What is NIS2?
NIS2 (Network and Information Systems Directive 2), Directive (EU) 2022/2555, is the EU's primary cybersecurity legislation. It replaced the original NIS Directive on 18 October 2024 and expands mandatory cybersecurity requirements to more than 18 sectors, introduces stricter incident reporting timelines, and places direct personal liability on senior management for non-compliance.
The original NIS Directive (2016) focused narrowly on operators of essential services. NIS2 expands that scope significantly — covering energy, transport, healthcare, digital infrastructure, managed services, and public administration. If your organization operates in one of these sectors within the EU, NIS2 is a legal obligation, not a voluntary framework.
The directive was adopted in December 2022. Member states had until 17 October 2024 to transpose it into national law. Several countries missed that deadline — Germany transposed in December 2025 [NIS2 Directive tracker, 2026]. The European Commission has referred seven member states to the Court of Justice of the EU for failure to transpose as of May 2026 [Optro, 2026]. The first NIS2 compliance audit deadline for in-scope entities is 30 June 2026.
Key figures
| 160,000+ organizations across the EU potentially in scope for NIS2 [European Commission estimates] |
18+ sectors covered by NIS2 — up from 7 under the original NIS Directive [Directive (EU) 2022/2555] |
€10M maximum fine for essential entities — or 2% of global annual revenue, whichever is higher [NIS2, Article 34] |
When you need NIS2 compliance
NIS2 applies to your organization if it operates in the EU and meets two criteria: it operates in one of the 18+ covered sectors, and it meets the size threshold (medium enterprise or above — generally 50 or more employees, or annual turnover above €10 million). Supply chain relationships create indirect obligations: even if your organization is not directly in scope, your customers or partners may require you to meet NIS2-equivalent standards as part of their own supply chain security obligations under Article 21(2)(d).
Essential entities vs. important entities
Essential entities: Higher criticality sectors — energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space. Fines up to €10 million or 2% of global annual revenue [NIS2, Article 34].
Important entities: Wider sectors — postal services, waste management, chemicals, food, manufacturing, digital providers, research. Fines up to €7 million or 1.4% of global annual revenue [NIS2, Article 34].
Management liability is the sharpest change from NIS1. NIS2 places direct personal responsibility on senior management for cybersecurity failures. Germany's December 2025 transposition explicitly elevates NIS2 to a board-level issue with director liability [NIS2, Article 20]. Executives are required to undergo regular cybersecurity training.
Key dates
Date |
Obligation |
|---|---|
Jan 2023 |
NIS2 entered into force across the EU. |
Oct 2024 |
NIS1 repealed. NIS2 replaced it. Member states required to transpose into national law. |
Apr 2025 |
Member states required to deliver lists of essential and important entities to the European Commission. |
Jun 2026 |
Deadline for in-scope entities to complete their first NIS2 compliance audit [Optro, 2026]. |
Oct 2027 |
Three-year review of NIS2 functioning. Potential updates to scope and requirements. |
What NIS2 requires: Article 21 and Article 23
NIS2's core security obligations sit in Article 21. All in-scope entities must implement technical and organizational measures across ten areas. Article 23 governs incident reporting with a tiered 24-to-72-hour timeline. These are not aspirational guidelines — they are legally binding requirements backed by financial penalties and management liability.
Art. 21(2)(a) Risk analysis and information security policies
You must establish and maintain documented policies on risk analysis and information system security. This covers how you identify, assess, and address cybersecurity risks across your network and information systems.
DRA COVERS THIS DRA assesses domain, email, application, and network security continuously — producing a cyber score that quantifies your risk posture across all four areas. This gives you the objective risk analysis evidence Article 21(2)(a) requires.
Art. 21(2)(b) Incident handling
You must have measures and protocols to prevent, detect, and recover from incidents. Article 23 requires initial incident notification to your national CSIRT within 24 hours, a fuller report within 72 hours, and a final report within 30 days.
