.
Article 21 requires all-hazards risk-management measures covering, among other things, incident handling, supply chain security, and vulnerability disclosure. Article 23 sets a phased incident-reporting timeline: an early warning within 24 hours, a formal notification within 72 hours, and a final report within one month.
Article 24 covers the use of certified ICT products and services where required, and Article 32 concerns supervisory powers: the ability of your competent authority to audit and inspect your compliance directly.
What EuroCompliant does
Enabling NIS2 adds five obligations to your Obligations page, and all five carry real, specific guidance rather than a generic placeholder. Only Article 32 (audit readiness) is platform-managed, auto-evidenced from your audit trail activity.
Article 20, 21, 23 and 24 need your action: management approval and training records, documenting the all-hazards risk-management measures (risk analysis policy, incident handling, business continuity, supply chain security, cryptography, and more) required by Article 21, the phased incident-reporting process itself, and evidence of certified products where you rely on them.
Two document types exist for this framework, a risk-management measures register and a significant-incident notification form, both built to Article 21 and 23's structure.
Walking through it
Enable NIS2
Adds all five obligations to your Obligations page with full guidance.
Open /settings/profile?tab=frameworks →Get management approval on record
Article 20 wants evidence the risk-management measures were actually approved at management level, not just written.
Open /obligations →Rehearse the phased reporting timeline
24-hour early warning, 72-hour notification, one-month final report. Know who does what before you need to move fast.
The law
Governance
Management bodies must approve cybersecurity risk-management measures and can be held accountable for infringements.
Risk-management measures
All-hazards measures covering incident handling, supply chain security, and vulnerability management.
Reporting obligations
Phased incident reporting: early warning within 24 hours, notification within 72 hours, final report within one month.
Supervisory measures
Competent authorities may audit and inspect essential and important entities directly.
Penalties for non-compliance
NIS2 sets maximum fines of at least €10 million or 2% of total worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher, alongside possible personal liability for management bodies.
Frequently asked
Are we an essential or important entity?
NIS2 sets out sector-based criteria (energy, transport, health, digital infrastructure and others) combined with size thresholds. If you're unsure, that determination is worth getting right early, since it affects both your obligations and your penalty exposure.
How is this different from DORA?
NIS2 is the general EU cybersecurity baseline across many sectors. DORA is financial-sector-specific and more prescriptive about ICT third-party risk. A financial entity can be in scope for both at once.
Related guides
DORA: digital operational resilience
What DORA requires of EU financial entities, and the real, working parts of the platform built around it: vendor criticality flags and infrastructure scanning.
Breach notification
The seventy-two hour clock under Article 33, what the notification must contain, and when you must tell individuals directly.
Automated Scanning: Continuous Telemetry and Scan Pipelines
How scheduled scan jobs, 12 scan engines and local PII scrubbing produce dated Article 10/15 evidence without moving data outside the EEA.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial