NIS2

NIS2 Compliance, Governance and Cybersecurity Risk Management

From regulatory scope and management accountability to operational resilience, incident reporting and continuing compliance.

NIS2 brings cybersecurity into the governance and risk-management framework of organisations operating across critical and digitally important sectors.

OSTRAI helps organisations determine whether NIS2 applies, establish the appropriate governance and cybersecurity framework, implement the required technical, operational and organisational measures and prepare for incident reporting, supervision and continuing compliance.

NIS2 SCOPE

Does NIS2 apply to your organisation?

NIS2 applicability depends on more than sector alone.

The assessment can require analysis of the services and activities performed, the relevant sector and entity type, organisational size, group structure, establishment, jurisdiction and any specific inclusion or exemption under EU or national law.

Certain entities can fall within scope regardless of size.

OSTRAI supports organisations in establishing and documenting the correct regulatory position before implementation begins.

  1. SECTOR

    Does the organisation operate within an NIS2 sector or subsector?

  2. ENTITY TYPE

    Does the organisation correspond to an entity type covered by the framework?

  3. SIZE

    Does the applicable size threshold bring the entity within scope?

  4. SPECIAL INCLUSION

    Does NIS2 apply regardless of size or because of criticality or national identification?

  5. JURISDICTION

    Which Member State or Member States have regulatory jurisdiction?

  6. SECTOR-SPECIFIC REGIME

    Does another EU cybersecurity regime apply instead for particular obligations?

Request an NIS2 scope assessment
Sunlit limestone colonnade overlooking a European city, with NIS2 governance inscriptions

REGULATORY ARCHITECTURE

Cybersecurity becomes an organisational obligation.

NIS2 requires essential and important entities to manage cybersecurity risk through appropriate and proportionate technical, operational and organisational measures.

The framework reaches beyond individual IT systems.

It connects cybersecurity with governance, risk, people, suppliers, continuity, incident management and regulatory accountability.

OSTRAI approaches NIS2 as an operational regulatory system rather than a documentation exercise.

  1. GOVERN

    Management responsibility · Roles · Policies · Oversight

  2. ASSESS

    Assets · Services · Threats · Vulnerabilities · Risk

  3. PROTECT

    People · Systems · Access · Supply chain · Physical environment

  4. RESPOND

    Detection · Incident handling · Reporting · Crisis management

  5. REVIEW

    Testing · Monitoring · Audit · Remediation · Continual improvement

SECTORS & ENTITIES

NIS2 extends across critical and digitally important sectors.

The Directive covers entity types across sectors of high criticality and other critical sectors, subject to the applicable scope rules and specific inclusions.

  1. SECTORS OF HIGH CRITICALITY

    • Energy
    • Transport
    • Banking
    • Financial market infrastructures
    • Health
    • Drinking water
    • Waste water
    • Digital infrastructure
    • ICT service management
    • Public administration
    • Space
  2. OTHER CRITICAL SECTORS

    • Postal and courier services
    • Waste management
    • Chemicals
    • Food production, processing and distribution
    • Selected manufacturing
    • Online marketplaces
    • Online search engines
    • Social networking platforms
    • Research organisations

ENTITY CLASSIFICATION

Essential and important entities share core obligations, but not the same supervisory model.

NIS2 classifies in-scope organisations as essential or important entities according to the applicable sector, entity type, size and identification rules.

The distinction does not mean that important entities have a separate light version of the cybersecurity risk-management obligations.

It is particularly relevant to the supervisory and enforcement framework.

  1. ESSENTIAL ENTITIES

    Core NIS2 cybersecurity and reporting obligations Subject to both proactive and reactive supervisory measures under the applicable national framework.

  2. IMPORTANT ENTITIES

    Core NIS2 cybersecurity and reporting obligations Generally subject to ex post supervision where evidence, indications or information suggest potential non-compliance.

Correct classification should therefore form part of the initial NIS2 scope analysis.

NIS2 ADVISORY

From scope determination to continuing compliance.

OSTRAI supports organisations across the full NIS2 implementation lifecycle.

  1. SCOPE, CLASSIFICATION & JURISDICTION

    NIS2 applicability, sector and entity-type analysis, size assessment, essential / important classification, establishment, jurisdiction and national implementation.

