Framework · NIS2
NIS2: ten measures, management liability, 24-hour warning
The EU network and information security directive: ten minimum measures under Article 21, management body accountability and 24-hour incident early warning.
The NIS2 Directive (Directive (EU) 2022/2555) extends the European Union's cybersecurity requirements to “essential” and “important” entities across many sectors, including digital infrastructure, cloud, managed services and manufacturing. Member states had to transpose it by 17 October 2024. Management bodies must approve the security measures and can be held liable for failures.
Key facts
- 17 October 2024: deadline for member states to transpose the directive.
- 10: minimum security measures under Article 21(2).
- 24 h, 72 h, 1 month: early warning, incident notification and final report to the national CSIRT for significant incidents.
- Management: management bodies approve the measures, oversee implementation and can be held liable.
What NIS2 requires
Article 21 requires essential and important entities to implement “appropriate and proportionate” technical and organizational measures. The ten minimum measures cover everything from risk analysis and incident handling to supply chain security and cryptography.
- Art. 21(2)(a): risk analysis and information system security policies
- Art. 21(2)(b): incident handling, detection, and response
- Art. 21(2)(c): business continuity and crisis management
- Art. 21(2)(d): supply chain security, including supplier relationships
- Art. 21(2)(e): security in network and information systems acquisition, development and maintenance
- Art. 21(2)(f)–(j): effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, MFA and secured communications
What Sentrix provides for NIS2
Management body accountability
NIS2 requires management bodies to approve security measures and oversee implementation. Sentrix provides board-level dashboards, risk appetite documentation, and management sign-off workflows that demonstrate oversight.
Incident notification workflow
24-hour early warning, 72-hour notification and final report within one month: Sentrix automates the classification, timeline tracking, and regulatory template generation for each stage.
Supply chain security (Art. 21(2)(d))
Sentrix maps your vendor risk program to Article 21(2)(d) and continuously monitors your supply chain posture.
Business continuity (Art. 21(2)(c))
Sentrix tracks continuity and recovery test evidence, recovery time objectives, and backup verification with continuous monitoring.
Mapping of the ten measures
Each Article 21 measure is mapped to your existing controls; gaps surface before your national authority finds them.
Crosswalks
- DORA: lex specialis for financial entities; the shared controls are identified for entities subject to both regimes.
- ISO 27001: ISO 27001 evidence is mapped to the Article 21 measures and the remaining work is shown.
- TISAX: automotive suppliers established in the EU may fall under NIS2; TISAX and ISO 27001 controls are mapped to Article 21.
- GDPR: the data protection regime applicable to the same entities.
Further reading
Third-party risk and financial services solution.
See your NIS2 posture on your real infrastructure.
Frequently asked questions
- Who is covered by NIS2?
- NIS2 applies to “essential” and “important” entities established in the European Union in the sectors listed by the directive, including digital infrastructure, cloud, managed services and manufacturing. Each member state has transposed it into national law, with a deadline of 17 October 2024. Management bodies must approve the security measures and oversee their implementation.
- What are the incident notification deadlines under NIS2?
- For a significant incident, the directive requires an early warning to the national CSIRT or competent authority within 24 hours, an incident notification within 72 hours and a final report within one month. Sentrix automates the classification, timeline tracking and regulatory template generation for each of the three stages.
- Does a financial entity subject to DORA also have to apply NIS2?
- DORA is the lex specialis for financial entities: where its requirements apply, they take precedence over those of NIS2 on the same subjects. Entities subject to both regimes manage both from one Sentrix program; the crosswalk identifies the controls that satisfy the NIS2 Article 21 measures and the DORA chapters at the same time.
Related pages
Framework · DORA
DORA is in force. Your ICT risk framework needs to be too.
The EU Digital Operational Resilience Act for financial entities, applicable since 17 January 2025: ICT risk, incident reporting, testing and ICT third parties.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Framework · TISAX
TISAX: VDA ISA controls, ENX assessment, shared label
The automotive industry's information security standard: VDA ISA questionnaire, three assessment levels, ENX-accredited providers, label valid three years.
Framework · GDPR
GDPR: Article 32, DPIAs and data subject rights, all mapped
The EU regulation for any organization processing data of EU residents: lawful basis, DPIAs, data subject rights, Article 32 measures and processor contracts.
Let's talk about your compliance program.
Last updated: 2026-09-17
