Why NIS2 timing matters
NIS2 transposition deadline was 17 October 2024. Most EU member states have transposed; some are late. National competent authorities and CSIRTs are operational. Enforcement is now.
Article 21 — 10 mandatory areas
Each in-scope entity must take measures across:
- Policies on risk analysis and information system security
- Incident handling
- Business continuity
- Supply chain security
- Acquisition / development / maintenance security
- Effectiveness assessment policies
- Cyber hygiene + cybersecurity training
- Cryptography / encryption
- HR security, access control, asset management
- MFA / continuous authentication / secured comms
Article 23 — incident reporting timeline
- 24-hour early warning to CSIRT
- 72-hour incident notification with severity assessment
- 1-month final report with root cause and mitigation
The architecture must support detection and reporting at these timelines.
Most-common findings
In Ænix NIS2 engagements:
- Detection telemetry tuned for performance, not security
- BCP plan documented but never tested
- Supply-chain visible only to first hop
- Incident-reporting process undocumented for 24-hour timeline
How to use the checklist
Walk through with platform engineering + security + compliance. Identify gaps. Prioritize remediation.
For deeper engagement: NIS2 compliance services.
Test yourself: NIS2 checklist (essential entities)
5 questions · ~2 min