
Nis2 Directive Specialist
- 91 installs
- 451 repo stars
- Updated July 21, 2026
- borghei/claude-skills
nis2-directive-specialist is a Claude Code skill for NIS2 Directive (EU 2022/2555) compliance covering the 10 minimum security measures.
About
nis2-directive-specialist is a skill for assessing compliance with the EU NIS2 Directive (2022/2555) for critical infrastructure entities. It covers the 10 minimum security measures, entity scope and size-threshold analysis, supply chain security, management accountability, and incident reporting readiness. A security or compliance owner uses it when running a NIS2 assessment or determining whether an entity falls in scope.
- NIS2 Directive (EU 2022/2555) compliance across the 10 minimum security measures
- Entity scope and applicability analysis for Essential vs Important entities
- Incident reporting readiness and supply chain security guidance
Nis2 Directive Specialist by the numbers
- 91 all-time installs (skills.sh)
- Ranked #1,044 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
nis2-directive-specialist capabilities & compatibility
- Capabilities
- nist csf specialist · pci dss specialist · compliance assessment · security audit
- Use cases
- security audit
What nis2-directive-specialist says it does
NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities,
covering the 10 minimum security measures.
with Member States required to transpose it into national law by **October 17, 2024**.
npx skills add https://github.com/borghei/claude-skills --skill nis2-directive-specialistAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 91 |
|---|---|
| repo stars | ★ 451 |
| Last updated | July 21, 2026 |
| Repository | borghei/claude-skills ↗ |
What it does
Assess an organization's NIS2 compliance and determine whether it is in scope.
Who is it for?
NIS2 compliance assessments, entity scope analysis, supply chain security, and incident reporting readiness.
Skip if: Non-EU cybersecurity frameworks or general appsec code review.
When should I use this skill?
You need a NIS2 compliance assessment, entity scope analysis, or incident reporting readiness check.
What you get
A NIS2 scope determination and compliance assessment against the 10 minimum security measures.
- Entity scope determination
- NIS2 compliance assessment
- Incident reporting readiness review
By the numbers
- 10 minimum security measures (Article 21)
- Transposition deadline October 17, 2024
- Two entity tiers (Essential, Important)
Files
NIS2 Directive Specialist
Tools and guidance for EU Directive 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive).
---
Table of Contents
- NIS2 Overview
- Scope and Applicability
- 10 Minimum Security Measures
- Incident Reporting Requirements
- Management Accountability
- Supply Chain Security
- Penalties
- NIS2 vs NIS1 Comparison
- Infrastructure Security Checks
- Tools
- Reference Guides
- Compliance Assessment Workflow
- NIS2 Implementation Roadmap
---
NIS2 Overview
The NIS2 Directive (EU 2022/2555) is the EU's updated framework for cybersecurity, replacing the original NIS Directive (EU 2016/1148). It entered into force on January 16, 2023, with Member States required to transpose it into national law by October 17, 2024.
Key objectives:
- Establish a high common level of cybersecurity across the EU
- Harmonize cybersecurity requirements and enforcement
- Expand scope to cover more sectors and entities
- Strengthen incident reporting obligations
- Introduce management accountability for cybersecurity
- Enhance supply chain security requirements
Legal basis: Article 114 TFEU (internal market harmonization)
Relationship to other frameworks:
| Framework | Relationship |
|---|---|
| ISO 27001 | NIS2 measures map closely to ISO 27001 controls |
| GDPR | NIS2 complements GDPR for security of processing |
| CER Directive | Critical Entities Resilience — physical security complement |
| DORA | Lex specialis for financial sector entities |
| Cyber Resilience Act | Product security requirements for hardware/software |
---
Scope and Applicability
Essential Entities (Annex I — High Criticality Sectors)
| Sector | Sub-sectors |
|---|---|
| Energy | Electricity (DSOs, TSOs, producers, storage), oil (pipelines, production, refineries, storage), gas (DSOs, TSOs, LNG, storage), hydrogen, district heating/cooling |
| Transport | Air (carriers, airports, traffic management), rail (infrastructure managers, operators), water (inland, maritime, port operators), road (traffic management, ITS operators) |
| Banking | Credit institutions as defined in Regulation (EU) No 575/2013 |
| Financial market infrastructure | Trading venues, central counterparties |
| Health | Healthcare providers, EU reference laboratories, entities manufacturing pharmaceutical products, entities manufacturing medical devices considered critical during public health emergencies |
| Drinking water | Suppliers and distributors of water intended for human consumption |
| Waste water | Entities collecting, disposing, or treating urban waste water, domestic waste water, or industrial waste water |
| Digital infrastructure | IXPs, DNS providers, TLD registries, cloud computing providers, data center operators, CDN providers, trust service providers, public electronic communications networks, publicly available electronic communications services |
| ICT service management (B2B) | Managed service providers, managed security service providers |
| Public administration | Central government entities, regional government entities at NUTS level 1 and 2 |
| Space | Operators of ground-based infrastructure supporting space-based services |
Important Entities (Annex II — Other Critical Sectors)
| Sector | Sub-sectors |
|---|---|
| Postal and courier services | Providers of postal services including courier services |
| Waste management | Entities carrying out waste management (excluding those for whom waste management is not their principal economic activity) |
| Chemicals | Entities manufacturing, producing, or distributing chemical substances and mixtures |
| Food | Food businesses engaged in wholesale distribution, industrial production, and processing |
| Manufacturing | Medical devices and in vitro diagnostics, computer/electronic/optical products, electrical equipment, machinery and equipment, motor vehicles/trailers, other transport equipment |
| Digital providers | Online marketplaces, online search engines, social networking services platforms |
| Research | Research organizations |
Size Thresholds
| Category | Employees | Annual Turnover | Annual Balance Sheet |
|---|---|---|---|
| Medium enterprise | 50–249 | €10M–€50M | €10M–€43M |
| Large enterprise | 250+ | €50M+ | €43M+ |
Automatic inclusion regardless of size:
- Trust service providers
- TLD name registries
- DNS service providers
- Public electronic communications networks/services
- Public administration entities
- Sole provider of a service in a Member State
- Entity whose disruption could have significant impact on public safety, security, or health
- Entity whose disruption could induce systemic risk (especially cross-border)
Exclusions:
- Micro and small enterprises (generally excluded unless specifically designated)
- National security, public security, defense, law enforcement
- Judiciary, parliaments, central banks
---
10 Minimum Security Measures (Article 21)
All essential and important entities must implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. These measures must be based on an all-hazards approach and cover at minimum:
1. Risk Analysis and Information System Security Policies
Establish and maintain comprehensive risk analysis processes and information security policies covering all information systems.
Requirements:
- Formal risk assessment methodology
- Asset inventory and classification
- Security policy framework (approved by management body)
- Regular policy review cycles (at least annually)
- Risk appetite and tolerance definitions
- Documented risk treatment plans
2. Incident Handling
Implement procedures for detecting, managing, and responding to cybersecurity incidents.
Requirements:
- Incident detection capabilities
- Incident classification and triage procedures
- Incident response plans and playbooks
- Incident escalation procedures
- Post-incident review process
- Integration with CSIRT reporting (see Incident Reporting section)
3. Business Continuity and Crisis Management
Ensure service continuity during and after cybersecurity incidents.
Requirements:
- Business impact analysis (BIA)
- Business continuity plans (BCP)
- Disaster recovery plans (DRP)
- Backup management policies
- Crisis management procedures
- Regular testing of continuity plans (at least annually)
- Recovery time objectives (RTO) and recovery point objectives (RPO)
4. Supply Chain Security
Address security risks in relationships with direct suppliers and service providers.
Requirements:
- Supplier risk assessment process
- Security requirements in contracts with suppliers
- Monitoring of supplier security posture
- Supplier incident notification requirements
- Assessment of aggregate supply chain risks
- Product/service quality and cybersecurity practices of suppliers
5. Security in Network and Information Systems Acquisition, Development, and Maintenance
Integrate security throughout the system lifecycle.
Requirements:
- Secure development lifecycle (SDLC) practices
- Vulnerability management procedures
- Security testing (SAST, DAST, penetration testing)
- Patch management processes
- Change management with security review
- Secure configuration management
6. Policies and Procedures for Assessing Effectiveness
Evaluate whether cybersecurity risk management measures are effective.
Requirements:
- Security metrics and KPIs
- Regular security assessments and audits
- Penetration testing program
- Vulnerability scanning
- Compliance monitoring
- Continuous improvement processes
7. Basic Cyber Hygiene Practices and Cybersecurity Training
Ensure all personnel have adequate cybersecurity awareness and skills.
Requirements:
- Cybersecurity awareness training for all staff
- Role-based security training for technical staff
- Management body cybersecurity training (mandatory under Article 20)
- Phishing simulation exercises
- Security awareness campaigns
- Training records and effectiveness measurement
8. Policies and Procedures Regarding Use of Cryptography and Encryption
Protect data confidentiality and integrity through cryptographic controls.
Requirements:
- Cryptography policy
- Encryption standards for data at rest and in transit
- Key management procedures
- Certificate management
- Cryptographic algorithm selection guidance
- Regular review of cryptographic implementations
9. Human Resources Security, Access Control Policies, and Asset Management
Manage people, access, and assets securely.
Requirements:
- Pre-employment screening and security checks
- Security responsibilities in employment contracts
- Departure procedures (access revocation)
- Role-based access control (RBAC)
- Privileged access management (PAM)
- Asset inventory and ownership
- Acceptable use policies
10. Multi-Factor Authentication, Secured Communications, and Emergency Communications
Deploy strong authentication and secure communication channels.
Requirements:
- MFA for all remote access and privileged accounts
- MFA for access to critical systems
- Continuous authentication where appropriate
- Encrypted communications (TLS 1.2+ minimum)
- Secure emergency communication channels
- Out-of-band communication capabilities
- Secure voice and video communications
---
Incident Reporting Requirements
NIS2 introduces a multi-stage incident reporting regime for significant incidents. An incident is considered significant if it causes or is capable of causing:
- Severe operational disruption or financial loss
- Considerable material or non-material damage to other persons
Reporting Timeline
| Stage | Deadline | Content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Whether the incident is suspected of being caused by unlawful or malicious acts, whether it could have cross-border impact |
| Incident notification | Within 72 hours of becoming aware | Update of early warning, initial assessment of severity and impact, indicators of compromise where applicable |
| Intermediate report | Upon CSIRT/authority request | Status update on incident handling and response |
| Final report | Within 1 month of incident notification | Detailed description of the incident and its root cause, mitigation measures applied and ongoing, cross-border impact if applicable |
Additional Requirements
- Entities must inform recipients of their services without undue delay if the significant incident is likely to adversely affect the provision of those services
- Member States may require entities to use specific platforms or templates
- CSIRTs must provide feedback and guidance within 24 hours of receiving early warning
- Active cyber threats must be reported to recipients of services along with remediation measures
---
Management Accountability (Article 20)
NIS2 introduces personal accountability for management bodies — a significant departure from NIS1.
Key requirements:
1. Approval and oversight: Management bodies must approve cybersecurity risk management measures and oversee their implementation 2. Liability: Management bodies can be held liable for infringements of Article 21 3. Training: Members of management bodies must undergo cybersecurity training and encourage similar training for employees 4. Sufficient knowledge: Management bodies must have sufficient knowledge and skills to assess cybersecurity risks and management practices
Consequences of non-compliance:
- Member States may impose a temporary prohibition on natural persons holding management responsibilities at CEO or legal representative level in essential entities
- Administrative fines and other enforcement measures
- Personal liability for management body members who fail to comply
---
Supply Chain Security Deep-Dive
Supply chain security is one of the most impactful new requirements under NIS2.
