Article by Aenix Team

NIS2 cybersecurity requirements — checklist for essential and important entities

NIS2 Article 21 risk-management areas and Article 23 reporting deadlines mapped to architecture, with the findings that recur in essential-entity reviews.

Nis2CozystackPlatform EngineeringCompliance

Why NIS2 timing matters

NIS2 transposition deadline was 17 October 2024. Most EU member states have transposed; some are late. National competent authorities and CSIRTs are operational. Enforcement is now.

Article 21 — 10 mandatory areas

Each in-scope entity must take measures across:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity
  4. Supply chain security
  5. Acquisition / development / maintenance security
  6. Effectiveness assessment policies
  7. Cyber hygiene + cybersecurity training
  8. Cryptography / encryption
  9. HR security, access control, asset management
  10. MFA / continuous authentication / secured comms

Article 23 — incident reporting timeline

  • 24-hour early warning to CSIRT
  • 72-hour incident notification with severity assessment
  • 1-month final report with root cause and mitigation

The architecture must support detection and reporting at these timelines.

Most-common findings

In Ænix NIS2 engagements:

  1. Detection telemetry tuned for performance, not security
  2. BCP plan documented but never tested
  3. Supply-chain visible only to first hop
  4. Incident-reporting process undocumented for 24-hour timeline

How to use the checklist

Walk through with platform engineering + security + compliance. Identify gaps. Prioritize remediation.

For deeper engagement: NIS2 compliance services.

Test yourself: NIS2 checklist (essential entities)

5 questions · ~2 min