  2. GOVERNANCE & MANAGEMENT ACCOUNTABILITY

    Management-body responsibilities, governance structures, roles, reporting lines, policy approval, management oversight and cybersecurity training.

  3. CYBERSECURITY RISK MANAGEMENT

    Risk methodology, risk criteria, risk assessments, risk treatment, residual-risk acceptance and integration with enterprise risk management.

  4. POLICIES, CONTROLS & IMPLEMENTATION

    Cybersecurity policies, operational controls, access, cryptography, asset management, monitoring, testing, secure configuration, vulnerability and patch management.

  5. INCIDENT RESPONSE & REPORTING

    Incident classification, escalation, response processes, significant-incident assessment, notification workflows, authority communications and reporting readiness.

  6. BUSINESS CONTINUITY & CRISIS MANAGEMENT

    Business impact analysis, recovery objectives, backups, redundancy, disaster recovery, crisis governance and testing.

  7. SUPPLY-CHAIN SECURITY

    Supplier risk, contractual cybersecurity requirements, due diligence, third-party monitoring, vulnerability obligations, audit rights and subcontracting controls.

  8. SUPERVISION & REGULATORY RESPONSE

    Registration, authority engagement, information requests, audits, remediation, supervisory readiness and continuing compliance.

MANAGEMENT ACCOUNTABILITY

Cybersecurity oversight belongs at management level.

NIS2 places responsibility for cybersecurity risk management within organisational governance.

Management bodies are required to approve the cybersecurity risk-management measures and oversee their implementation.

Members of management bodies are also required to receive cybersecurity training under the applicable national framework.

For organisations subject to the detailed Implementing Regulation, management oversight extends into formal security policies, risk acceptance, compliance reporting and review.

  1. APPROVE

    Cybersecurity framework · Policies · Risk-management measures

  2. OVERSEE

    Implementation · Compliance · Remediation · Resources

  3. UNDERSTAND

    Cyber risks · Operational impact · Regulatory obligations

  4. REVIEW

    Risk position · Incidents · Effectiveness · Material change

OSTRAI supports management bodies in establishing the governance, information flows and evidence needed to exercise meaningful cybersecurity oversight.

Sunlit cloister with engraved risk management, incident response, continuity and supply-chain themes

RISK MANAGEMENT

NIS2 requires an all-hazards approach to cybersecurity risk.

Cybersecurity risk management under NIS2 extends across network and information systems, people, processes, third parties and the physical environment supporting those systems.

Measures must be appropriate and proportionate to the organisation's risk exposure.

  1. RISK ANALYSIS & INFORMATION SECURITY

  2. INCIDENT HANDLING

  3. BUSINESS CONTINUITY & CRISIS MANAGEMENT

  4. SUPPLY-CHAIN SECURITY

  5. SECURE ACQUISITION, DEVELOPMENT & MAINTENANCE

  6. CONTROL EFFECTIVENESS & TESTING

  7. CYBER HYGIENE & TRAINING

  8. CRYPTOGRAPHY & ENCRYPTION

  9. HR SECURITY, ACCESS CONTROL & ASSET MANAGEMENT

  10. MULTI-FACTOR & SECURE COMMUNICATIONS

IMPLEMENTING REGULATION

For specified digital providers, NIS2 is considerably more granular.

Commission Implementing Regulation (EU) 2024/2690 establishes detailed technical and methodological cybersecurity requirements for specified digital and trust-service providers.

It applies to:

  • DNS service providers
  • TLD name registries
  • Cloud computing service providers
  • Data centre service providers
  • Content delivery network providers
  • Managed service providers
  • Managed security service providers
  • Online marketplaces
  • Online search engines
  • Social networking service platforms
  • Trust service providers

For these organisations, the regulatory framework reaches into detailed governance, operational and technical controls.