Requirements
Entities must take into account:
1. Vulnerabilities specific to each direct supplier and service provider 2. Overall quality of products and cybersecurity practices of suppliers, including secure development procedures 3. Results of coordinated security risk assessments of critical supply chains (per Article 22) 4. Supplier contractual arrangements including:
- Security requirements and certifications
- Right to audit
- Incident notification obligations
- Sub-contractor security requirements
Implementation Framework
Tier 1 — Critical suppliers:
- Full security assessment before onboarding
- Annual security audits or certification verification (ISO 27001, SOC 2)
- Real-time incident notification requirements
- Right to audit clauses
- Exit strategy and data portability requirements
Tier 2 — Important suppliers:
- Security questionnaire and self-assessment
- Periodic security review (biannual)
- Contractual security requirements
- Incident notification within 48 hours
Tier 3 — Standard suppliers:
- Basic security questionnaire
- Annual review of security posture
- Standard contractual security clauses
Coordinated Risk Assessments (Article 22)
The NIS Cooperation Group may carry out coordinated risk assessments of critical supply chains, considering:
- Technical and non-technical risk factors
- Dependencies and potential points of failure
- Risks from non-EU influence on supply chains
---
Penalties
Administrative Fines
| Entity Type | Maximum Fine |
|---|---|
| Essential entities | €10,000,000 or 2% of total worldwide annual turnover, whichever is higher |
| Important entities | €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
Other Enforcement Measures
For essential entities (Article 32):
- Binding instructions
- Orders to implement security audit recommendations
- Orders to bring measures into compliance
- Temporary suspension of certifications or authorizations
- Temporary prohibition of management responsibilities for responsible natural persons
For important entities (Article 33):
- Binding instructions
- Orders to implement security audit recommendations
- Orders to bring measures into compliance
- Administrative fines
Supervisory Regime Differences
| Aspect | Essential Entities | Important Entities |
|---|---|---|
| Supervision | Ex-ante (proactive) | Ex-post (reactive/complaint-based) |
| Audits | Regular security audits | Audits when justified |
| On-site inspections | Yes | Upon reasonable request |
| Management bans | Yes (temporary) | No |
---
NIS2 vs NIS1 Comparison
| Aspect | NIS1 (2016/1148) | NIS2 (2022/2555) |
|---|---|---|
| Scope | 7 sectors, ~10K entities | 18 sectors, ~160K entities |
| Entity classification | OES and DSP | Essential and Important |
| Security measures | General requirements | 10 specific minimum measures |
| Incident reporting | No specific timeline | 24h / 72h / 1 month staged |
| Management accountability | Not specified | Mandatory training, personal liability |
| Supply chain | Not addressed | Explicit requirements |
| Penalties | Set by Member States | Harmonized: €10M/2% or €7M/1.4% |
| Supervision | Varied | Harmonized ex-ante/ex-post |
| Peer review | Limited | Enhanced peer review mechanism |
| Vulnerability disclosure | Not addressed | Coordinated vulnerability disclosure |
| Size threshold | Member State designation | Clear size-cap rules |
| Enforcement | Weak, inconsistent | Strong, harmonized |
---
Infrastructure Security Checks
DNS Security
- DNSSEC implementation is effectively mandatory for DNS service providers and TLD registries under NIS2
- Validate DNSSEC chain of trust for all zones
- Implement DNS monitoring and anomaly detection
- Consider DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) for internal resolution
- Monitor for DNS tunneling and exfiltration
Network Monitoring and Segmentation
- Deploy network monitoring for anomaly detection (Article 21(2)(b))
- Implement network segmentation between critical and non-critical systems
- Monitor east-west traffic within data centers
- Deploy network-based intrusion detection/prevention systems
- Maintain network flow logs for forensic analysis
Endpoint Detection and Response
- Deploy EDR solutions on all endpoints accessing critical systems
- Configure automated threat detection and response
- Maintain endpoint inventory with health status
- Implement application whitelisting for critical systems
- Regular endpoint compliance scanning
MFA Enforcement (Article 21(2)(j))
- Deploy MFA for all remote access
- Enforce MFA for privileged accounts
- Implement MFA for access to critical systems and data
- Consider passwordless authentication where feasible
- Support hardware security keys (FIDO2/WebAuthn) for high-risk accounts
Encryption Requirements
- TLS 1.2 minimum for all external communications; TLS 1.3 preferred
- Encrypt data at rest using AES-256 or equivalent
- Implement end-to-end encryption for sensitive communications
- Deploy certificate management and monitoring
- Regular cryptographic algorithm review
Vulnerability Disclosure Coordination
- Establish a coordinated vulnerability disclosure (CVD) policy
- Designate a vulnerability disclosure contact
- Participate in ENISA's vulnerability database
- Implement responsible disclosure processes
- Track and remediate disclosed vulnerabilities within defined timelines
Physical Security for Critical Infrastructure
- Physical access controls for data centers and critical facilities
- Environmental monitoring (temperature, humidity, water detection)
- Surveillance and intrusion detection systems
- Visitor management and escort procedures
- Physical security testing as part of overall resilience testing
---
Tools
NIS2 Scope Analyzer
Determines whether an organization falls within NIS2 scope and classifies it as Essential or Important.
# Analyze scope interactively
python scripts/nis2_scope_analyzer.py --sector energy --sub-sector electricity --employees 500 --turnover 100
# Full analysis with JSON output
python scripts/nis2_scope_analyzer.py --sector health --sub-sector healthcare_providers --employees 75 --turnover 15 --json
# Generate compliance checklist
python scripts/nis2_scope_analyzer.py --sector digital_infrastructure --sub-sector cloud_computing --employees 200 --turnover 50 --checklist
# Load from config file
python scripts/nis2_scope_analyzer.py --config organization.json --json --output scope_report.jsonFeatures:
- Sector and sub-sector classification against Annex I and Annex II
- Size threshold evaluation (employees, turnover, balance sheet)
- Automatic inclusion detection (DNS providers, TLD registries, etc.)
- Entity type determination (Essential vs Important)
- Applicable obligations summary
- Compliance checklist generation
---
NIS2 Compliance Checker
Assesses compliance against all 10 minimum security measures with per-measure scoring.
# Run full compliance check
python scripts/nis2_compliance_checker.py --config assessment.json
# Generate assessment template
python scripts/nis2_compliance_checker.py --template > assessment.json
# Check specific measures only
python scripts/nis2_compliance_checker.py --config assessment.json --measures 1 2 4 --json
# Generate gap analysis report
python scripts/nis2_compliance_checker.py --config assessment.json --output gap_report.json --jsonFeatures:
- Assessment against all 10 Article 21 minimum measures
- Per-measure compliance scoring (0–100)
- Overall compliance score
- Incident reporting readiness validation
- Supply chain security assessment
- Management accountability verification
- Gap analysis with prioritized remediation recommendations
---
Reference Guides
NIS2 Requirements Guide
Complete coverage of all 10 minimum security measures with implementation guidance, incident reporting procedures, management accountability requirements, supply chain security framework, and ISO 27001 control mapping.
NIS2 Implementation Playbook
12-month implementation roadmap with resource requirements, policy templates, technical controls checklist, training requirements, and cost estimation framework.
---
Compliance Assessment Workflow
Phase 1: Scope Determination
1. Identify sector and sub-sector classification
→ Use NIS2 Scope Analyzer tool
2. Determine entity size (employees, turnover, balance sheet)
3. Check for automatic inclusion criteria
4. Classify as Essential or Important entity
5. Identify applicable Member State transposition requirementsPhase 2: Gap Assessment
1. Document current security posture
2. Map existing controls to NIS2 10 minimum measures
→ Use NIS2 Compliance Checker tool
3. Assess incident reporting readiness
4. Evaluate supply chain security maturity
5. Review management accountability compliance
6. Generate gap analysis reportPhase 3: Remediation Planning
1. Prioritize gaps by risk and regulatory impact
2. Develop remediation roadmap (see Implementation Playbook)
3. Allocate budget and resources
4. Define project milestones and ownership
5. Establish governance structurePhase 4: Implementation
1. Implement technical controls
2. Develop and approve policies
3. Deploy monitoring and detection capabilities
4. Establish incident reporting procedures
5. Conduct supply chain security assessments
6. Train management body and staffPhase 5: Continuous Compliance
1. Regular compliance assessments (quarterly minimum)
2. Annual management body training refresh
3. Incident response exercises (biannual)
4. Supply chain security reviews (annual)
5. Policy review and update cycles
6. Audit preparation and execution---
NIS2 Implementation Roadmap
12-Month Plan
| Month | Phase | Key Activities |
|---|---|---|
| 1–2 | Assessment | Scope determination, gap analysis, current state documentation |
| 3–4 | Planning | Remediation roadmap, budget allocation, governance setup, quick wins |
| 5–6 | Foundation | Core policies, risk framework, asset inventory, management training |
| 7–8 | Implementation | Technical controls, monitoring deployment, incident response setup |
| 9–10 | Supply Chain | Supplier assessments, contractual updates, third-party risk program |
| 11 | Testing | Incident response exercises, penetration testing, compliance validation |
| 12 | Operationalize | Final audit, continuous monitoring, ongoing compliance program launch |
Quick Wins (Month 1–3)
1. Enable MFA for all remote access and privileged accounts 2. Document existing security policies 3. Establish incident reporting contact with national CSIRT 4. Begin management body cybersecurity training 5. Create asset inventory of critical systems 6. Review and update backup procedures
Resource Estimates
| Organization Size | FTE Requirement | Estimated Budget |
|---|---|---|
| Medium (50–249) | 1–2 dedicated + project team | €200K–€500K |
| Large (250–999) | 2–4 dedicated + project team | €500K–€1.5M |
| Enterprise (1000+) | 4–8 dedicated + project team | €1.5M–€5M+ |
---
---
Troubleshooting
| Problem | Likely Cause | Resolution |
|---|---|---|
| Scope Analyzer returns "out of scope" for an entity that should be in scope | Automatic inclusion criteria not triggered; size thresholds not met | Check for automatic inclusion flags (DNS providers, TLD registries, sole provider). Verify --turnover and --employees values. Use --checklist flag to review all criteria. |
| Compliance Checker scores are unexpectedly low | Assessment JSON has missing or null control responses | Run --template to regenerate a fresh assessment template. Ensure every control question has a boolean or score value. |
| Gap report does not cover all 10 measures | --measures flag is filtering output | Remove the --measures flag to assess all 10 Article 21 measures. Verify the config JSON includes all measure sections. |
| Entity classified as "Important" instead of "Essential" | Sector falls under Annex II rather than Annex I | Review sector/sub-sector classification. Annex I sectors produce Essential entities; Annex II sectors produce Important entities. Size also matters. |
| National transposition requirements unclear | Member State has not yet fully transposed NIS2 | As of early 2026, 13 of 27 EU Member States have incomplete transposition. Check the ECSO NIS2 Transposition Tracker for country-specific status. Apply the directive's baseline requirements. |
| Supply chain assessment section incomplete | Supplier tier classification not provided in config | Populate supplier data with tier levels (Critical/Important/Standard) and include contractual security requirements for each tier. |
| Incident reporting readiness score is zero | No incident handling controls documented in assessment | Complete Measure 2 (Incident Handling) controls in the assessment JSON, including detection capabilities, classification procedures, and CSIRT reporting integration. |
---
Success Criteria
- All in-scope entities correctly classified as Essential or Important with documented rationale for the classification decision
- Compliance scores of 70% or higher across all 10 minimum security measures within the first assessment cycle, trending toward 90%+ within 12 months
- Incident reporting procedures tested and validated against the 24h/72h/1-month staged timeline, with documented CSIRT contact and reporting templates
- Management body members have completed mandatory cybersecurity training with documented attendance and knowledge assessment records
- Supply chain security program covers 100% of Tier 1 (critical) suppliers with quality agreements, right-to-audit clauses, and incident notification requirements in contracts
- Gap analysis produces a prioritized remediation roadmap with assigned owners, budgets, and milestone dates for every identified gap
- Quarterly compliance reassessments demonstrate measurable improvement with trending metrics reported to management
---
Scope & Limitations
In Scope:
- NIS2 Directive (EU 2022/2555) compliance assessment and gap analysis
- Entity classification (Essential vs Important) per Annex I and Annex II
- All 10 Article 21 minimum security measures assessment
- Incident reporting readiness evaluation against the multi-stage reporting regime
- Supply chain security framework assessment (Tier 1/2/3 suppliers)
- Management accountability verification per Article 20
- Cross-framework mapping to ISO 27001 controls
Out of Scope:
- National transposition specifics (varies by Member State; the tools assess against the directive baseline, not country-specific implementing legislation)
- Technical penetration testing or vulnerability scanning (use infrastructure-compliance-auditor for technical checks)
- CER Directive (EU 2022/2557) physical resilience requirements (complementary but separate regulation)
- DORA (EU 2022/2554) requirements for financial sector entities (use dora-compliance-expert for lex specialis)
- Legal advice on penalty exposure or liability (consult qualified legal counsel)
- Real-time infrastructure monitoring or SIEM deployment
---
Integration Points
| Skill | Integration |
|---|---|
| information-security-manager-iso27001 | NIS2 measures map closely to ISO 27001 Annex A controls; use ISO 27001 ISMS as the implementation backbone for NIS2 compliance |
| infrastructure-compliance-auditor | Validate technical controls (DNS, TLS, MFA, encryption, monitoring) that satisfy NIS2 Article 21 requirements |
| dora-compliance-expert | DORA is lex specialis for financial sector entities; coordinate NIS2 and DORA assessments to avoid duplication |
| nist-csf-specialist | NIST CSF 2.0 functions map to NIS2 measures; use CSF maturity assessor to benchmark cybersecurity posture |
| soc2-compliance-expert | SOC 2 Trust Services Criteria overlap significantly with NIS2 measures; leverage existing SOC 2 evidence |
| isms-audit-expert | ISO 27001 audit evidence directly supports NIS2 compliance demonstrations |
---
Tool Reference
nis2_scope_analyzer.py
Determines NIS2 applicability and entity classification.
