Compliance & Regulations/European Union/NIS2
Critical Infrastructure · European Union — essential and important entities

NIS2 Directive

The expanded EU network and information security directive, covering essential and important entities across 18 sectors.

Regulator
ENISA + national competent authorities (transposed per Member State)
Jurisdiction
European Union — essential and important entities
Status
Transposition deadline was 17 October 2024 — most Member States have national laws now in force.
In force since
Directive entered into force January 2023; national transpositions Oct 2024 onward.
Regulator's source
Who it applies to

Essential entities (large operators in critical sectors) and Important entities (medium operators) across 18 sectors.

Penalties

Up to €10M or 2% global turnover (essential entities); €7M or 1.4% (important entities).

What it requires

What NIS2 actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Risk-based cybersecurity measures including incident handling, business continuity, supply chain security.

02

24-hour early warning to the national CSIRT; 72-hour formal incident notification; 1-month final report.

03

Management body accountability — leadership must approve and oversee cyber risk measures.

04

Vulnerability handling and coordinated disclosure policy.

05

Use of cryptography (incl. end-to-end where appropriate) and multi-factor authentication.

06

Supply chain risk management including direct supplier cyber posture assessment.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Incident timer that surfaces the 24/72/30 NIS2 milestones automatically.

Supply-chain risk module covering direct suppliers and transitive open-source dependencies.

Management-body briefing pack auto-generated quarterly.

Crosswalks to ENISA NIS Cooperation Group reference and per Member State transposition (DE, FR, IT, ES, NL, PL, IE).

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Incident timeline with regulator-aligned milestones.

Supply chain cyber posture report.

Management body briefing — board pack format.

Coordinated disclosure policy and vulnerability handling logs.

Ready for NIS2?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing