Sentrix

Framework · NIS2

NIS2: ten measures, management liability, 24-hour warning

The EU network and information security directive: ten minimum measures under Article 21, management body accountability and 24-hour incident early warning.

The NIS2 Directive (Directive (EU) 2022/2555) extends the European Union's cybersecurity requirements to “essential” and “important” entities across many sectors, including digital infrastructure, cloud, managed services and manufacturing. Member states had to transpose it by 17 October 2024. Management bodies must approve the security measures and can be held liable for failures.

Key facts

  • 17 October 2024: deadline for member states to transpose the directive.
  • 10: minimum security measures under Article 21(2).
  • 24 h, 72 h, 1 month: early warning, incident notification and final report to the national CSIRT for significant incidents.
  • Management: management bodies approve the measures, oversee implementation and can be held liable.

What NIS2 requires

Article 21 requires essential and important entities to implement “appropriate and proportionate” technical and organizational measures. The ten minimum measures cover everything from risk analysis and incident handling to supply chain security and cryptography.

  1. Art. 21(2)(a): risk analysis and information system security policies
  2. Art. 21(2)(b): incident handling, detection, and response
  3. Art. 21(2)(c): business continuity and crisis management
  4. Art. 21(2)(d): supply chain security, including supplier relationships
  5. Art. 21(2)(e): security in network and information systems acquisition, development and maintenance
  6. Art. 21(2)(f)–(j): effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, MFA and secured communications

What Sentrix provides for NIS2

Management body accountability

NIS2 requires management bodies to approve security measures and oversee implementation. Sentrix provides board-level dashboards, risk appetite documentation, and management sign-off workflows that demonstrate oversight.

Incident notification workflow

24-hour early warning, 72-hour notification and final report within one month: Sentrix automates the classification, timeline tracking, and regulatory template generation for each stage.

Supply chain security (Art. 21(2)(d))

Sentrix maps your vendor risk program to Article 21(2)(d) and continuously monitors your supply chain posture.

Business continuity (Art. 21(2)(c))

Sentrix tracks continuity and recovery test evidence, recovery time objectives, and backup verification with continuous monitoring.

Mapping of the ten measures

Each Article 21 measure is mapped to your existing controls; gaps surface before your national authority finds them.

Crosswalks

  • DORA: lex specialis for financial entities; the shared controls are identified for entities subject to both regimes.
  • ISO 27001: ISO 27001 evidence is mapped to the Article 21 measures and the remaining work is shown.
  • TISAX: automotive suppliers established in the EU may fall under NIS2; TISAX and ISO 27001 controls are mapped to Article 21.
  • GDPR: the data protection regime applicable to the same entities.

Further reading

Third-party risk and financial services solution.

See your NIS2 posture on your real infrastructure.

Contact us

Frequently asked questions

Who is covered by NIS2?
NIS2 applies to “essential” and “important” entities established in the European Union in the sectors listed by the directive, including digital infrastructure, cloud, managed services and manufacturing. Each member state has transposed it into national law, with a deadline of 17 October 2024. Management bodies must approve the security measures and oversee their implementation.
What are the incident notification deadlines under NIS2?
For a significant incident, the directive requires an early warning to the national CSIRT or competent authority within 24 hours, an incident notification within 72 hours and a final report within one month. Sentrix automates the classification, timeline tracking and regulatory template generation for each of the three stages.
Does a financial entity subject to DORA also have to apply NIS2?
DORA is the lex specialis for financial entities: where its requirements apply, they take precedence over those of NIS2 on the same subjects. Entities subject to both regimes manage both from one Sentrix program; the crosswalk identifies the controls that satisfy the NIS2 Article 21 measures and the DORA chapters at the same time.

Let's talk about your compliance program.

Last updated: 2026-09-17