| Flag | Required | Description |
|---|---|---|
--sector | Yes (or --config) | Sector identifier (e.g., energy, health, digital_infrastructure) |
--sub-sector | Yes (or --config) | Sub-sector identifier (e.g., electricity, healthcare_providers, cloud_computing) |
--employees | Yes (or --config) | Number of employees in the organization |
--turnover | Yes (or --config) | Annual turnover in millions of euros |
--config | No | Path to organization JSON config file (alternative to individual flags) |
--json | No | Output results in JSON format |
--checklist | No | Generate a compliance checklist based on entity classification |
--output | No | Path to write the output report file |
nis2_compliance_checker.py
Assesses compliance against all 10 Article 21 minimum security measures.
| Flag | Required | Description |
|---|---|---|
--config | Yes (or --template) | Path to assessment JSON file with control responses |
--template | No | Generate a blank assessment template (pipe to file with >) |
--measures | No | Space-separated list of measure numbers to assess (e.g., 1 2 4). Omit for all 10. |
--json | No | Output results in JSON format |
--output | No | Path to write the gap analysis report |
---
Last Updated: March 2026 Directive Reference: EU 2022/2555 Applicable From: October 17, 2024 (Member State transposition deadline)
NIS2 Implementation Playbook
A 12-month implementation roadmap for achieving NIS2 Directive compliance, including resource requirements, policy templates, technical controls, training, and cost estimation.
---
Table of Contents
- 12-Month Implementation Roadmap
- Resource Requirements
- Policy Templates Needed
- Technical Controls Checklist
- Training Requirements
- Cost Estimation Framework
---
12-Month Implementation Roadmap
Phase 1: Assessment and Foundation (Months 1–3)
Month 1: Scope and Gap Analysis
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Determine NIS2 scope and entity classification | CISO / Legal | Scope determination report |
| 1 | Identify national transposition requirements | Legal / RA | Regulatory requirements register |
| 2 | Conduct current-state assessment against 10 measures | CISO / Security | Baseline assessment report |
| 2 | Inventory existing policies and controls | Security / IT | Control inventory spreadsheet |
| 3 | Perform gap analysis (current vs required) | CISO | Gap analysis report |
| 3 | Identify quick wins (low effort, high impact) | CISO | Quick wins list |
| 4 | Present findings to management body | CISO | Executive briefing |
| 4 | Obtain management body commitment and budget approval | CEO / Board | Signed commitment, budget approval |
Month 2: Planning and Governance
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Establish NIS2 compliance project governance | CISO / PMO | Project charter, RACI matrix |
| 1 | Appoint NIS2 compliance lead and project team | HR / CISO | Team assignment document |
| 2 | Develop detailed remediation roadmap with milestones | Project team | Project plan with Gantt chart |
| 2 | Define KPIs for compliance progress tracking | CISO | KPI dashboard framework |
| 3 | Procure necessary tools and services | Procurement | Procurement plan, vendor selection |
| 3 | Engage external advisors if needed | CISO | Advisory contract |
| 4 | Begin management body cybersecurity training | CISO / Training | Training schedule, initial session |
Month 3: Quick Wins and Foundation
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Enable MFA for all remote access and privileged accounts | IT / Security | MFA deployment report |
| 1 | Register with national CSIRT / competent authority | CISO / Legal | Registration confirmation |
| 2 | Document existing security policies (formalize undocumented practices) | Security | Draft policy documents |
| 2 | Begin comprehensive asset inventory | IT / Security | Initial asset inventory |
| 3 | Establish incident reporting contacts and initial templates | CISO | CSIRT contact register, report templates |
| 3 | Deploy backup verification for critical systems | IT | Backup verification schedule |
| 4 | Complete quick wins implementation | Project team | Quick wins completion report |
Phase 2: Core Implementation (Months 4–8)
Month 4: Risk Framework and Policies
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1–2 | Develop and approve risk assessment methodology | CISO | Risk assessment methodology document |
| 2–3 | Conduct first comprehensive risk assessment | Security | Risk register |
| 3–4 | Develop core information security policies | CISO / Legal | 10+ policy documents |
| 4 | Management body review and approval of policies | Board / CISO | Signed policy approvals |
Month 5: Incident Management
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Develop incident response plan | Security | IR plan document |
| 2 | Create incident playbooks (ransomware, data breach, DDoS, supply chain) | Security | 4+ playbooks |
| 3 | Deploy or enhance SIEM and EDR capabilities | IT / Security | Deployment documentation |
| 3 | Establish 24/7 monitoring capability (internal or MSSP) | CISO | SOC operational documentation |
| 4 | Develop NIS2 incident reporting procedures and templates | CISO / Legal | Reporting procedures, templates for 24h/72h/1mo |
Month 6: Business Continuity and Cryptography
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Conduct Business Impact Analysis | CISO / Business | BIA report |
| 2 | Develop/update BCPs and DRPs | IT / Security | BCP and DRP documents |
| 3 | Implement cryptography policy and encryption standards | Security / IT | Cryptography policy, encryption deployment plan |
| 3 | Deploy key management procedures | Security | Key management procedures |
| 4 | Review and upgrade TLS configurations | IT | TLS audit report |
Month 7: Access Control and HR Security
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Implement RBAC with documented role-permission matrix | IT / Security | RBAC documentation |
| 2 | Deploy PAM solution for privileged accounts | Security / IT | PAM deployment documentation |
| 3 | Establish HR security procedures (screening, contracts, departure) | HR / Security | HR security procedures |
| 4 | Complete comprehensive asset inventory with ownership | IT / Security | Final asset inventory |
Month 8: Secure Development and Vulnerability Management
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Implement SDLC security gates | Development / Security | SDLC security procedures |
| 2 | Deploy vulnerability scanning (internal and external) | Security | Scanning deployment report |
| 3 | Establish patch management procedures with SLAs | IT | Patch management policy |
| 4 | Implement change management with security review | IT / Security | Change management procedures |
Phase 3: Supply Chain and Training (Months 9–10)
Month 9: Supply Chain Security
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Develop supplier classification framework (Tier 1/2/3) | Procurement / Security | Supplier classification criteria |
| 1 | Create supplier register with tier assignments | Procurement | Supplier register |
| 2 | Develop supplier security assessment questionnaires | Security | Assessment questionnaires by tier |
| 2 | Update contract templates with NIS2 security clauses | Legal / Security | Updated contract templates |
| 3 | Begin Tier 1 supplier assessments | Security / Procurement | Tier 1 assessment reports |
| 4 | Assess aggregate supply chain risks (concentration, geopolitical) | CISO | Supply chain risk report |
Month 10: Training and Awareness
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Complete management body cybersecurity training program | CISO / Training | Training completion certificates |
| 2 | Deploy organization-wide cybersecurity awareness training | Training / HR | Training deployment report |
| 3 | Implement phishing simulation program | Security | First simulation results |
| 3 | Deliver role-based training for technical staff | Security / Training | Technical training completion records |
| 4 | Establish ongoing training calendar | Training / CISO | Annual training plan |
Phase 4: Validation and Operationalization (Months 11–12)
Month 11: Testing and Validation
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Conduct BCP/DRP exercise | CISO / IT | Exercise report |
| 2 | Execute incident response tabletop exercise | Security | Exercise report |
| 2 | Test incident reporting procedures (CSIRT notification dry run) | CISO | Test results |
| 3 | Commission external penetration test | Security | Pentest report |
| 4 | Conduct internal compliance audit against all 10 measures | CISO / Audit | Compliance audit report |
Month 12: Operationalize and Continuous Improvement
| Week | Activity | Owner | Deliverable |
|---|---|---|---|
| 1 | Address findings from Month 11 testing and audit | Project team | Remediation tracker |
| 2 | Establish continuous compliance monitoring program | CISO | Monitoring procedures and dashboard |
| 3 | Document compliance evidence repository | CISO / Compliance | Evidence repository |
| 3 | Develop ongoing compliance calendar (reviews, tests, training) | CISO | Annual compliance calendar |
| 4 | Present final compliance status to management body | CISO | Board presentation, compliance status report |
| 4 | Transition from project to BAU (business as usual) | CISO / PMO | Operational handover document |
---
Resource Requirements
Staffing
| Role | Responsibility | Time Commitment | Phase |
|---|---|---|---|
| CISO / Security Lead | Overall NIS2 compliance ownership | 50-80% for 12 months, then ongoing | All |
| NIS2 Project Manager | Day-to-day project coordination | 100% for 12 months | All |
| Security Analyst(s) | Technical implementation, monitoring | 1-3 FTE for 12 months | 2-4 |
| IT Operations | Infrastructure changes, tool deployment | 50% for months 4-8 | 2-3 |
| Legal Counsel | Regulatory interpretation, contracts | 20-30% for months 1-3, 9 | 1, 3 |
| HR Representative | HR security procedures, training | 20% for months 7, 10 | 2, 3 |
| Procurement | Supplier assessments, contracts | 30% for month 9 | 3 |
| External Advisor | Gap analysis, audit, specialized expertise | As needed | 1, 4 |
| Penetration Tester | External pentest | Engagement in month 11 | 4 |
Organization Size Scaling
| Size | Core Team | Extended Team | External Support |
|---|---|---|---|
| Medium (50-249 employees) | 1-2 dedicated | 3-5 part-time | Advisory, pentest |
| Large (250-999 employees) | 2-4 dedicated | 5-10 part-time | Advisory, MSSP, pentest |
| Enterprise (1000+ employees) | 4-8 dedicated | 10-20 part-time | Advisory, MSSP, pentest, audit |
---
Policy Templates Needed
The following policies must be developed or updated to satisfy NIS2 Article 21:
Tier 1: Mandatory Policies (Months 3-4)
| Policy | NIS2 Measure | Priority |
|---|---|---|
| Information Security Policy (overarching) | M1 | Critical |
| Risk Management Policy | M1 | Critical |
| Incident Response Policy | M2 | Critical |
| Business Continuity Policy | M3 | Critical |
| Access Control Policy | M9 | Critical |
| Acceptable Use Policy | M9 | Critical |
Tier 2: Supporting Policies (Months 4-6)
| Policy | NIS2 Measure | Priority |
|---|---|---|
| Supplier Security Policy | M4 | High |
| Secure Development Policy | M5 | High |
| Vulnerability Management Policy | M5 | High |
| Patch Management Policy | M5 | High |
| Change Management Policy | M5 | High |
| Cryptography and Encryption Policy | M8 | High |
| Data Classification Policy | M1, M8 | High |
Tier 3: Operational Policies (Months 6-8)
| Policy | NIS2 Measure | Priority |
|---|---|---|
| Security Monitoring Policy | M6 | High |
| Penetration Testing Policy | M6 | High |
| Cybersecurity Training Policy | M7 | High |
| HR Security Policy | M9 | High |
| Physical Security Policy | M9 | Medium |
| Remote Working Security Policy | M10 | Medium |
| Mobile Device Policy | M9, M10 | Medium |
| Logging and Audit Trail Policy | M2, M6 | Medium |
| Backup and Recovery Policy | M3 | High |
| Network Security Policy | M5 | High |
| Emergency Communication Policy | M10 | High |
---
Technical Controls Checklist
Identity and Access
- [ ] MFA deployed for all remote access
- [ ] MFA deployed for all privileged accounts
- [ ] MFA deployed for critical system access
- [ ] SSO implemented for enterprise applications
- [ ] PAM solution deployed for privileged access management
- [ ] RBAC implemented with documented role-permission matrix
- [ ] Automated user provisioning/deprovisioning connected to HR
- [ ] Access review process operational (quarterly for critical systems)
- [ ] FIDO2/WebAuthn supported for high-risk accounts
Network Security
- [ ] Network segmentation between critical and non-critical zones
- [ ] Firewall rules reviewed and minimized
- [ ] IDS/IPS deployed at network perimeter and critical segments
- [ ] VPN with MFA for remote access
- [ ] DNS security controls (DNSSEC where applicable)
