NIS2 Directive (EU) 2022/2555: cited answers and gap reviews
NIS2 sets cybersecurity risk management and incident reporting duties for essential and important entities across the EU. Compliance Colleague covers classification, the Article 21 measures, the Article 23 reporting clock and the implementing regulation for digital providers.
What it covers
- Essential vs important entity classification
- Article 21 risk management measures and Article 20 management duties
- Article 23 incident reporting: 24 hours, 72 hours, one month
- Implementing Regulation (EU) 2024/2690 for digital and managed service providers
- Supply chain security and the interplay with DORA
Questions you can ask
- “Are we an essential or an important entity?”
- “What has to be in the 24-hour early warning?”
- “Which Article 21 measures does ISO 27001 already cover?”
Every answer cites the NIS2 requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- An incident response plan checked against the Article 23 timeline
- A supplier security policy checked against Article 21(2)(d)
- A risk management framework checked against Article 21
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk NIS2 to other standards
With NIS2 in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
Example answers
What it’s built from
Compliance Colleague carries the official text and checks its answers against it: Directive (EU) 2022/2555 (NIS2 Directive) (Publications Office of the European Union (EUR-Lex)); Commission Implementing Regulation (EU) 2024/2690 (technical and methodological requirements; significant incidents) (Publications Office of the European Union (EUR-Lex)).
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More EU & UK standards
GDPR · EU AI Act · DORA · EU Cyber Resilience Act · CSRD
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.