NIS2 Directive (EU) 2022/2555
EU directive on cybersecurity risk-management measures for essential and important entities. Medium and large companies in sectors such as energy, transport, health, digital infrastructure and manufacturing, and their suppliers.
6 controls supported. References are points of Article 21(2).
Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.
Mapping under review
- Control
- 21.2.cBusiness continuity
- How we help
- A second site and tested failover are the disaster-recovery part of the measures NIS2 requires.
- Evidence you get
- Disaster-recovery plan inputs, failover test reports.
Mapping under review
- Control
- 21.2.cBusiness continuity
- 21.2.hCryptography and encryption
- How we help
- Backup management with encryption, the part of NIS2 that decides whether you recover from ransomware.
- Evidence you get
- Backup and retention configuration, restore test records.
Mapping under review
- Control
- 21.2.cBusiness continuity
- How we help
- Automates failover between services and, on the Enterprise plan, removes DNS as a single point of failure, part of the business continuity and disaster-recovery measures NIS2 requires.
- Evidence you get
- DNS architecture description, failover configuration, failover event history.
Mapping under review
- Control
- 21.2.bIncident handling
- How we help
- Complete logs are what make incident detection, analysis and reporting possible.
- Evidence you get
- Log inventory and the queries used in incident handling.
Mapping under review
- Control
- 21.2.eSecurity in acquisition
- How we help
- Virtual patching and API schema validation reduce exposure while vulnerabilities are being fixed.
- Evidence you get
- WAF rule history and threat reports.
Mapping under review
- Control
- 21.2.iAccess control policies
- 21.2.jMulti-factor authentication and secured communications
- How we help
- Access control policies enforced per application, with multi-factor authentication and encrypted connections.
- Evidence you get
- Access policy export and authentication logs.
Tell us what you are preparing for
We reply with the controls we can cover, what stays on your side, and a realistic timeline.