- [ ] DDoS mitigation in place for public-facing services
- [ ] Network monitoring for anomaly detection
- [ ] East-west traffic monitoring within data centers
Endpoint Security
- [ ] EDR deployed on all endpoints
- [ ] Full disk encryption on all endpoints
- [ ] Application control/whitelisting for critical systems
- [ ] Automated patch management for endpoints
- [ ] Mobile device management (MDM) for company devices
- [ ] USB device control policies enforced
Data Protection
- [ ] Data at rest encrypted (AES-256 or equivalent)
- [ ] Data in transit encrypted (TLS 1.2+ minimum)
- [ ] Database encryption deployed for sensitive data
- [ ] Backup encryption enabled
- [ ] Key management solution deployed
- [ ] Certificate management and monitoring in place
- [ ] Data classification scheme applied
Monitoring and Detection
- [ ] SIEM deployed with log sources from all critical systems
- [ ] Log retention policy enforced (minimum per regulatory requirement)
- [ ] Alerting rules configured for security events
- [ ] 24/7 monitoring capability (SOC or MSSP)
- [ ] User behavior analytics (UBA/UEBA) for anomaly detection
- [ ] File integrity monitoring for critical systems
Vulnerability Management
- [ ] External vulnerability scanning (weekly minimum)
- [ ] Internal vulnerability scanning (monthly minimum)
- [ ] Web application scanning for public-facing applications
- [ ] Vulnerability prioritization process with SLAs
- [ ] Remediation tracking and reporting
- [ ] Annual external penetration testing
Backup and Recovery
- [ ] Automated backups aligned with RPO requirements
- [ ] 3-2-1 backup strategy implemented
- [ ] Immutable/air-gapped backups for ransomware protection
- [ ] Backup restoration tested quarterly
- [ ] DRP documented and tested annually
- [ ] Recovery procedures validated for all critical systems
Emergency Communications
- [ ] Out-of-band communication channel established
- [ ] Emergency contact lists maintained and accessible offline
- [ ] Crisis communication platform deployed
- [ ] Emergency communication tested biannually
- [ ] Secure messaging platform for sensitive communications
---
Training Requirements
Management Body Training
| Topic | Duration | Frequency | Delivery |
|---|---|---|---|
| NIS2 overview and management obligations | 2 hours | Once (plus refresher) | Workshop |
| Cyber threat landscape (sector-specific) | 1.5 hours | Annually | Briefing |
| Cybersecurity risk management fundamentals | 2 hours | Once | Workshop |
| Incident response oversight | 1 hour | Annually | Tabletop exercise |
| Cybersecurity investment and budgeting | 1 hour | Annually | Briefing |
| Total initial: | 7.5 hours | ||
| Total annual refresh: | 4.5 hours |
All-Staff Awareness Training
| Topic | Duration | Frequency | Delivery |
|---|---|---|---|
| Cybersecurity awareness fundamentals | 1 hour | At onboarding + annually | E-learning |
| Phishing and social engineering | 30 min | Quarterly (simulations) | E-learning + simulation |
| Data handling and classification | 30 min | Annually | E-learning |
| Incident reporting procedures | 20 min | Annually | E-learning |
| Physical security awareness | 20 min | Annually | E-learning |
| Total annual: | ~3 hours |
Technical Staff Training
| Role | Topics | Duration | Frequency |
|---|---|---|---|
| Security team | Incident response, forensics, threat intelligence | 40 hours/year | Ongoing |
| IT operations | Secure configuration, patch management, monitoring | 24 hours/year | Ongoing |
| Developers | Secure coding, OWASP Top 10, SAST/DAST tools | 24 hours/year | Ongoing |
| Network engineers | Network security, segmentation, monitoring | 16 hours/year | Ongoing |
---
Cost Estimation Framework
One-Time Implementation Costs
| Category | Medium (50-249) | Large (250-999) | Enterprise (1000+) |
|---|---|---|---|
| Gap assessment and planning | €20K–€50K | €50K–€100K | €100K–€200K |
| Policy development | €15K–€30K | €30K–€60K | €60K–€120K |
| Technical controls deployment | €50K–€150K | €150K–€400K | €400K–€1.5M |
| SIEM/SOC setup | €30K–€80K | €80K–€200K | €200K–€500K |
| PAM deployment | €15K–€40K | €40K–€100K | €100K–€300K |
| MFA rollout | €10K–€30K | €30K–€80K | €80K–€200K |
| Training program development | €10K–€25K | €25K–€50K | €50K–€100K |
| External penetration testing | €10K–€25K | €25K–€50K | €50K–€150K |
| Legal and advisory | €15K–€40K | €40K–€80K | €80K–€200K |
| Total one-time | €175K–€470K | €470K–€1.12M | €1.12M–€3.27M |
Annual Recurring Costs
| Category | Medium (50-249) | Large (250-999) | Enterprise (1000+) |
|---|---|---|---|
| Dedicated security personnel | €80K–€160K | €200K–€500K | €500K–€1.5M |
| SIEM/SOC operations (or MSSP) | €30K–€60K | €60K–€150K | €150K–€500K |
| Tool licensing | €20K–€50K | €50K–€150K | €150K–€400K |
| Training and awareness | €5K–€15K | €15K–€40K | €40K–€100K |
| Annual penetration testing | €10K–€25K | €25K–€50K | €50K–€150K |
| Audit and compliance | €10K–€25K | €25K–€60K | €60K–€150K |
| Insurance (cyber liability) | €5K–€15K | €15K–€40K | €40K–€100K |
| Total annual | €160K–€350K | €390K–€990K | €990K–€2.9M |
ROI Considerations
The cost of non-compliance significantly exceeds implementation costs:
| Factor | Essential Entity | Important Entity |
|---|---|---|
| Maximum fine | €10M or 2% turnover | €7M or 1.4% turnover |
| Management ban risk | Yes | No |
| Reputational damage | Significant | Moderate |
| Incident response costs (without preparation) | 3-5x higher | 2-3x higher |
Cost Optimization Strategies
1. Leverage existing ISO 27001 certification — Organizations with ISO 27001 can reduce implementation costs by 30-40% 2. Use managed security services — MSSP can be more cost-effective than building internal SOC for medium enterprises 3. Prioritize by risk — Address high-risk gaps first, defer lower-risk items 4. Group with related compliance — Combine NIS2 with GDPR, DORA, or ISO 27001 implementation for shared controls 5. Automate where possible — Invest in automated vulnerability scanning, compliance monitoring, and reporting to reduce ongoing personnel costs
---
Last Updated: March 2026 Directive Reference: EU 2022/2555
NIS2 Requirements Guide
Comprehensive reference for implementing all requirements of the NIS2 Directive (EU 2022/2555), including the 10 minimum security measures, incident reporting procedures, management accountability, and supply chain security.
---
Table of Contents
- 10 Minimum Security Measures — Implementation Guidance
- Incident Reporting Procedures
- Management Accountability Requirements
- Supply Chain Security Framework
- ISO 27001 Control Mapping
---
10 Minimum Security Measures — Implementation Guidance
Measure 1: Risk Analysis and Information System Security Policies
Article Reference: Article 21(2)(a)
What is required:
- Formal, documented risk assessment methodology covering all information systems
- Comprehensive asset inventory with classification and ownership
- Information security policy framework approved by the management body
- Regular review and update cycle for policies and risk assessments
Implementation steps:
1. Establish risk assessment methodology
- Select a recognized framework (ISO 27005, NIST SP 800-30, OCTAVE, FAIR)
- Define risk identification, analysis, evaluation, and treatment processes
- Document risk appetite and tolerance thresholds approved by management
- Define criteria for "significant" risks requiring treatment
2. Build asset inventory
- Identify all information systems, hardware, software, data stores, and network components
- Assign ownership for each asset
- Classify assets by criticality and data sensitivity
- Maintain automated discovery and inventory updates
3. Develop policy framework
- Create an overarching information security policy (top-level commitment)
- Develop topic-specific policies: access control, cryptography, physical security, operations security, communications security, system acquisition/development, supplier relationships, incident management, business continuity, compliance
- Ensure management body formally approves each policy
- Establish a policy exception process
4. Implement review cycles
- Annual policy review (minimum) or upon significant changes
- Quarterly risk assessment updates for critical systems
- Annual comprehensive risk reassessment
- Document all review outcomes and actions
Evidence to maintain:
- Risk assessment methodology document
- Risk register with treatment plans
- Asset inventory with last-updated dates
- Signed policy approval records
- Policy review meeting minutes
---
Measure 2: Incident Handling
Article Reference: Article 21(2)(b)
What is required:
- Detection capabilities across all information systems
- Incident classification and triage procedures
- Response plans and playbooks for key scenarios
- Post-incident analysis and lessons learned
Implementation steps:
1. Deploy detection capabilities
- SIEM for log correlation and alerting
- Network intrusion detection/prevention systems (NIDS/NIPS)
- Endpoint detection and response (EDR) on all endpoints
- Application-level monitoring and anomaly detection
- Email security gateway with phishing detection
2. Define classification and triage
- Establish severity levels (Critical, High, Medium, Low, Informational)
- Define classification criteria: impact on services, data affected, geographic scope, financial impact
- Create decision trees for triage
- Define escalation paths for each severity level
3. Develop response playbooks
- Ransomware response playbook
- Data breach response playbook
- DDoS attack response playbook
- Insider threat response playbook
- Supply chain compromise playbook
- Advanced persistent threat (APT) playbook
4. Establish 24/7 response capability
- SOC or on-call rotation covering all hours
- Defined communication channels for incident escalation
- Contact lists for internal teams, management, CSIRT, legal, PR
- War room procedures for major incidents
5. Implement post-incident review
- Mandatory post-incident review for all Medium+ incidents
- Root cause analysis methodology (5-Why, Fishbone)
- Lessons learned documentation
- Tracking of improvement actions to completion
Evidence to maintain:
- Incident response policy and procedures
- Playbook documents for each scenario
- On-call schedule and escalation matrix
- Incident log with classification, response timeline, and outcomes
- Post-incident review reports
---
Measure 3: Business Continuity and Crisis Management
Article Reference: Article 21(2)(c)
What is required:
- Business impact analysis (BIA)
- Business continuity plans (BCP) and disaster recovery plans (DRP)
- Backup management with tested restoration
- Regular testing of all plans
Implementation steps:
1. Conduct Business Impact Analysis
- Identify all critical business functions and supporting systems
- Determine maximum tolerable downtime for each function
- Set Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
- Assess financial, operational, reputational, and regulatory impact of disruption
2. Develop Business Continuity Plans
- Create BCPs for each critical business function
- Define roles and responsibilities during continuity events
- Establish alternate work locations and communication procedures
- Document manual workarounds for critical processes
3. Develop Disaster Recovery Plans
- Create DRPs for each critical system
- Define failover procedures (automated and manual)
- Document system restoration sequences (dependency-aware)
- Establish data validation and integrity checks post-recovery
4. Implement backup management
- Automated backups aligned with RPO requirements
- 3-2-1 backup strategy: 3 copies, 2 media types, 1 offsite
- Immutable backups for ransomware protection
- Regular backup integrity verification
5. Test plans regularly
- Annual full-scale BCP/DRP exercise
- Biannual tabletop exercises for crisis scenarios
- Quarterly backup restoration tests
- Document test results and improvement actions
Evidence to maintain:
- Business Impact Analysis document
- BCP and DRP documents
- Backup configuration and schedule documentation
- Backup restoration test records
- BCP/DRP exercise reports and improvement tracking
---
Measure 4: Supply Chain Security
Article Reference: Article 21(2)(d)
What is required:
- Supplier risk assessment process
- Security requirements in contracts
- Ongoing monitoring of supplier security
- Assessment of aggregate supply chain risks
Implementation steps:
1. Establish supplier classification
- Tier 1 (Critical): Direct access to sensitive systems/data, essential to operations
- Tier 2 (Important): Limited access, important but not essential
- Tier 3 (Standard): No direct access, limited business impact
2. Conduct supplier risk assessments
- Pre-onboarding security assessment (questionnaire, certification check, audit)
- Risk scoring based on access level, data exposure, service criticality
- Annual reassessment for Tier 1, biannual for Tier 2
- Automated continuous monitoring where available
