NIS2 Directive (EU) 2022/2555

EU directive on cybersecurity risk-management measures for essential and important entities. Medium and large companies in sectors such as energy, transport, health, digital infrastructure and manufacturing, and their suppliers.

6 controls supported. References are points of Article 21(2).

Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

  • Control
    • 21.2.cBusiness continuity
    How we help
    A second site and tested failover are the disaster-recovery part of the measures NIS2 requires.
    Evidence you get
    Disaster-recovery plan inputs, failover test reports.
  • Mapping under review

    Control
    • 21.2.cBusiness continuity
    • 21.2.hCryptography and encryption
    How we help
    Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware.
    Evidence you get
    Backup and retention configuration, restore test records.
  • Mapping under review

    Control
    • 21.2.cBusiness continuity
    How we help
    Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires.
    Evidence you get
    DNS architecture description, failover configuration, failover event history.
  • Mapping under review

    Control
    • 21.2.bIncident handling
    How we help
    Complete logs are what make incident detection, analysis and reporting possible.
    Evidence you get
    Log inventory and the queries used in incident handling.
  • Mapping under review

    Control
    • 21.2.eSecurity in acquisition
    How we help
    Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed.
    Evidence you get
    WAF rule history and threat reports.
  • Control
    • 21.2.iAccess control policies
    • 21.2.jMulti-factor authentication and secured communications
    How we help
    Access control policies enforced per application, with multi-factor authentication and encrypted connections.
    Evidence you get
    Access policy export and authentication logs.

Tell us what you are preparing for

We reply with the controls we can cover, what stays on your side, and a realistic timeline.

Where are you now?