DRA COVERS THIS DRA sends real-time alerts the moment a security signal changes — via email, SMS, Slack, or PagerDuty. Early detection of vendor-side incidents shortens your own response window and supports the Article 23 notification timeline.
Art. 21(2)(c) Business continuity
You need a documented business continuity plan covering backup management, disaster recovery, and crisis handling. The plan must be tested and kept current — not drafted once and filed.
Art. 21(2)(d) Supply chain security
You must implement measures addressing the quality, resilience, and cybersecurity of your suppliers and service providers. This includes assessing vendor security posture, enforcing security clauses in contracts, auditing suppliers, and managing sub-supplier (fourth-party) risk.
DRA COVERS THIS DRA evaluates the cybersecurity posture of every vendor in your ecosystem — analyzing domain, email, application, and network security from the outside in. No vendor cooperation required. Built-in security questionnaires complement scanning with structured vendor-reported evidence. Fourth-party discovery maps sub-supplier risk automatically.
Art. 21(2)(e) Security in acquisition, development, and maintenance
Security must be built into how you acquire, develop, and maintain your network and information systems — including vulnerability management and responsible disclosure.
DRA COVERS THIS DRA detects CVEs across monitored domains and vendor assets continuously — surfacing vulnerabilities by CVE ID, type, severity, and status. Pre-procurement security scoring lets you assess new vendors before acquisition decisions are made.
Art. 21(2)(f)–(j) Policies, cyber hygiene, cryptography, access control, and MFA
Additional obligations cover: effectiveness assessment policies, basic cyber hygiene and staff training, cryptography and encryption policies, HR security and access control, and multi-factor authentication across network access.
NIS2 supply chain security (Article 21(2)(d)) creates the broadest downstream impact.
In-scope entities must assess and enforce cybersecurity requirements on their vendors. That means your suppliers — even those not directly covered by NIS2 — face contractual security requirements from their NIS2-regulated customers.
Where Site24x7 Digital Risk Analyzer fits in your NIS2 program
DRA directly addresses three of the ten Article 21(2) obligations — the three that require continuous technical monitoring rather than organizational policy. Here is a clear view of what DRA covers, and what sits outside its scope.
Article 21 obligation |
DRA coverage |
|---|---|
Art. 21(2)(a) — Risk analysis and security policies |
Covered. Continuous cyber score across domain, email, application, and network security. Objective risk evidence for your security policy framework. |
Art. 21(2)(b) — Incident handling |
Partially covered. Real-time alerts on security signal changes support early detection. Full incident response workflows require additional tooling. |
Art. 21(2)(c) — Business continuity |
Not covered. Business continuity planning, backup management, and disaster recovery require dedicated continuity tooling. |
Art. 21(2)(d) — Supply chain security |
Fully covered. Outside-in vendor scanning, security questionnaires, fourth-party discovery, vendor risk scoring, and NIS2-mapped compliance reports. |
Art. 21(2)(e) — Security in acquisition and maintenance |
Covered. CVE detection by ID, type, severity, and status. Pre-procurement risk scoring before acquisition decisions. |
Art. 21(2)(f)–(j) — Hygiene, cryptography, access control |
Not covered. Access control, MFA, encryption policies, and HR security require identity, endpoint, and policy management tooling. |
DORA: third-party risk management for EU financial entities
DORA (the Digital Operational Resilience Act), Regulation (EU) 2022/2554, is a directly applicable EU regulation for the financial sector. It became enforceable on 17 January 2025 and applies to approximately 22,000 EU financial entities and their ICT third-party service providers — regardless of where those providers are headquartered.
Unlike NIS2 (a directive transposed into national law) and CIS or NIST (voluntary frameworks), DORA is a directly applicable regulation. It creates uniform, binding obligations across all EU financial entities simultaneously. Its third-party chapter (Articles 28 to 44) carries the highest rate of supervisory findings in 2025 to 2026 assessments.
