NIS2 Directive
What is NIS2 Directive?
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, covering essential and important entities.. It comprises 8 controls organised across 8 domains, and applies in the European Union.
How NIS2 Directive maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains NIS2 Directive groups its controls into
Where NIS2 Directive overlaps with the standards you already hold
Training that covers NIS2 Directive
What NIS2 Directive means in your sector
What NIS2 Directive means for your job
Questions people ask about NIS2 Directive
What is NIS2 Directive?
How many controls does NIS2 Directive have?
Where does NIS2 Directive apply?
What frameworks does NIS2 Directive map to?
How do I get started with NIS2 Directive compliance?
Query NIS2 Directive programmatically
NIS2 Directive, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIS2 Directive API reference and MCP config →What NIS2 Directive requires, control by control
Each page carries the requirement text for one NIS2 Directive control and what an assessor expects to see as evidence.
- ART-20-1 Management body approves the cybersecurity risk-management measures and oversees their implementation
- ART-20-2 Train the management body, and offer equivalent training to staff on a regular basis
- ART-21-1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
- ART-21-2-A Policies on risk analysis and on information system security
- ART-21-2-B Incident handling
- ART-21-2-C Business continuity, backup management, disaster recovery and crisis management
- ART-21-2-D Supply chain security, covering the relationship with each direct supplier and service provider
- ART-21-2-E Security in acquisition, development and maintenance, including vulnerability handling and disclosure
- ART-21-2-F Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
- ART-21-2-G Basic cyber hygiene practices and cybersecurity training
How much of another standard NIS2 Directive already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- APRA CPS 234 to NIS2 Directive crosswalk
- C5 (Germany) to NIS2 Directive crosswalk
- CIS Controls v8 to NIS2 Directive crosswalk
- Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to NIS2 Directive crosswalk
- CMMC 2.0 to NIS2 Directive crosswalk
- DORA to NIS2 Directive crosswalk
- FedRAMP Moderate to NIS2 Directive crosswalk
- ISO 27001:2022 to NIS2 Directive crosswalk
How ready are you for NIS2 Directive?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.