EU · Directive (EU) 2022/2555

NIS2 Directive

NIS2 replaced the 2016 NIS Directive and widened the sectors covered. It is a directive, not a regulation: it binds you through your member state’s transposing law rather than directly, and member states were required to transpose it by 17 October 2024. It applies to named sectors above a size threshold — not to businesses in general.

Scope

Does this apply to you?

Two tests must both be met: sector and size. If either fails, and you are not in one of the size-independent categories, you are very likely outside the directive. Most vendor pages skip this section, which is why most readers arrive believing NIS2 covers them.

You are likely in scope if

  • Your organisation operates in a sector listed in Annex I — energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, or space.
  • Or in a sector listed in Annex II — postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing (including medical devices, computers and electronics, machinery, motor vehicles), digital providers such as online marketplaces, search engines and social networking platforms, or research organisations.
  • AND you meet the Article 2(1) size threshold: at least a medium-sized enterprise, meaning 50 or more employees, or annual turnover and annual balance sheet total both above €10 million.
  • Or, regardless of size, you fall in one of the Article 2(2) categories: providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers, the sole provider in a member state of a service essential for societal or economic activity, or central public administration entities.

You are probably not in scope if

  • You are below the size threshold — fewer than 50 employees and not above both €10 million figures — and you are not in an Article 2(2) size-independent category. Most small businesses land here, and the honest answer is that NIS2 does not apply to you.
  • Your sector appears in neither Annex I nor Annex II, whatever your size.
  • You supply an in-scope entity but are not yourself in a listed sector. Being in someone else’s supply chain does not put you in scope. Article 21(2)(d) makes supply-chain risk their obligation, and it reaches you through their contract and their questionnaire — which is a commercial requirement to answer, not a legal one under NIS2.

NIS2 is a directive, so your actual obligations come from your member state’s transposing law, which may differ in scope, in thresholds and in dates. Whether an entity is classified “essential” or “important” — and therefore which supervisory regime and which penalty ceiling applies — is determined under that national law. This page describes the directive; it does not tell you your status under it, and it is not legal advice.

Requirements

What the framework asks for.

Named as the framework names them, with its own references, so you can check this page against the source below.

  • 21(2)(a)

    Policies on risk analysis and information system security

    The baseline governance requirement: a documented approach to analysing risk to network and information systems.

  • 21(2)(b)

    Incident handling

    Detection, response, and the handling process itself — distinct from the reporting duties in Article 23.

  • 21(2)(c)

    Business continuity

    Named in the directive as including backup management, disaster recovery, and crisis management.

  • 21(2)(d)

    Supply chain security

    Security-related aspects of the relationship between the entity and its direct suppliers or service providers. This is the clause that reaches suppliers contractually.

  • 21(2)(e)

    Security in acquisition, development and maintenance

    Covering network and information system acquisition, development and maintenance, including vulnerability handling and disclosure.

  • 21(2)(f)

    Policies and procedures to assess effectiveness

    Assessing whether the cybersecurity risk-management measures actually work. This is an effectiveness-review duty, and it is frequently misread as part of (e).

  • 21(2)(g)

    Basic cyber hygiene practices and cybersecurity training

    Both the hygiene practices and the training obligation sit in the same point.

  • 21(2)(h)

    Policies on the use of cryptography and, where appropriate, encryption

    A policy requirement, qualified by appropriateness rather than mandating encryption everywhere.

  • 21(2)(i)

    Human resources security, access control policies and asset management

    Three organisational strands in one point.

  • 21(2)(j)

    Multi-factor or continuous authentication, and secured communications

    Use of MFA or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems.

  • Article 23

    Incident reporting deadlines

    For significant incidents: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month, to the CSIRT or competent authority.

  • Article 20

    Management body accountability

    Management bodies must approve the risk-management measures and oversee their implementation, and can be held liable for failing to do so. They are also required to follow training.

The register

What Fortoxa puts against each requirement.

Fortoxa evidences six of the ten Article 21(2) measures in part, from server telemetry. The remaining four are organisational and appear below under what stays your job rather than as rows Fortoxa can fill.

NIS2 Directive — control register

5 of 6 evidenced

  • 21(2)(a)

    Risk analysis and information system security policies

    Control register with current state per requirement

    security-score-service · 9 min ago

    Calculated
  • 21(2)(b)

    Incident handling

    Incident timeline: detection, action taken, and by whom

    log_events · 1 min ago

    Live
  • 21(2)(e)

    Security in acquisition, development and maintenance

    Patch and configuration state per monitored host

    fortoxa-agent · 1 day ago

    Stale
  • 21(2)(g)

    Basic cyber hygiene practices

    Account hygiene: dormant accounts, role changes, key age

    workspace_members · 2 min ago

    Live
  • 21(2)(h)

    Cryptography and encryption

    Transport encryption state for monitored services

    fortoxa-agent · 18 min ago

    Live
  • 21(2)(j)

    Multi-factor authentication

    MFA state per account

    identity-provider · never collected

    Not configured

Rows marked as not measured are shown, not hidden. A register with every requirement satisfied is the outcome this product exists to prevent.

Example workspace, sample data. Your own register is built from your servers once an agent is installed.

Not covered

What stays your job.

Fortoxa evidences what it can observe on the servers you install the agent on. Everything below is outside that, and the register marks it as not measured rather than as a pass.

  • 21(2)(c) — business continuity

    Backup management, disaster recovery and crisis management. Fortoxa does not run, hold or test your backups, and does not evidence that a restore has ever succeeded.

  • 21(2)(d) — supply chain security

    Supplier contracts, assurance activity and the security terms you impose downstream. These are commercial artifacts, not telemetry.

  • 21(2)(f) — assessing effectiveness

    Fortoxa records that a control check ran and what it returned. Judging whether your measures are effective overall, and changing them when they are not, is a review you own.

  • 21(2)(i) — human resources security

    Vetting, joiners and leavers processes, and asset management beyond the servers the agent runs on.

  • Article 23 — the reports themselves

    Fortoxa’s incident timeline is evidence you can attach to a 24-hour early warning or a 72-hour notification. Judging whether an incident is “significant”, and filing with your CSIRT or competent authority, is yours and is time-bound.

  • Article 20 — management accountability

    Approval and oversight by the management body, and the training obligation on it, sit with your directors. No monitoring product can discharge a personal accountability duty.

Sources

Check this page against the text.

Everything above is Fortoxa's reading of the framework. It is not the framework, and it is not advice about your obligations. The publishers below are authoritative; this page is not.

Next

See what your own servers produce.

Install the agent on one server and the register builds itself from what it finds — including the requirements it cannot see.

The control register and the evidence export are Business features, £349/month. Monitoring, alerts and the live activity feed start at £29 on Micro, which does not include the register. Starter and Business include a 14-day trial on a new subscription.