DORA and NIS2 run in parallel. Financial entities subject to DORA are largely exempt from NIS2's equivalent provisions — DORA is the lex specialis for the financial sector. Both require continuous vendor risk oversight, not periodic review.
How Site24x7 DRA maps to DORA
Continuous outside-in vendor monitoring
DRA monitors every vendor's external attack surface continuously — no vendor cooperation, no agent installs. The data comes from live infrastructure, not self-reported attestations.
Maps to: DORA Article 28(4) — continuous monitoring obligation; Article 28(2) — risk-based TPRM strategy with objective evidence.
Fourth-party and sub-outsourcing discovery
DRA automatically discovers and maps sub-vendors behind your tier-1 providers. The sub-outsourcing chains DORA Article 29(2) requires you to monitor are often invisible to manual programs.
Maps to: DORA Article 29(2) — sub-outsourcing obligations; concentration risk identification across the full supply chain.
DORA-mapped compliance reports
Generate audit-ready reports mapped to DORA's third-party risk requirements. Evidence is timestamped and continuously updated. When your NCA asks, the evidence trail is ready immediately.
Maps to: DORA Article 28(3) — Register of Information maintenance; Article 28(6) — audit rights; reporting obligations to NCAs and ESAs.
How Site24x7 Digital Risk Analyzer addresses all four frameworks
NIS2, CIS v8, NIST CSF 2.0, and DORA share a common operational requirement: continuous visibility into your vendor ecosystem. Site24x7 Digital Risk Analyzer provides the continuous, outside-in monitoring layer that all four frameworks demand — from a single platform.
Cross-framework DRA capabilities
Security questionnaire
Send DRA's built-in standardized cybersecurity questionnaire to vendors. Covers application, network, domain, and email security. Responses captured centrally, scored, and included in vendor risk reports.
Maps to: NIS2 Art. 21(2)(d); DORA Art. 28(4); NIST CSF 2.0 GV.SC-07; CIS Control 15.
Real-time risk alerts
Notified the moment a vendor's risk posture changes — via email, SMS, Slack, PagerDuty, or 50+ integrations. A new CVE, an expired certificate, a misconfigured DNS record — you know within hours.
Maps to: NIS2 Art. 23 incident notification; DORA Art. 30(3) 4-hour notification; NIST CSF 2.0 DE.CM-09; CIS Control 13.
Multi-framework compliance reports
Generate reports mapped to NIS2, DORA, ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, and PCI-DSS in one click. Evidence collected and timestamped continuously.
Maps to: All four frameworks require documented evidence of continuous monitoring. DRA generates that evidence automatically.
What most teams miss: the frameworks are converging on the same requirement. NIS2 Article 21(2)(d), NIST CSF 2.0 GV.SC, CIS Control 15, and DORA Article 28(4) all require continuous, independent visibility into your supply chain's security posture. You do not need four different tools to satisfy four different frameworks.
Get continuous visibility across all five security domains — DNS, email, web, network, and vendor risk
Start 30-day free trailFAQ
1. What is NIS2 and who does it apply to?
NIS2 (Directive (EU) 2022/2555) is the EU's primary cybersecurity legislation, effective from 18 October 2024. It applies to medium and large organizations in 18+ covered sectors across the EU. It also creates indirect obligations for suppliers of in-scope entities through its supply chain security requirements in Article 21(2)(d).
2. When is the NIS2 compliance deadline?
NIS2 became applicable on 18 October 2024. The first compliance audit deadline for in-scope entities is 30 June 2026 [Optro, 2026]. Fines and supervisory enforcement are already active in member states that have transposed.
3. What are the NIS2 penalties for non-compliance?
Essential entities face fines up to €10 million or 2% of global annual revenue. Important entities face fines up to €7 million or 1.4% of global revenue. Senior management can be held personally liable for cybersecurity failures [NIS2, Article 34].