3. Define contractual requirements
- Security baseline requirements proportionate to tier
- Incident notification obligations (24h for Tier 1, 48h for Tier 2)
- Right to audit clause
- Sub-processor and sub-contractor notification and approval
- Data protection and confidentiality
- Exit and transition provisions
4. Monitor aggregate risks
- Identify concentration risks (single points of failure)
- Assess geographic and geopolitical risks
- Evaluate technology stack dependencies
- Review vendor financial stability
Evidence to maintain:
- Supplier register with tier classification
- Supplier risk assessment records
- Contract templates with security clauses
- Supplier audit reports
- Supply chain risk assessment reports
---
Measure 5: Security in Acquisition, Development, and Maintenance
Article Reference: Article 21(2)(e)
What is required:
- Secure development lifecycle (SDLC)
- Vulnerability management
- Patch management
- Change management with security review
Implementation steps:
1. Implement secure SDLC
- Security requirements gathering at design phase
- Threat modeling for new systems and significant changes
- Secure coding standards and developer training
- Static application security testing (SAST) in CI/CD
- Dynamic application security testing (DAST) before release
- Security-focused code reviews
2. Establish vulnerability management
- Regular vulnerability scanning (weekly external, monthly internal)
- Vulnerability prioritization using CVSS + business context
- Defined remediation SLAs: Critical 24-72h, High 1-2 weeks, Medium 1 month, Low quarterly
- Tracking and reporting on vulnerability metrics
3. Implement patch management
- Patch identification and assessment process
- Emergency patch procedures for zero-day vulnerabilities
- Scheduled patch windows with change management approval
- Rollback procedures for failed patches
4. Enforce change management
- All changes reviewed for security impact
- Separation of development, testing, and production environments
- Approval workflows for production changes
- Configuration management and drift detection
Evidence to maintain:
- SDLC documentation and security gates
- Vulnerability scan reports and remediation records
- Patch management records
- Change management logs with security reviews
---
Measure 6: Assessing Effectiveness
Article Reference: Article 21(2)(f)
What is required:
- Cybersecurity metrics and KPIs
- Regular security assessments and audits
- Penetration testing
- Continuous improvement process
Implementation steps:
1. Define cybersecurity metrics
- Mean time to detect (MTTD)
- Mean time to respond (MTTR)
- Patch compliance rate
- Vulnerability count trends (open/closed)
- Phishing simulation click rates
- Security training completion rates
- Incidents by severity and type
2. Conduct regular assessments
- Annual internal security audit covering all 10 measures
- External security audit at least biennially (annually for essential entities)
- Compliance gap assessments against NIS2 requirements
- Control effectiveness testing
3. Implement penetration testing
- Annual external penetration test (network and web application)
- Internal penetration testing for critical systems
- Social engineering assessments
- Red team exercises for mature organizations
4. Drive continuous improvement
- Management review of security metrics (quarterly minimum)
- Formal corrective action process for audit findings
- Security improvement roadmap aligned with risk register
- Benchmarking against industry standards and peers
Evidence to maintain:
- Security dashboard and metrics reports
- Internal and external audit reports
- Penetration test reports and remediation tracking
- Management review minutes and improvement actions
---
Measure 7: Cyber Hygiene and Training
Article Reference: Article 21(2)(g)
What is required:
- Cybersecurity awareness training for all personnel
- Management body cybersecurity training (mandatory)
- Role-based training for technical staff
- Phishing simulations and effectiveness measurement
Implementation steps:
1. General awareness training
- Mandatory at onboarding, annual refresher
- Topics: phishing, social engineering, password hygiene, data handling, physical security, reporting procedures
- Format: interactive e-learning modules with quiz assessment
- Minimum passing score: 80%
2. Management body training
- Dedicated cybersecurity training for board and executive members
- Topics: cyber risk landscape, NIS2 obligations, management liability, incident oversight, cybersecurity investment decisions
- Frequency: at onboarding, then annually
- This is mandatory under Article 20(2)
3. Technical role-based training
- Secure coding training for developers
- Incident response training for SOC/IR teams
- Cloud security training for infrastructure teams
- Security architecture training for architects
4. Simulated exercises
- Quarterly phishing simulations
- Targeted campaigns for high-risk departments (finance, executive, HR)
- Remedial training for repeat clickers
- Track trends over time
Evidence to maintain:
- Training program documentation
- Completion records for all personnel
- Quiz scores and pass rates
- Phishing simulation reports
- Management body training certificates
---
Measure 8: Cryptography and Encryption
Article Reference: Article 21(2)(h)
What is required:
- Cryptography policy
- Encryption for data at rest and in transit
- Key management procedures
- Regular review of cryptographic implementations
Implementation steps:
1. Develop cryptography policy
- Approved algorithms: AES-256 for symmetric, RSA-2048+ or ECDSA P-256+ for asymmetric
- Minimum TLS version: 1.2 (1.3 preferred)
- Prohibited algorithms: DES, 3DES, RC4, MD5, SHA-1 (for security purposes)
- Use cases requiring encryption (data classification driven)
2. Encrypt data at rest
- Database encryption (transparent data encryption or column-level)
- File system encryption for sensitive data
- Backup encryption
- Full disk encryption for endpoints
3. Encrypt data in transit
- TLS 1.2+ for all external communications
- TLS for internal service-to-service communications
- VPN with strong encryption for remote access
- Certificate pinning where appropriate
4. Implement key management
- Key generation using cryptographically secure random number generators
- Key storage in HSMs or secure key management services
- Key rotation schedule (annual minimum, or per use case)
- Key revocation and destruction procedures
5. Review implementations
- Annual review of cryptographic algorithm choices against current guidance (ENISA, NIST)
- TLS configuration testing (SSL Labs grade A minimum)
- Certificate expiry monitoring
- Migration plans for deprecated algorithms
Evidence to maintain:
- Cryptography policy document
- Key management procedures
- TLS configuration audit results
- Certificate inventory with expiry dates
- Cryptographic review records
---
Measure 9: Human Resources Security, Access Control, and Asset Management
Article Reference: Article 21(2)(i)
What is required:
- Pre-employment security checks
- Role-based access control (RBAC) with least privilege
- Privileged access management (PAM)
- Asset inventory with ownership
- Secure departure procedures
Implementation steps:
1. Human resources security
- Background checks proportionate to role sensitivity
- Security clauses in employment contracts
- Confidentiality/NDA agreements
- Clear definition of security responsibilities per role
- Exit interviews with security component
2. Access control
- Implement RBAC with documented role-permission matrices
- Enforce least privilege principle
- Automated provisioning and deprovisioning tied to HR systems
- Access request and approval workflows
- Regular access reviews (quarterly for critical systems, biannual for others)
3. Privileged access management
- PAM solution for credential vaulting and session management
- Just-in-time (JIT) access for administrative tasks
- Session recording for privileged access to critical systems
- Separate administrative accounts from daily-use accounts
- Break-glass procedures for emergency access
4. Asset management
- Automated discovery and inventory of all assets
- Asset classification by criticality and data sensitivity
- Asset ownership assignment and accountability
- End-of-life and disposal procedures for hardware and data
- Acceptable use policies for organizational assets
5. Departure procedures
- Immediate notification from HR to IT upon termination
- Access revocation within 24 hours (immediately for involuntary termination)
- Return of physical assets (laptops, keys, badges, tokens)
- Remote wipe capability for mobile devices
- Transfer of data ownership
Evidence to maintain:
- Background check records (per retention policy)
- Role-permission matrix
- Access review reports
- PAM deployment and session logs
- Asset inventory with ownership records
- Departure checklists with completion dates
---
Measure 10: MFA, Secured Communications, and Emergency Communications
Article Reference: Article 21(2)(j)
What is required:
- Multi-factor authentication for remote, privileged, and critical system access
- End-to-end encrypted communications
- Secured emergency communication channels
- Out-of-band communication capabilities
Implementation steps:
1. Deploy MFA
- All remote access (VPN, cloud services, email)
- All privileged and administrative accounts
- Access to critical systems and sensitive data
- Single sign-on (SSO) with MFA for all enterprise applications
- Support FIDO2/WebAuthn hardware keys for high-risk accounts
- Phishing-resistant MFA where feasible
2. Secured communications
- Encrypted email for sensitive communications (S/MIME or PGP)
- Encrypted instant messaging for business communications
- Encrypted file sharing with access controls
- Secure video conferencing platforms
3. Emergency communications
- Out-of-band communication channel (satellite phones, separate network)
- Emergency contact lists accessible offline
- Pre-established communication protocols for crisis scenarios
- Regular testing of emergency communication channels
Evidence to maintain:
- MFA deployment records and coverage metrics
- MFA exception register (with risk acceptance)
- Emergency communication procedures
- Emergency communication test records
---
Incident Reporting Procedures
Overview
Under Article 23, entities must report significant incidents to the CSIRT or competent authority using a multi-stage process. An incident is significant if it:
- Has caused or is capable of causing severe operational disruption of services or financial loss
- Has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage
Early Warning (Within 24 Hours)
Trigger: Upon becoming aware of a significant incident
Content requirements:
- Whether the incident is suspected of being caused by unlawful or malicious acts
- Whether the incident could have a cross-border impact
- Brief factual description
Template fields:
- Reporting entity identification (name, NIS2 registration)
- Date and time of detection
- Date and time of incident occurrence (if known)
- Brief description of the incident
- Suspected malicious/unlawful activity: Yes / No / Unknown
- Potential cross-border impact: Yes / No / Unknown
- Contact person for follow-up
Incident Notification (Within 72 Hours)
Trigger: 72 hours from becoming aware of the significant incident
Content requirements:
- Update to the early warning information
- Initial assessment of the incident severity and impact
- Indicators of compromise (IoC) where applicable
Template fields:
- Reference to early warning (case ID)
- Updated description of the incident
- Systems and services affected
- Number of users/entities affected
- Geographic scope
- Severity assessment (Critical / High / Medium)
- Root cause assessment (if known at this stage)
- Indicators of compromise (IPs, domains, hashes, signatures)
- Mitigation measures implemented
Intermediate Report (Upon Request)
Trigger: Upon request from CSIRT or competent authority
Content requirements:
- Status update on incident handling and response
- Additional details as requested
Final Report (Within 1 Month)
Trigger: No later than one month after the incident notification
Content requirements:
- Detailed description of the incident, including severity and impact
- Type of threat or root cause that likely triggered the incident
- Applied and ongoing mitigation measures
- Cross-border impact (if applicable)
Template fields:
- Complete incident timeline
- Root cause analysis results
- Full impact assessment (operational, financial, data, reputational)
- Detailed description of mitigation measures
- Lessons learned
- Improvement actions planned
- Cross-border impact details (affected Member States, entities)
---
Management Accountability Requirements
Article 20 Obligations
Management body refers to the governing body of the entity (board of directors, executive management, or equivalent).
