Solution · NIS2
NIS2 obligations, traced to the measures behind them
Directive (EU) 2022/2555 sets cybersecurity risk-management and reporting obligations for essential and important entities; member states had to transpose it by 17 October 2024. Secantra turns the Article 21 measures into adoptable requirements and ties them to your assets, suppliers and evidence.
- Instrument
- Directive (EU) 2022/2555 — transposed into national law
- Applies from
- Transposition deadline 17 October 2024; national dates vary
- Who
- Essential and important entities in 18 sectors — energy, transport, banking, health, digital infrastructure, public administration, manufacturing and more
- Supervision
- National competent authorities and CSIRTs; management bodies personally accountable (Art. 20)
Mapping
What NIS2 asks — and where it lives in Secantra
Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet. Frameworks ship as curated, versioned libraries (ISO/IEC 27001 Annex A 93 requirements, DORA 29, NIS2 21 today) that you extend with tenant requirements — not verbatim reproductions of the legal text.
| NIS2 area | Articles | What is expected | In Secantra | Status |
|---|---|---|---|---|
| Risk-management measures | Art. 21(1)–(2) | Appropriate, proportionate technical, operational and organisational measures — ten named areas. | Each measure adopted as a requirement with applicability; controls and evidence mapped; posture derived per measure. | LIVE |
| Asset management & access control | Art. 21(2)(i) | Human-resources security, access-control policies and asset management. | The CMDB is the asset record; owners, criticality and environments per asset; access policies as governance documents. | LIVE |
| Supply-chain security | Art. 21(2)(d) | Security-related aspects of relationships with direct suppliers and service providers. | Third-party registry linked to the assets and services each supplier provides; supplier risk in the register. Contract records are not in the current release. | PARTLY |
| Incident handling & reporting | Art. 21(2)(b), 23 | Early warning within 24 h, notification within 72 h, final report within one month. | Handling procedures and classification as governance documents; findings for gaps. A dedicated incident workflow is not in the current release. | PARTLY |
| Business continuity & crisis management | Art. 21(2)(c) | Backup management, disaster recovery, crisis management. | Continuity requirements adopted and evidenced today; a dedicated continuity-planning workflow is not in the current release. | PARTLY |
| Cyber hygiene & training | Art. 21(2)(g), 20(2) | Basic cyber-hygiene practices and cybersecurity training, including for management bodies. | Training requirements adopted and evidenced; per-person training tracking is not in the current release. | PLANNED |
How it runs
A NIS2 programme in Secantra
- 01
Adopt NIS2 v1.x
Pin the published version; decide applicability per measure for essential vs important entity status.
- 02
Map assets and suppliers
Business solutions and services in scope, the assets under them, and the suppliers behind them.
- 03
Attach controls and evidence
Policies, procedures, test results and training records — with recency rules per control.
- 04
Show it from the record
Posture snapshots, open findings, supplier exposure — and generated reports from the record: framework status, risk register, executive summary.
Questions NIS2 teams ask
Our national transposition differs from the directive — how do you handle that?
Frameworks are versioned libraries. National variants are published as their own versions; you adopt the one that binds you and applicability handles the rest.
Does it cover the 24 h / 72 h reporting workflow?
Procedures and classification are governance documents today; a dedicated incident workflow is not in the current release. The page says so rather than implying it.
We are an important entity, not essential — does the scope change?
Yes, and applicability per requirement is how you express it: proportionate scope is a setting, not a workaround.
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.