4. What is the difference between NIS2 and DORA?
NIS2 is an EU directive transposed into national law by each member state. DORA is a directly applicable EU regulation — uniform across all member states. NIS2 is cross-sector. DORA applies specifically to the EU financial sector. Financial entities subject to DORA are largely exempt from equivalent NIS2 provisions. Both require continuous vendor risk oversight.
5. How does Site24x7 DRA help with NIS2 supply chain security requirements?
DRA addresses NIS2 Article 21(2)(d) directly: continuous outside-in scanning of vendor security posture, a built-in security questionnaire, fourth-party supply chain discovery, real-time risk alerts, and NIS2-mapped compliance reports — all centrally captured and timestamped.
6. Can one tool satisfy NIS2, CIS v8, NIST CSF 2.0, and DORA?
A single tool cannot satisfy all requirements across all four frameworks. But the common thread — continuous visibility into your supply chain's security posture — can be addressed by one monitoring platform. Site24x7 DRA generates compliance-mapped reports for all four frameworks from a single scan cycle.
7. Which NIS2 Article 21 obligations does Site24x7 DRA directly address?
DRA directly covers three obligations. Art. 21(2)(a) — Risk analysis: DRA produces a continuous cyber score across domain, email, application, and network security, giving you objective, audit-ready risk evidence. Art. 21(2)(d) — Supply chain security: outside-in vendor scanning, built-in security questionnaires, fourth-party discovery, and NIS2-mapped compliance reports satisfy the full scope of this obligation. Art. 21(2)(e) — Acquisition and maintenance security: DRA detects CVEs by ID, type, and severity continuously, and enables pre-procurement risk scoring before any vendor is onboarded. Incident detection under Art. 21(2)(b) is partially covered — real-time alerts shorten your response window, but full incident response workflows require additional tooling.
8. How does DRA's security questionnaire support NIS2 Article 21(2)(d)?
NIS2 Article 21(2)(d) requires you to assess vendor security posture and maintain documented evidence of that assessment. DRA's built-in security questionnaire lets you send a standardized cybersecurity questionnaire — covering application, network, domain, and email security — directly to vendors from the platform. Responses are centrally captured and timestamped, vendor-side risks are flagged automatically, and completed assessments feed into the vendor's overall risk score. This gives you structured, vendor-reported evidence to complement DRA's outside-in scanning — exactly the kind of documented, auditable assessment trail NIS2 supervisors expect to see.
9. Does Site24x7 DRA generate NIS2-specific compliance reports?
Yes. Site24x7 DRA generates one-click compliance reports mapped to NIS2 alongside ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, DORA, and PCI-DSS. Evidence is collected and timestamped continuously — so when a national supervisory authority requests documentation, the audit trail is immediately available without manual assembly. The report maps DRA findings directly to the relevant NIS2 Article 21 obligations, making it usable as a structured compliance artefact for your first NIS2 audit.
10. How does DRA support NIS2 Article 23 incident reporting timelines?
NIS2 Article 23 requires initial notification to your national CSIRT within 24 hours of becoming aware of a significant incident, a fuller report within 72 hours, and a final report within 30 days. DRA contributes by shortening the detection window — real-time alerts fire the moment a vendor's security signal changes, via email, SMS, Slack, or PagerDuty. Early detection of a vendor-side exposure means you become aware sooner, which is when the Article 23 clock starts. DRA does not replace a full incident response workflow, but it closes the gap between an event occurring and your team knowing about it.
11. We use annual vendor questionnaires today. Is that sufficient for NIS2?
No. NIS2 Article 21(2)(d) requires ongoing oversight of your supply chain — not a point-in-time snapshot. An annual questionnaire captures a vendor's self-reported posture on a single day. A vendor can pass a questionnaire in January and suffer a critical misconfiguration or CVE in March. NIS2 supervisors expect continuous monitoring evidence, not a completed form from the previous year. DRA addresses this gap by monitoring your vendors' external attack surfaces continuously and flagging changes in real time. DRA's security questionnaire feature can still be used alongside scanning — it provides structured vendor-reported evidence that complements the independent, outside-in data DRA collects automatically.