Approval and Oversight (Article 20(1))
The management body must:
- Approve the cybersecurity risk management measures adopted under Article 21
- Oversee the implementation of those measures
- Be liable for infringements of Article 21
Implementation guidance:
- Cybersecurity measures must be a formal board/management agenda item
- Management body must receive regular reports on cybersecurity posture
- Approval should be documented in meeting minutes
- A named member should have oversight responsibility for cybersecurity
Training (Article 20(2))
Members of the management body must:
- Undergo training to gain sufficient knowledge and skills to identify cybersecurity risks
- Assess cybersecurity risk management practices and their impact on services
- Encourage similar training for employees on a regular basis
Recommended training topics:
- Current cyber threat landscape relevant to the entity's sector
- NIS2 obligations and management liability
- Cybersecurity risk assessment fundamentals
- Incident response oversight responsibilities
- Cybersecurity investment and resource allocation
- Supply chain cybersecurity risks
Enforcement Implications
For essential entities, Member States may impose:
- Temporary prohibition on natural persons responsible from exercising managerial functions at CEO or legal representative level
- This is a significant personal consequence unique to NIS2
---
Supply Chain Security Framework
Tier-Based Approach
Tier 1 — Critical Suppliers (Direct access to sensitive systems, essential to core operations)
| Requirement | Detail |
|---|---|
| Pre-onboarding | Full security assessment (audit or equivalent) |
| Certification | ISO 27001 or SOC 2 Type II required |
| Contracts | Full security clauses, right to audit, SLAs |
| Incident notification | Within 24 hours |
| Reviews | Annual security audit or certification check |
| Monitoring | Continuous (security rating services, threat intelligence) |
| Exit strategy | Documented transition plan, data return/destruction |
Tier 2 — Important Suppliers (Limited access, important but not essential)
| Requirement | Detail |
|---|---|
| Pre-onboarding | Security questionnaire and self-assessment |
| Certification | ISO 27001 or SOC 2 preferred, not mandatory |
| Contracts | Security requirements, incident notification, NDA |
| Incident notification | Within 48 hours |
| Reviews | Biannual security review |
| Monitoring | Periodic (annual questionnaire refresh) |
Tier 3 — Standard Suppliers (No direct access, limited impact)
| Requirement | Detail |
|---|---|
| Pre-onboarding | Basic security questionnaire |
| Contracts | Standard security clauses, NDA |
| Reviews | Annual self-assessment |
Contractual Security Requirements
Essential clauses for Tier 1 and Tier 2 supplier contracts:
1. Security baseline: Supplier must maintain security measures at least equivalent to industry standards 2. Incident notification: Supplier must notify of any security incident affecting the entity's data or services within defined timeline 3. Right to audit: Entity may audit or commission audit of supplier's security controls 4. Sub-processor notification: Supplier must notify and obtain approval before engaging sub-processors 5. Data protection: Compliance with applicable data protection requirements 6. Business continuity: Supplier must maintain BCP/DRP for services provided 7. Termination and transition: Data return, deletion, and transition assistance obligations 8. Compliance: Supplier must comply with applicable NIS2 requirements
---
ISO 27001 Control Mapping
NIS2 Measure to ISO 27001:2022 Control Mapping
| NIS2 Measure | ISO 27001:2022 Controls |
|---|---|
| M1: Risk analysis and policies | A.5.1 (Policies), A.5.2 (Roles), A.5.9-5.11 (Asset management), Cl.6.1 (Risk assessment), Cl.8.2-8.3 (Risk treatment) |
| M2: Incident handling | A.5.24 (IR planning), A.5.25 (Assessment), A.5.26 (Response), A.5.27 (Learning), A.8.16 (Monitoring) |
| M3: Business continuity | A.5.29 (ICT readiness), A.5.30 (ICT for BC), A.8.13 (Backup), A.8.14 (Redundancy) |
| M4: Supply chain security | A.5.19 (Supplier policy), A.5.20 (Addressing security), A.5.21 (ICT supply chain), A.5.22 (Monitoring), A.5.23 (Cloud services) |
| M5: Acquisition, development, maintenance | A.8.8 (Vulnerability management), A.8.9 (Configuration), A.8.25 (Secure development), A.8.26 (Application security), A.8.27 (Secure architecture), A.8.28 (Secure coding), A.8.29 (Security testing), A.8.31 (Separation), A.8.32 (Change management) |
| M6: Assessing effectiveness | Cl.9.1 (Monitoring/measurement), Cl.9.2 (Internal audit), Cl.9.3 (Management review), Cl.10.1-10.2 (Improvement) |
| M7: Cyber hygiene and training | A.6.3 (Awareness/training), A.6.8 (Information security event reporting) |
| M8: Cryptography and encryption | A.8.24 (Use of cryptography) |
| M9: HR security, access control, asset management | A.6.1 (Screening), A.6.2 (Terms), A.6.4 (Disciplinary), A.6.5 (Termination), A.5.15 (Access control), A.5.16-5.18 (Identity management), A.8.2 (Privileged access), A.8.3 (Access restriction), A.8.5 (Authentication) |
| M10: MFA, secured and emergency communications | A.8.5 (Secure authentication), A.5.14 (Information transfer), A.8.20 (Networks security), A.8.21 (Web services security), A.8.24 (Cryptography) |
Gap Analysis Approach
For organizations already ISO 27001 certified:
1. Map existing ISO 27001 controls to NIS2 measures using the table above 2. Identify NIS2-specific requirements not fully covered by ISO 27001:
- Specific incident reporting timelines (24h/72h/1 month)
- Management body training and personal liability
- Supply chain security at the level of detail required
- Emergency communication channels
3. Conduct gap assessment for these areas 4. Develop remediation plan for identified gaps
Organizations with ISO 27001 certification typically have 60-70% of NIS2 requirements already addressed. Key gaps are usually in incident reporting timelines, management accountability, supply chain depth, and emergency communication.
---
Last Updated: March 2026 Directive Reference: EU 2022/2555, Articles 20-23
#!/usr/bin/env python3
"""
NIS2 Compliance Checker
Assesses organizational compliance against all 10 minimum security measures
defined in Article 21 of the NIS2 Directive (EU 2022/2555). Validates incident
reporting readiness, supply chain security, and management accountability.
Generates per-measure scoring and gap analysis reports.
Usage:
python nis2_compliance_checker.py --template > assessment.json
python nis2_compliance_checker.py --config assessment.json
python nis2_compliance_checker.py --config assessment.json --measures 1 2 4 --json
python nis2_compliance_checker.py --config assessment.json --output gap_report.json --json
"""
import argparse
import json
import sys
from datetime import datetime
from typing import Any, Dict, List, Optional
# --- Assessment Structure ---
MEASURES = {
1: {
"title": "Risk analysis and information system security policies",
"article": "Article 21(2)(a)",
"controls": [
{
"id": "M1.1",
"question": "Is there a formal risk assessment methodology documented and approved?",
"weight": 20,
"iso27001_map": "A.5.1, 6.1.2",
"guidance": "Establish a documented risk assessment methodology covering identification, analysis, evaluation, and treatment of cybersecurity risks.",
},
{
"id": "M1.2",
"question": "Is a comprehensive asset inventory maintained covering all information systems?",
"weight": 15,
"iso27001_map": "A.5.9, A.5.10",
"guidance": "Maintain an up-to-date inventory of all hardware, software, data, and network assets with ownership assignments.",
},
{
"id": "M1.3",
"question": "Are information security policies documented and approved by management?",
"weight": 20,
"iso27001_map": "A.5.1, A.5.2",
"guidance": "Develop a policy framework including an overarching information security policy and supporting topic-specific policies.",
},
{
"id": "M1.4",
"question": "Are risk assessments performed at least annually or upon significant changes?",
"weight": 15,
"iso27001_map": "8.2",
"guidance": "Conduct risk assessments at planned intervals and when significant changes occur to systems, services, or threat landscape.",
},
{
"id": "M1.5",
"question": "Are risk treatment plans documented with clear ownership and timelines?",
"weight": 15,
"iso27001_map": "6.1.3, 8.3",
"guidance": "For each identified risk above tolerance, document a treatment plan specifying controls, responsible owner, and implementation deadline.",
},
{
"id": "M1.6",
"question": "Are policies reviewed and updated at least annually?",
"weight": 15,
"iso27001_map": "A.5.1",
"guidance": "Implement a policy review cycle to ensure policies remain current with evolving threats and business changes.",
},
],
},
2: {
"title": "Incident handling",
"article": "Article 21(2)(b)",
"controls": [
{
"id": "M2.1",
"question": "Are incident detection capabilities deployed (SIEM, IDS/IPS, EDR)?",
"weight": 20,
"iso27001_map": "A.8.16",
"guidance": "Deploy monitoring tools capable of detecting security events across network, endpoint, and application layers.",
},
{
"id": "M2.2",
"question": "Is there a documented incident classification and triage procedure?",
"weight": 15,
"iso27001_map": "A.5.25",
"guidance": "Define incident severity levels, classification criteria, and triage procedures to prioritize response.",
},
{
"id": "M2.3",
"question": "Are incident response plans and playbooks documented for key scenarios?",
"weight": 20,
"iso27001_map": "A.5.26",
"guidance": "Develop response playbooks for common incident types (ransomware, data breach, DDoS, insider threat, supply chain compromise).",
},
{
"id": "M2.4",
"question": "Is there a 24/7 incident response capability or on-call rotation?",
"weight": 15,
"iso27001_map": "A.5.24",
"guidance": "Ensure incidents can be detected and responded to at any time, including weekends and holidays.",
},
{
"id": "M2.5",
"question": "Are post-incident reviews conducted and lessons learned documented?",
"weight": 15,
"iso27001_map": "A.5.27",
"guidance": "Conduct structured post-incident reviews to identify root causes and improve security measures.",
},
{
"id": "M2.6",
"question": "Are incident response exercises conducted at least annually?",
"weight": 15,
"iso27001_map": "A.5.24",
"guidance": "Run tabletop exercises or simulated incident drills to validate response plans and team readiness.",
},
],
},
3: {
"title": "Business continuity and crisis management",
"article": "Article 21(2)(c)",
"controls": [
{
"id": "M3.1",
"question": "Has a business impact analysis (BIA) been conducted?",
"weight": 20,
"iso27001_map": "A.5.30",
"guidance": "Conduct BIA to identify critical business functions, acceptable downtimes (RTO), and data loss tolerances (RPO).",
},
{
"id": "M3.2",
"question": "Are business continuity plans (BCP) documented and approved?",
"weight": 20,
"iso27001_map": "A.5.30",
"guidance": "Develop BCPs for all critical functions identified in the BIA with clear roles, procedures, and contact information.",
},
{
"id": "M3.3",
"question": "Are disaster recovery plans (DRP) in place for critical systems?",
"weight": 20,
"iso27001_map": "A.5.30",
"guidance": "Create technical recovery procedures for each critical system including failover, restoration, and validation steps.",
},
{
"id": "M3.4",
"question": "Are backups performed regularly with tested restoration procedures?",
"weight": 20,
"iso27001_map": "A.8.13",
"guidance": "Implement automated backups aligned with RPO requirements. Test restoration procedures at least quarterly.",
},
{
"id": "M3.5",
"question": "Are BCP/DRP plans tested at least annually?",
"weight": 20,
"iso27001_map": "A.5.30",
"guidance": "Conduct annual BCP/DRP tests ranging from tabletop exercises to full failover tests for critical systems.",
},
],
},
4: {
"title": "Supply chain security",
"article": "Article 21(2)(d)",
"controls": [
{
"id": "M4.1",
"question": "Is there a documented supplier risk assessment process?",
"weight": 20,
"iso27001_map": "A.5.19, A.5.21",
"guidance": "Establish a process to assess cybersecurity risks of suppliers before onboarding and periodically thereafter.",
},
{
"id": "M4.2",
"question": "Do contracts with suppliers include cybersecurity requirements?",
"weight": 20,
"iso27001_map": "A.5.20",
"guidance": "Include security clauses covering data protection, incident notification, right to audit, and sub-contractor requirements.",
},
{
"id": "M4.3",
"question": "Is supplier security posture monitored on an ongoing basis?",
"weight": 15,
"iso27001_map": "A.5.22",
"guidance": "Monitor suppliers through periodic assessments, certification verification, and security rating services.",
},
{
"id": "M4.4",
"question": "Are suppliers required to notify of security incidents?",
"weight": 15,
"iso27001_map": "A.5.20",
"guidance": "Require suppliers to report security incidents that could affect your organization within defined timelines.",
