REGULATION · NIS2
NIS2 compliance you can demonstrate, not just declare.
NIS2 makes management personally accountable for cybersecurity risk management. Mindlapse turns each obligation into controls verified continuously against live evidence, the posture a supervisor actually asks to see.
WHAT IS NIS2?
The EU’s baseline cybersecurity law, with teeth.
NIS2 (Directive (EU) 2022/2555) is the European Union’s framework for the cybersecurity of essential and important entities. It replaces the 2016 NIS Directive, dramatically widening scope to 18 sectors, from energy, transport and health to digital infrastructure, manufacturing and public administration.
It requires in-scope organizations to adopt risk-management measures (governance, incident handling, business continuity, supply-chain security, vulnerability handling, encryption, access control…), to report significant incidents on strict timelines, and it makes management bodies explicitly responsible, with sanctions up to 10 M€ or 2% of worldwide turnover for essential entities.
Transposition was due by 17 October 2024 and is in force in most member states; supervision and enforcement are ramping up across the EU, France among the late transposers (see the FAQ). The practical question is no longer “are we in scope?” but “can we prove our measures actually operate?”
KEY OBLIGATIONS
What NIS2 actually asks of you.
Article 21 defines the minimum risk-management measures; Article 23 the incident-reporting discipline. In practice, five workstreams dominate.
Governance & accountability (Art. 20)
Management bodies must approve risk-management measures, oversee their implementation and be trained on cyber risk. Accountability is personal.
Risk-management measures (Art. 21)
Policies on risk analysis, incident handling, continuity, supply-chain security, secure development, effectiveness assessment, cryptography, access control and MFA.
Incident reporting (Art. 23)
Early warning within 24 hours, incident notification within 72 hours, final report within one month, with intermediate updates on request.
Supply-chain security
Assess and manage the security of direct suppliers and service providers, including their development practices and your contractual leverage.
Proof of effectiveness
Policies must be assessed for effectiveness. A binder of PDFs is not effectiveness. Operating, verifiable controls are.
HOW MINDLAPSE HELPS
From articles to verified controls.
NIS2 obligations are pre-mapped to controls in the platform; Ernest keeps their state verified against live signals.
Art. 20: management accountability
The Cyber Cockpit gives executive bodies a verified, board-readable posture (measures, state, exposure) generated from evidence, not assembled slides.
Art. 21: risk-management measures
Smart Compliance maps NIS2 to your control set (alongside ISO 27001 and others) and monitors each control continuously with sourced verdicts.
Art. 21(2)(d): supply-chain security
TPRM runs proportionate, context-aware vendor assessments with contradiction detection and a living risk network of your dependencies.
Art. 23: incident reporting readiness
Risk Intelligence keeps scenarios, owners and escalation paths current, so the 24h/72h clock starts with context instead of chaos.
Effectiveness assessment
Every control carries dated, verifiable evidence and an audit trail, demonstrating operation over time, exactly what supervisors request.
RESOURCE · NIS2
NIS2 readiness guide
What the directive actually requires, what evidence holds up under scrutiny, and where documented declarations stop being enough.
NIS2 - FAQ
Frequently asked, directly answered.
Who falls under NIS2?
Essential and important entities across 18 sectors (Annexes I & II): energy, transport, banking and financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, space, plus postal services, waste, chemicals, food, manufacturing, digital providers and research. As a rule, entities with 50+ employees or €10M+ turnover in those sectors are in scope; some are included regardless of size.
What are the NIS2 incident-reporting deadlines?
An early warning to your CSIRT/authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month, with progress updates on request.
What sanctions does NIS2 carry?
Up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and up to €7 million or 1.4% for important entities, plus management liability and possible temporary bans on exercising managerial functions.
Is NIS2 applicable in France?
Not yet as national law. NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. Entities that will be essential or important should already run the Article 21 measures: the directive’s obligations are known, only the national supervision regime is pending.
How does Mindlapse shorten the path to NIS2 compliance?
NIS2 requirements arrive pre-mapped to controls shared with your other frameworks, so existing measures count immediately. Continuous verification then replaces the annual evidence hunt: your NIS2 posture is current every day, with proof attached.
GLOSSARY
Terms to know
NIS2, UNDER CONTROL
See your NIS2 posture, verified, today.
Bring your scope; we map it live against Article 21 and show you the gaps with evidence.