NIS 2, without the spreadsheets.
Meet the EU’s cybersecurity baseline before the regulator asks.
What is NIS 2?
NIS 2 widens the EU’s cybersecurity rules to many more sectors and to medium and large companies within them. Essential and important entities must take the risk-management measures listed in Article 21, report significant incidents on a strict timeline and make management personally accountable for oversight.
Who needs it
- Medium and large companies in sectors such as energy, transport, health, digital infrastructure and ICT services
- Managed service and cloud providers serving those sectors
- Suppliers whose NIS 2 customers pass supply-chain requirements down to them
What NIS 2 looks at
Risk analysis and security policies
Documented policies for risk analysis and information system security.
Incident handling and continuity
Incident response, backup management, disaster recovery and crisis management.
Supply chain security
Security requirements for direct suppliers and service providers.
Cyber hygiene and access
Training, cryptography, access control, asset management and MFA.
How Beviso gets you there
- Article 21 measures pre-loaded and mapped to ISO 27001 controls you may already run
- Incident log with the 24-hour early-warning clock
- Vendor register for supply-chain security
- Readiness reporting that management can review and sign off
9 NIS 2 controls, ready on day one
These controls are loaded when you enable NIS 2, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
Art.21.2.a
Risk Analysis and Information System Security Policies
Policies on risk analysis and information system security shall be adopted and implemented.
Evidence from
- Snyk
- Wiz
- Qualys
- Rapid7
- Lacework
- AWS
Art.21.2.b
Incident Handling
Incident handling procedures shall be established, including prevention, detection, and response.
Evidence from
- PagerDuty
- ServiceNow
- CrowdStrike
- SentinelOne
- Datadog
Art.21.2.c
Business Continuity and Crisis Management
Business continuity and crisis management including backup management and disaster recovery shall be in place.
Evidence from
- PagerDuty
- AWS
- Datadog
- Grafana
Art.21.2.d
Supply Chain Security
Security in network and information systems acquisition, development, and maintenance including vulnerability handling.
Evidence from
- Ironclad
- DocuSign
- Snyk
- GitHub
- SonarCloud
Art.21.2.e
Network and Information Systems Security Measures
Security in network and information systems acquisition, development, and maintenance.
Evidence from
- Cloudflare
- AWS
- DigitalOcean
- Hetzner
- Microsoft Azure
Art.21.2.f
Policies and Procedures for Cryptography
Policies and procedures on the use of cryptography and, where appropriate, encryption.
Evidence from
- HashiCorp Vault
- Doppler
- 1Password
- Bitwarden
Art.21.2.g
Human Resources Security
Human resources security, access control policies and asset management shall be implemented.
Evidence from
- Okta
- BambooHR
- HiBob
- Personio
- Google Workspace
- KnowBe4
Art.21.2.h
Multi-Factor Authentication
The use of multi-factor authentication or continuous authentication solutions shall be required.
Evidence from
- Okta
- Duo
- Microsoft Azure
- Google Workspace
- 1Password
- JumpCloud
Art.21.2.i
Secure Communications
Secured voice, video, and text communications and secured emergency communication systems within the entity.
Evidence from
- Slack
- Mattermost
- Cloudflare
NIS 2 questions
- Does NIS 2 apply to us?
- It depends on your sector, size and the member state’s transposition. Broadly, medium and large companies in the listed sectors are in scope, and some entities are in scope regardless of size.
- Is ISO 27001 enough for NIS 2?
- It covers much of Article 21, which is why Beviso maps the two. NIS 2 adds strict incident reporting deadlines and management accountability that ISO 27001 does not specify.
Often run alongside NIS 2
ISO 27001
Build an information security management system an auditor will certify.
DORA
Prove operational resilience to EU financial regulators — and to the banks you supply.
GDPR
Show, not just claim, that personal data is handled lawfully.
ISO 22301
Show customers you can keep running when something breaks.
Start your NIS 2 programme today.
Free while Beviso is in beta. No credit card required.
Get started free