Skip to content
Secantra

Solution · NIS2

NIS2 obligations, traced to the measures behind them

Directive (EU) 2022/2555 sets cybersecurity risk-management and reporting obligations for essential and important entities; member states had to transpose it by 17 October 2024. Secantra turns the Article 21 measures into adoptable requirements and ties them to your assets, suppliers and evidence.

At a glance
Instrument
Directive (EU) 2022/2555 — transposed into national law
Applies from
Transposition deadline 17 October 2024; national dates vary
Who
Essential and important entities in 18 sectors — energy, transport, banking, health, digital infrastructure, public administration, manufacturing and more
Supervision
National competent authorities and CSIRTs; management bodies personally accountable (Art. 20)

Mapping

What NIS2 asks — and where it lives in Secantra

Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet. Frameworks ship as curated, versioned libraries (ISO/IEC 27001 Annex A 93 requirements, DORA 29, NIS2 21 today) that you extend with tenant requirements — not verbatim reproductions of the legal text.

What NIS2 asks — and where it lives in Secantra
NIS2 areaArticlesWhat is expectedIn SecantraStatus
Risk-management measuresArt. 21(1)–(2)Appropriate, proportionate technical, operational and organisational measures — ten named areas.Each measure adopted as a requirement with applicability; controls and evidence mapped; posture derived per measure.LIVE
Asset management & access controlArt. 21(2)(i)Human-resources security, access-control policies and asset management.The CMDB is the asset record; owners, criticality and environments per asset; access policies as governance documents.LIVE
Supply-chain securityArt. 21(2)(d)Security-related aspects of relationships with direct suppliers and service providers.Third-party registry linked to the assets and services each supplier provides; supplier risk in the register. Contract records are not in the current release.PARTLY
Incident handling & reportingArt. 21(2)(b), 23Early warning within 24 h, notification within 72 h, final report within one month.Handling procedures and classification as governance documents; findings for gaps. A dedicated incident workflow is not in the current release.PARTLY
Business continuity & crisis managementArt. 21(2)(c)Backup management, disaster recovery, crisis management.Continuity requirements adopted and evidenced today; a dedicated continuity-planning workflow is not in the current release.PARTLY
Cyber hygiene & trainingArt. 21(2)(g), 20(2)Basic cyber-hygiene practices and cybersecurity training, including for management bodies.Training requirements adopted and evidenced; per-person training tracking is not in the current release.PLANNED

How it runs

A NIS2 programme in Secantra

  • 01

    Adopt NIS2 v1.x

    Pin the published version; decide applicability per measure for essential vs important entity status.

  • 02

    Map assets and suppliers

    Business solutions and services in scope, the assets under them, and the suppliers behind them.

  • 03

    Attach controls and evidence

    Policies, procedures, test results and training records — with recency rules per control.

  • 04

    Show it from the record

    Posture snapshots, open findings, supplier exposure — and generated reports from the record: framework status, risk register, executive summary.

Questions NIS2 teams ask

Our national transposition differs from the directive — how do you handle that?

Frameworks are versioned libraries. National variants are published as their own versions; you adopt the one that binds you and applicability handles the rest.

Does it cover the 24 h / 72 h reporting workflow?

Procedures and classification are governance documents today; a dedicated incident workflow is not in the current release. The page says so rather than implying it.

We are an important entity, not essential — does the scope change?

Yes, and applicability per requirement is how you express it: proportionate scope is a setting, not a workaround.

See it on your own frameworks

A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.