},
{
"id": "M4.5",
"question": "Are aggregate supply chain risks assessed (concentration, geographic, geopolitical)?",
"weight": 15,
"iso27001_map": "A.5.21",
"guidance": "Assess risks from supply chain concentration, single points of failure, and geopolitical factors.",
},
{
"id": "M4.6",
"question": "Are supplier tiers defined with proportionate security requirements?",
"weight": 15,
"iso27001_map": "A.5.19",
"guidance": "Categorize suppliers by criticality (Tier 1/2/3) with proportionate security assessment and monitoring requirements.",
},
],
},
5: {
"title": "Security in network and information systems acquisition, development, and maintenance",
"article": "Article 21(2)(e)",
"controls": [
{
"id": "M5.1",
"question": "Is a secure development lifecycle (SDLC) implemented?",
"weight": 20,
"iso27001_map": "A.8.25, A.8.26",
"guidance": "Integrate security requirements, threat modeling, secure coding, and security testing into the development lifecycle.",
},
{
"id": "M5.2",
"question": "Is there a vulnerability management program with defined SLAs?",
"weight": 20,
"iso27001_map": "A.8.8",
"guidance": "Implement vulnerability scanning, prioritization, and remediation with defined timelines based on severity.",
},
{
"id": "M5.3",
"question": "Is patch management performed with defined timelines?",
"weight": 20,
"iso27001_map": "A.8.8",
"guidance": "Establish patch management procedures with timelines: critical patches within 24-72 hours, high within 1-2 weeks.",
},
{
"id": "M5.4",
"question": "Are security reviews conducted for system changes?",
"weight": 20,
"iso27001_map": "A.8.32",
"guidance": "Require security review and approval for all changes to production systems, including infrastructure and application changes.",
},
{
"id": "M5.5",
"question": "Is secure configuration management applied to all systems?",
"weight": 20,
"iso27001_map": "A.8.9",
"guidance": "Define and enforce security baselines for operating systems, applications, network devices, and cloud services.",
},
],
},
6: {
"title": "Policies and procedures for assessing effectiveness of cybersecurity risk management",
"article": "Article 21(2)(f)",
"controls": [
{
"id": "M6.1",
"question": "Are cybersecurity metrics and KPIs defined and tracked?",
"weight": 20,
"iso27001_map": "9.1",
"guidance": "Define measurable KPIs (mean time to detect, mean time to respond, patch compliance, vulnerability counts, etc.).",
},
{
"id": "M6.2",
"question": "Are regular internal security assessments or audits conducted?",
"weight": 20,
"iso27001_map": "9.2",
"guidance": "Conduct internal security audits at least annually covering all 10 NIS2 minimum measures.",
},
{
"id": "M6.3",
"question": "Is penetration testing performed at least annually?",
"weight": 20,
"iso27001_map": "A.8.8",
"guidance": "Commission external penetration testing annually covering network, web application, and social engineering vectors.",
},
{
"id": "M6.4",
"question": "Is continuous vulnerability scanning operational?",
"weight": 20,
"iso27001_map": "A.8.8",
"guidance": "Run automated vulnerability scans at least weekly for external assets and monthly for internal infrastructure.",
},
{
"id": "M6.5",
"question": "Is there a documented continuous improvement process?",
"weight": 20,
"iso27001_map": "10.1, 10.2",
"guidance": "Implement a process to identify improvement opportunities from audits, incidents, metrics, and external threat intelligence.",
},
],
},
7: {
"title": "Basic cyber hygiene practices and cybersecurity training",
"article": "Article 21(2)(g)",
"controls": [
{
"id": "M7.1",
"question": "Do all employees receive cybersecurity awareness training at onboarding and annually?",
"weight": 25,
"iso27001_map": "A.6.3",
"guidance": "Implement mandatory cybersecurity awareness training for all staff upon hiring and at least annually thereafter.",
},
{
"id": "M7.2",
"question": "Do management body members receive dedicated cybersecurity training?",
"weight": 25,
"iso27001_map": "A.6.3, Article 20(2)",
"guidance": "Mandatory under NIS2 Article 20(2). Management body members must have sufficient knowledge to assess cybersecurity risks.",
},
{
"id": "M7.3",
"question": "Are phishing simulation exercises conducted regularly?",
"weight": 15,
"iso27001_map": "A.6.3",
"guidance": "Run phishing simulations at least quarterly to measure and improve employee resistance to social engineering.",
},
{
"id": "M7.4",
"question": "Is role-based security training provided for technical staff?",
"weight": 20,
"iso27001_map": "A.6.3",
"guidance": "Provide specialized training for IT, security, and development staff on secure coding, incident response, and tool usage.",
},
{
"id": "M7.5",
"question": "Are training records maintained and effectiveness measured?",
"weight": 15,
"iso27001_map": "A.6.3",
"guidance": "Track completion rates, quiz scores, phishing simulation results, and link to security incident trends.",
},
],
},
8: {
"title": "Policies and procedures regarding use of cryptography and encryption",
"article": "Article 21(2)(h)",
"controls": [
{
"id": "M8.1",
"question": "Is there a documented cryptography and encryption policy?",
"weight": 20,
"iso27001_map": "A.8.24",
"guidance": "Define approved cryptographic algorithms, key lengths, and use cases for data at rest, in transit, and in use.",
},
{
"id": "M8.2",
"question": "Is data encrypted at rest using strong algorithms (AES-256 or equivalent)?",
"weight": 20,
"iso27001_map": "A.8.24",
"guidance": "Encrypt sensitive data at rest in databases, file systems, and backups using AES-256 or equivalent.",
},
{
"id": "M8.3",
"question": "Is data encrypted in transit using TLS 1.2+ for all communications?",
"weight": 20,
"iso27001_map": "A.8.24",
"guidance": "Enforce TLS 1.2 minimum (TLS 1.3 preferred) for all external and internal network communications.",
},
{
"id": "M8.4",
"question": "Are key management procedures documented and followed?",
"weight": 20,
"iso27001_map": "A.8.24",
"guidance": "Implement key lifecycle management covering generation, distribution, storage, rotation, and destruction.",
},
{
"id": "M8.5",
"question": "Are cryptographic implementations reviewed for weaknesses periodically?",
"weight": 20,
"iso27001_map": "A.8.24",
"guidance": "Review cryptographic algorithms and implementations against current best practices and deprecation schedules.",
},
],
},
9: {
"title": "Human resources security, access control policies, and asset management",
"article": "Article 21(2)(i)",
"controls": [
{
"id": "M9.1",
"question": "Are pre-employment background checks conducted for sensitive roles?",
"weight": 15,
"iso27001_map": "A.6.1",
"guidance": "Conduct background verification proportionate to role sensitivity, classification of information accessed, and perceived risks.",
},
{
"id": "M9.2",
"question": "Is role-based access control (RBAC) implemented?",
"weight": 20,
"iso27001_map": "A.5.15, A.8.2",
"guidance": "Implement RBAC with least privilege principle. Define roles, map to access permissions, and enforce consistently.",
},
{
"id": "M9.3",
"question": "Is privileged access management (PAM) deployed for administrative accounts?",
"weight": 20,
"iso27001_map": "A.8.2, A.8.18",
"guidance": "Implement PAM solutions for just-in-time access, session recording, and credential vaulting for privileged accounts.",
},
{
"id": "M9.4",
"question": "Are access rights reviewed at least quarterly for critical systems?",
"weight": 15,
"iso27001_map": "A.5.18",
"guidance": "Conduct regular access reviews to verify that permissions remain appropriate and remove stale accounts.",
},
{
"id": "M9.5",
"question": "Are departure procedures ensuring timely access revocation in place?",
"weight": 15,
"iso27001_map": "A.6.5",
"guidance": "Implement automated access revocation triggered by HR departure workflow, effective within 24 hours of termination.",
},
{
"id": "M9.6",
"question": "Is there a comprehensive asset inventory with ownership?",
"weight": 15,
"iso27001_map": "A.5.9, A.5.10, A.5.11",
"guidance": "Maintain a complete inventory of information assets (hardware, software, data, services) with designated owners.",
},
],
},
10: {
"title": "Multi-factor authentication, secured communications, and secured emergency communications",
"article": "Article 21(2)(j)",
"controls": [
{
"id": "M10.1",
"question": "Is MFA enforced for all remote access?",
"weight": 20,
"iso27001_map": "A.8.5",
"guidance": "Require MFA for VPN, remote desktop, cloud services, and any external access to organizational resources.",
},
{
"id": "M10.2",
"question": "Is MFA enforced for all privileged and administrative accounts?",
"weight": 20,
"iso27001_map": "A.8.5",
"guidance": "Require MFA for all accounts with elevated privileges, including system administrators and security personnel.",
},
{
"id": "M10.3",
"question": "Is MFA enforced for access to critical systems and sensitive data?",
"weight": 15,
"iso27001_map": "A.8.5",
"guidance": "Require MFA for access to systems classified as critical or containing sensitive/personal data.",
},
{
"id": "M10.4",
"question": "Are communications encrypted end-to-end for sensitive exchanges?",
"weight": 15,
"iso27001_map": "A.8.24, A.5.14",
"guidance": "Deploy end-to-end encrypted communication tools for confidential business communications.",
},
{
"id": "M10.5",
"question": "Are out-of-band emergency communication channels established and tested?",
"weight": 15,
"iso27001_map": "A.5.24, A.5.30",
"guidance": "Establish alternative communication channels (satellite phones, out-of-band messaging) for crisis situations.",
},
{
"id": "M10.6",
"question": "Are hardware security keys (FIDO2/WebAuthn) supported for high-risk accounts?",
"weight": 15,
"iso27001_map": "A.8.5",
"guidance": "Support phishing-resistant authentication methods such as FIDO2 hardware keys for high-value targets.",
},
],
},
}
INCIDENT_REPORTING_CHECKS = [
{
"id": "IR.1",
"question": "Can the organization issue an early warning within 24 hours of detecting a significant incident?",
"weight": 25,
"reference": "Article 23(4)(a)",
},
{
"id": "IR.2",
"question": "Can the organization submit an incident notification within 72 hours?",
"weight": 25,
"reference": "Article 23(4)(b)",
},
{
"id": "IR.3",
"question": "Can the organization produce a final report within 1 month of incident notification?",
"weight": 20,
"reference": "Article 23(4)(d)",
},
{
"id": "IR.4",
"question": "Is the national CSIRT contact information documented and accessible to incident responders?",
"weight": 15,
"reference": "Article 23",
},
{
"id": "IR.5",
"question": "Are templates prepared for early warning, notification, and final report submissions?",
"weight": 15,
"reference": "Article 23",
},
]
MANAGEMENT_ACCOUNTABILITY_CHECKS = [
{
"id": "MA.1",
"question": "Has the management body formally approved the cybersecurity risk management measures?",
"weight": 30,
"reference": "Article 20(1)",
},
{
"id": "MA.2",
"question": "Does the management body oversee implementation of cybersecurity measures?",
"weight": 25,
"reference": "Article 20(1)",
},
{
"id": "MA.3",
"question": "Have management body members completed cybersecurity training?",
"weight": 25,
"reference": "Article 20(2)",
},
{
"id": "MA.4",
"question": "Is cybersecurity a regular agenda item in management body meetings?",
"weight": 20,
"reference": "Article 20",
},
]
def generate_template() -> Dict[str, Any]:
"""Generate an assessment input template."""
template = {
"_instructions": "Fill in each response with: 'yes', 'partial', 'no', or 'not_applicable'. "
"Add optional 'notes' field for context.",
"organization": {
"name": "Your Organization Name",
"entity_type": "essential or important",
"sector": "e.g., energy",
"assessment_date": datetime.now().strftime("%Y-%m-%d"),
},
"measures": {},
"incident_reporting": {},
"management_accountability": {},
}
for measure_num, measure_data in MEASURES.items():
template["measures"][f"measure_{measure_num}"] = {
"title": measure_data["title"],
"controls": {},
}
for control in measure_data["controls"]:
template["measures"][f"measure_{measure_num}"]["controls"][control["id"]] = {
"question": control["question"],
"response": "yes | partial | no | not_applicable",
"notes": "",
}
for check in INCIDENT_REPORTING_CHECKS:
template["incident_reporting"][check["id"]] = {
"question": check["question"],
"response": "yes | partial | no",
"notes": "",
}
for check in MANAGEMENT_ACCOUNTABILITY_CHECKS:
template["management_accountability"][check["id"]] = {
"question": check["question"],
"response": "yes | partial | no",
"notes": "",
}
return template
def score_response(response: str) -> float:
"""Convert a response to a numeric score."""
mapping = {
"yes": 1.0,
"partial": 0.5,
"no": 0.0,
"not_applicable": None,
}
return mapping.get(response.lower().strip(), 0.0)
def assess_measure(measure_num: int, responses: Dict[str, Any]) -> Dict[str, Any]:
"""Assess a single measure based on responses."""
