Regulation · EU

NIS 2, without the spreadsheets.

Meet the EU’s cybersecurity baseline before the regulator asks.

What is NIS 2?

NIS 2 widens the EU’s cybersecurity rules to many more sectors and to medium and large companies within them. Essential and important entities must take the risk-management measures listed in Article 21, report significant incidents on a strict timeline and make management personally accountable for oversight.

Who needs it

  • Medium and large companies in sectors such as energy, transport, health, digital infrastructure and ICT services
  • Managed service and cloud providers serving those sectors
  • Suppliers whose NIS 2 customers pass supply-chain requirements down to them

What NIS 2 looks at

Risk analysis and security policies

Documented policies for risk analysis and information system security.

Incident handling and continuity

Incident response, backup management, disaster recovery and crisis management.

Supply chain security

Security requirements for direct suppliers and service providers.

Cyber hygiene and access

Training, cryptography, access control, asset management and MFA.

How Beviso gets you there

  • Article 21 measures pre-loaded and mapped to ISO 27001 controls you may already run
  • Incident log with the 24-hour early-warning clock
  • Vendor register for supply-chain security
  • Readiness reporting that management can review and sign off

9 NIS 2 controls, ready on day one

These controls are loaded when you enable NIS 2, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

Art.21.2.a

Risk Analysis and Information System Security Policies

Policies on risk analysis and information system security shall be adopted and implemented.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • Lacework
  • AWS

Art.21.2.b

Incident Handling

Incident handling procedures shall be established, including prevention, detection, and response.

Evidence from

  • PagerDuty
  • ServiceNow
  • CrowdStrike
  • SentinelOne
  • Datadog

Art.21.2.c

Business Continuity and Crisis Management

Business continuity and crisis management including backup management and disaster recovery shall be in place.

Evidence from

  • PagerDuty
  • AWS
  • Datadog
  • Grafana

Art.21.2.d

Supply Chain Security

Security in network and information systems acquisition, development, and maintenance including vulnerability handling.

Evidence from

  • Ironclad
  • DocuSign
  • Snyk
  • GitHub
  • SonarCloud

Art.21.2.e

Network and Information Systems Security Measures

Security in network and information systems acquisition, development, and maintenance.

Evidence from

  • Cloudflare
  • AWS
  • DigitalOcean
  • Hetzner
  • Microsoft Azure

Art.21.2.f

Policies and Procedures for Cryptography

Policies and procedures on the use of cryptography and, where appropriate, encryption.

Evidence from

  • HashiCorp Vault
  • Doppler
  • 1Password
  • Bitwarden

Art.21.2.g

Human Resources Security

Human resources security, access control policies and asset management shall be implemented.

Evidence from

  • Okta
  • BambooHR
  • HiBob
  • Personio
  • Google Workspace
  • KnowBe4

Art.21.2.h

Multi-Factor Authentication

The use of multi-factor authentication or continuous authentication solutions shall be required.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • Google Workspace
  • 1Password
  • JumpCloud

Art.21.2.i

Secure Communications

Secured voice, video, and text communications and secured emergency communication systems within the entity.

Evidence from

  • Slack
  • Mattermost
  • Cloudflare

NIS 2 questions

Does NIS 2 apply to us?
It depends on your sector, size and the member state’s transposition. Broadly, medium and large companies in the listed sectors are in scope, and some entities are in scope regardless of size.
Is ISO 27001 enough for NIS 2?
It covers much of Article 21, which is why Beviso maps the two. NIS 2 adds strict incident reporting deadlines and management accountability that ISO 27001 does not specify.

Start your NIS 2 programme today.

Free while Beviso is in beta. No credit card required.

Get started free