All frameworks
NISDirective 2022/2555

NIS2 compliance

The EU's raised bar for cyber resilience.

NIS2 significantly expands the EU's cybersecurity rules, covering more sectors and imposing stronger risk-management, incident-reporting and governance obligations — with direct accountability for management bodies and meaningful penalties for non-compliance.

Start from the basics

The standard

NIS2 — EU Directive 2022/2555 on network & information security

Who needs it

Essential and important entities across expanded sectors operating in the EU — energy, transport, health, digital infrastructure, manufacturing, and many providers of digital services.

24h

Incident early-warning window

The basics

What is NIS2?

NIS2 is the EU's upgraded cybersecurity directive, and it caught a lot of companies by surprise. It widens the net far beyond 'critical infrastructure' to cover many more sectors, and it raises the bar on risk management, incident reporting and — notably — holds senior management personally accountable.

If you operate in the EU in energy, transport, health, digital infrastructure, manufacturing, or as a digital-service provider, there's a good chance you're now in scope even if the original NIS directive never applied to you.

Why it matters

What NIS2 does for your business

Non-compliance is a board-level risk

NIS2 puts cyber oversight on management bodies with real penalties — no longer something leadership can quietly delegate to IT.

The clock is unforgiving

A significant incident means an early warning within 24 hours. Being ready, not improvising, is the difference between a controlled response and a public mess.

It's becoming a buyer expectation

As the directive beds in, EU customers increasingly expect suppliers to demonstrate NIS2 alignment. Getting ahead is a commercial advantage.

What it covers

Risk-management measures

A baseline set of technical and organisational measures every entity must implement.

Incident reporting

Early warning within 24h and staged reporting to national authorities.

Management accountability

Leadership is responsible for — and must be trained on — cyber-risk oversight.

Supply-chain security

Address risks arising from suppliers and service providers.

The hard way

NIS2's obligations span technical measures, governance and supply-chain risk — a lot to stand up from scratch, and painful to evidence when a supervisory authority comes knocking.

The easier way, with Compliance One

  • Maps NIS2's risk-management measures to an implementable, evidenced control set.
  • Provides incident workflows aligned to the 24-hour early-warning obligation.
  • Keeps management-level reporting and evidence ready for supervisory scrutiny.
  • EU data-region storage so evidence can stay within the Union.

Do it once, reuse it everywhere. Evidence you collect for NIS2is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

How do we know if we're in scope?
Scope hinges on your sector and size, and the net is much wider than under NIS1 — many mid-sized digital businesses are now covered, so it's worth checking carefully.
What does the 24-hour rule actually require?
An initial early warning to the relevant authority within 24 hours of becoming aware of a significant incident, followed by a fuller report later. Pre-built incident workflows make that achievable.
Does NIS2 overlap with ISO 27001?
Strongly. An ISO 27001 ISMS covers much of what NIS2's risk-management measures expect, so the two reinforce each other — and Compliance One maps between them.

Ready to tackle NIS2?

See exactly how Compliance One maps NIS2 to your environment in a 30-minute walkthrough — and how much of it we handle for you.