measure_data = MEASURES[measure_num]
controls_key = f"measure_{measure_num}"
result = {
"measure": measure_num,
"title": measure_data["title"],
"article": measure_data["article"],
"controls": [],
"score": 0,
"max_score": 0,
"gaps": [],
"recommendations": [],
}
measure_responses = responses.get("measures", {}).get(controls_key, {}).get("controls", {})
total_weighted_score = 0.0
total_weight = 0
for control in measure_data["controls"]:
control_response = measure_responses.get(control["id"], {})
response_value = control_response.get("response", "no") if isinstance(control_response, dict) else "no"
notes = control_response.get("notes", "") if isinstance(control_response, dict) else ""
score = score_response(response_value)
control_result = {
"id": control["id"],
"question": control["question"],
"response": response_value,
"notes": notes,
"weight": control["weight"],
"iso27001_map": control["iso27001_map"],
}
if score is None:
control_result["status"] = "not_applicable"
control_result["score_contribution"] = "N/A"
else:
weighted = score * control["weight"]
total_weighted_score += weighted
total_weight += control["weight"]
control_result["status"] = "compliant" if score == 1.0 else ("partial" if score == 0.5 else "non_compliant")
control_result["score_contribution"] = round(weighted, 1)
if score < 1.0:
gap = {
"control_id": control["id"],
"question": control["question"],
"current_status": control_result["status"],
"guidance": control["guidance"],
"iso27001_map": control["iso27001_map"],
"priority": "high" if score == 0.0 else "medium",
}
result["gaps"].append(gap)
result["recommendations"].append({
"control_id": control["id"],
"action": control["guidance"],
"priority": gap["priority"],
})
result["controls"].append(control_result)
if total_weight > 0:
result["score"] = round((total_weighted_score / total_weight) * 100, 1)
else:
result["score"] = 0
result["max_score"] = 100
result["compliance_level"] = _compliance_level(result["score"])
return result
def assess_incident_reporting(responses: Dict[str, Any]) -> Dict[str, Any]:
"""Assess incident reporting readiness."""
ir_responses = responses.get("incident_reporting", {})
result = {
"category": "Incident Reporting Readiness",
"checks": [],
"score": 0,
"gaps": [],
}
total_weighted_score = 0.0
total_weight = 0
for check in INCIDENT_REPORTING_CHECKS:
check_response = ir_responses.get(check["id"], {})
response_value = check_response.get("response", "no") if isinstance(check_response, dict) else "no"
notes = check_response.get("notes", "") if isinstance(check_response, dict) else ""
score = score_response(response_value)
if score is None:
score = 0.0
weighted = score * check["weight"]
total_weighted_score += weighted
total_weight += check["weight"]
check_result = {
"id": check["id"],
"question": check["question"],
"response": response_value,
"notes": notes,
"status": "compliant" if score == 1.0 else ("partial" if score == 0.5 else "non_compliant"),
"reference": check["reference"],
}
result["checks"].append(check_result)
if score < 1.0:
result["gaps"].append({
"check_id": check["id"],
"question": check["question"],
"current_status": check_result["status"],
"reference": check["reference"],
"priority": "critical" if score == 0.0 else "high",
})
if total_weight > 0:
result["score"] = round((total_weighted_score / total_weight) * 100, 1)
result["compliance_level"] = _compliance_level(result["score"])
return result
def assess_management_accountability(responses: Dict[str, Any]) -> Dict[str, Any]:
"""Assess management accountability compliance."""
ma_responses = responses.get("management_accountability", {})
result = {
"category": "Management Accountability",
"checks": [],
"score": 0,
"gaps": [],
}
total_weighted_score = 0.0
total_weight = 0
for check in MANAGEMENT_ACCOUNTABILITY_CHECKS:
check_response = ma_responses.get(check["id"], {})
response_value = check_response.get("response", "no") if isinstance(check_response, dict) else "no"
notes = check_response.get("notes", "") if isinstance(check_response, dict) else ""
score = score_response(response_value)
if score is None:
score = 0.0
weighted = score * check["weight"]
total_weighted_score += weighted
total_weight += check["weight"]
check_result = {
"id": check["id"],
"question": check["question"],
"response": response_value,
"notes": notes,
"status": "compliant" if score == 1.0 else ("partial" if score == 0.5 else "non_compliant"),
"reference": check["reference"],
}
result["checks"].append(check_result)
if score < 1.0:
result["gaps"].append({
"check_id": check["id"],
"question": check["question"],
"current_status": check_result["status"],
"reference": check["reference"],
"priority": "critical" if score == 0.0 else "high",
})
if total_weight > 0:
result["score"] = round((total_weighted_score / total_weight) * 100, 1)
result["compliance_level"] = _compliance_level(result["score"])
return result
def _compliance_level(score: float) -> str:
"""Determine compliance level from score."""
if score >= 90:
return "strong"
elif score >= 70:
return "adequate"
elif score >= 50:
return "partial"
elif score >= 25:
return "weak"
else:
return "non_compliant"
def run_full_assessment(
responses: Dict[str, Any], measure_filter: Optional[List[int]] = None
) -> Dict[str, Any]:
"""Run a complete NIS2 compliance assessment."""
result = {
"timestamp": datetime.now().isoformat(),
"organization": responses.get("organization", {}),
"summary": {},
"measures": [],
"incident_reporting": {},
"management_accountability": {},
"overall_score": 0,
"overall_compliance_level": "",
"critical_gaps": [],
"remediation_priorities": [],
}
# Assess measures
measures_to_check = measure_filter if measure_filter else list(MEASURES.keys())
measure_scores = []
for m_num in measures_to_check:
if m_num in MEASURES:
measure_result = assess_measure(m_num, responses)
result["measures"].append(measure_result)
measure_scores.append(measure_result["score"])
# Assess incident reporting
ir_result = assess_incident_reporting(responses)
result["incident_reporting"] = ir_result
# Assess management accountability
ma_result = assess_management_accountability(responses)
result["management_accountability"] = ma_result
# Calculate overall score
all_scores = measure_scores + [ir_result["score"], ma_result["score"]]
if all_scores:
result["overall_score"] = round(sum(all_scores) / len(all_scores), 1)
result["overall_compliance_level"] = _compliance_level(result["overall_score"])
# Summary
result["summary"] = {
"total_measures_assessed": len(measures_to_check),
"measures_compliant": sum(1 for s in measure_scores if s >= 90),
"measures_partial": sum(1 for s in measure_scores if 50 <= s < 90),
"measures_non_compliant": sum(1 for s in measure_scores if s < 50),
"overall_score": result["overall_score"],
"compliance_level": result["overall_compliance_level"],
"incident_reporting_score": ir_result["score"],
"management_accountability_score": ma_result["score"],
}
# Collect critical gaps
for measure_result in result["measures"]:
for gap in measure_result.get("gaps", []):
if gap["priority"] == "high":
result["critical_gaps"].append({
"measure": measure_result["measure"],
"measure_title": measure_result["title"],
**gap,
})
for gap in ir_result.get("gaps", []):
if gap["priority"] == "critical":
result["critical_gaps"].append({"area": "Incident Reporting", **gap})
for gap in ma_result.get("gaps", []):
if gap["priority"] == "critical":
result["critical_gaps"].append({"area": "Management Accountability", **gap})
# Prioritized remediation
all_gaps = []
for measure_result in result["measures"]:
for rec in measure_result.get("recommendations", []):
all_gaps.append({
"measure": measure_result["measure"],
"measure_title": measure_result["title"],
**rec,
})
# Sort: high priority first, then by measure number
all_gaps.sort(key=lambda x: (0 if x["priority"] == "high" else 1, x.get("measure", 0)))
result["remediation_priorities"] = all_gaps
return result
def format_text_report(result: Dict[str, Any]) -> str:
"""Format assessment result as human-readable text."""
lines = []
lines.append("=" * 70)
lines.append("NIS2 COMPLIANCE ASSESSMENT REPORT")
lines.append("=" * 70)
lines.append(f"Generated: {result['timestamp']}")
org = result.get("organization", {})
if org:
lines.append(f"Organization: {org.get('name', 'N/A')}")
lines.append(f"Entity type: {org.get('entity_type', 'N/A')}")
lines.append(f"Sector: {org.get('sector', 'N/A')}")
lines.append("")
# Summary
summary = result.get("summary", {})
lines.append("EXECUTIVE SUMMARY")
lines.append("-" * 40)
lines.append(f" Overall Score: {summary.get('overall_score', 0)}/100")
lines.append(f" Compliance Level: {summary.get('compliance_level', 'N/A').upper()}")
lines.append(f" Measures Assessed: {summary.get('total_measures_assessed', 0)}")
lines.append(f" Compliant (>=90): {summary.get('measures_compliant', 0)}")
lines.append(f" Partial (50-89): {summary.get('measures_partial', 0)}")
lines.append(f" Non-compliant (<50): {summary.get('measures_non_compliant', 0)}")
lines.append(f" Incident Reporting: {summary.get('incident_reporting_score', 0)}/100")
lines.append(f" Management Accountability: {summary.get('management_accountability_score', 0)}/100")
lines.append("")
# Measure scores
lines.append("MEASURE SCORES")
lines.append("-" * 40)
for measure_result in result.get("measures", []):
score = measure_result["score"]
level = measure_result["compliance_level"]
bar = "#" * int(score / 5) + "." * (20 - int(score / 5))
lines.append(f" M{measure_result['measure']:2d}. {measure_result['title'][:45]:<45s}")
lines.append(f" [{bar}] {score:5.1f}/100 ({level})")
lines.append("")
# Critical gaps
critical_gaps = result.get("critical_gaps", [])
if critical_gaps:
lines.append("CRITICAL GAPS")
lines.append("-" * 40)
for gap in critical_gaps:
area = gap.get("measure_title", gap.get("area", ""))
lines.append(f" [!!!] {gap.get('control_id', gap.get('check_id', ''))}: {gap.get('question', '')}")
lines.append(f" Area: {area}")
if gap.get("guidance"):
lines.append(f" Action: {gap['guidance']}")
lines.append("")
# Remediation priorities
priorities = result.get("remediation_priorities", [])
if priorities:
lines.append("REMEDIATION PRIORITIES (Top 10)")
lines.append("-" * 40)
for i, rec in enumerate(priorities[:10], 1):
lines.append(f" {i}. [{rec['priority'].upper()}] {rec['control_id']} (Measure {rec['measure']})")
lines.append(f" {rec['action']}")
lines.append("")
lines.append("=" * 70)
return "\n".join(lines)
def main():
parser = argparse.ArgumentParser(
description="NIS2 Compliance Checker — Assess compliance against Article 21 minimum measures",
formatter_class=argparse.RawDescriptionHelpFormatter,
epilog="""
Examples:
%(prog)s --template > assessment.json
%(prog)s --config assessment.json
%(prog)s --config assessment.json --measures 1 2 4 --json
%(prog)s --config assessment.json --output gap_report.json --json
""",
)
parser.add_argument("--config", help="Path to JSON assessment file (use --template to generate)")
parser.add_argument("--template", action="store_true", help="Generate assessment input template")
parser.add_argument("--measures", nargs="+", type=int, help="Assess specific measures only (e.g., 1 2 4)")
parser.add_argument("--json", action="store_true", help="Output in JSON format")
parser.add_argument("--output", help="Write output to file")
args = parser.parse_args()
# Template mode
if args.template:
template = generate_template()
print(json.dumps(template, indent=2))
return
# Assessment mode
if not args.config:
parser.error("--config is required for assessment (use --template to generate input file)")
try:
with open(args.config) as f:
responses = json.load(f)
except (FileNotFoundError, json.JSONDecodeError) as e:
print(f"Error loading config file: {e}", file=sys.stderr)
sys.exit(1)
# Validate measure filter
if args.measures:
invalid = [m for m in args.measures if m not in MEASURES]
if invalid:
parser.error(f"Invalid measure numbers: {invalid}. Valid: 1-10")
# Run assessment
result = run_full_assessment(responses, measure_filter=args.measures)
# Format output
if args.json:
output = json.dumps(result, indent=2)
else:
output = format_text_report(result)
# Write or print
if args.output:
with open(args.output, "w") as f:
f.write(output)
print(f"Report written to {args.output}")
else:
print(output)
if __name__ == "__main__":
main()
Related skills
FAQ
When did NIS2 apply?
It entered into force on January 16, 2023, with Member States required to transpose it by October 17, 2024.
Who is in scope?
Essential entities (Annex I high-criticality sectors) and Important entities (Annex II), generally medium and large enterprises, with automatic inclusions regardless of size.