  1. GOVERNANCE & RISK

    Security policy · Roles · Risk framework · Risk treatment · Compliance monitoring

  2. DETECTION & INCIDENT HANDLING

    Monitoring · Logging · Event assessment · Incident response · Post-incident review

  3. CONTINUITY & CRISIS

    Business impact analysis · Recovery · Backups · Redundancy · Crisis management

  4. SUPPLY CHAIN

    Supplier selection · Security clauses · Incident notification · Audit rights · Subcontracting

  5. SECURE TECHNOLOGY LIFECYCLE

    Acquisition · Secure development · Configuration · Change · Testing · Patching · Vulnerability handling

  6. NETWORK & ACCESS

    Network security · Segmentation · Identity · Privileged access · Authentication · MFA

  7. PEOPLE & SECURITY CULTURE

    Cyber hygiene · Training · HR security · Responsibilities

  8. ASSETS & PHYSICAL ENVIRONMENT

    Asset classification · Inventory · Physical access · Utilities · Environmental security

Where a requirement is framed as applicable only where appropriate, applicable or feasible, a decision not to implement it can itself require a comprehensible documented justification.

European and international standards can support implementation and evidence of compliance, but the applicable legal requirements remain determined by NIS2, national law and, where relevant, Commission Implementing Regulation (EU) 2024/2690.

See Standards & Standardisation

COMPLIANCE EVIDENCE

Implementation must be capable of being demonstrated.

NIS2 compliance requires more than the existence of policies.

Governance decisions, risk assessments, control implementation, tests, incidents, reviews and corrective action should create a coherent evidence trail capable of supporting management oversight and regulatory supervision.

  1. POLICY

    Approved framework · Topic-specific policies · Responsibilities

  2. RISK

    Assessment · Treatment · Residual risk · Decisions

  3. CONTROL

    Implementation · Configuration · Testing · Monitoring

  4. ASSURANCE

    Review · Evidence · Corrective action · Management reporting

INCIDENT REPORTING

Significant incidents trigger a staged reporting process.

NIS2 requires essential and important entities to notify significant incidents without undue delay through a staged process.

  1. 24 HOURS

    EARLY WARNING

    Without undue delay and in any event within 24 hours of becoming aware of a significant incident.

    Where applicable: suspected unlawful or malicious cause · possible cross-border impact

  2. 72 HOURS

    INCIDENT NOTIFICATION

    Without undue delay and in any event within 72 hours of awareness.

    Updates the early warning and includes an initial assessment of severity and impact and, where available, indicators of compromise.

  3. ONE MONTH

    FINAL REPORT

    Not later than one month after the incident notification.

    Detailed description · Severity · Impact · Likely threat or root cause · Mitigation · Cross-border impact where applicable

Specific reporting timelines can apply to particular categories of entity, including trust service providers.

The reporting clock runs from awareness of a significant incident, making internal detection, escalation and legal assessment procedures important.

REPORTABILITY

The first question is whether the incident is significant.

Under NIS2, significant-incident assessment considers whether an incident has caused or is capable of causing severe operational disruption or financial loss for the entity, or considerable material or non-material damage to other persons.

For the digital and trust-service providers covered by Commission Implementing Regulation (EU) 2024/2690, additional horizontal and sector-specific significance criteria apply.

  1. OPERATIONAL EFFECT

    Availability · Service disruption · Duration · Users

  2. FINANCIAL / THIRD-PARTY EFFECT

    Financial loss · Material damage · Non-material damage · Health impacts

  3. SECURITY EFFECT

    Unauthorised access · Confidentiality · Integrity · Authenticity · Recurring incidents

OSTRAI supports incident triage, reportability assessment, regulatory notification preparation and coordination of the legal and operational response.

OPERATIONAL READINESS

Reporting only works if the incident process works first.

Organisations need processes capable of detecting, assessing, escalating, containing and documenting incidents quickly enough to support regulatory reporting.

  1. DETECT

    Monitoring · Logging · Event reporting

  2. ASSESS

    Nature · Severity · Impact · Significance

  3. CONTAIN

    Containment · Evidence · Stakeholder coordination

  4. REPORT

    24-hour warning · 72-hour notification · Regulatory communication

  5. RECOVER

    Eradication · Restoration · Business continuity

  6. LEARN

    Root cause · Post-incident review · Corrective action

OPERATIONAL RESILIENCE

Cybersecurity includes the ability to continue and recover.

NIS2 connects cybersecurity risk management with business continuity, disaster recovery, backup and crisis management.

For organisations subject to the detailed Implementing Regulation, this includes business-impact analysis, recovery requirements, tested backup arrangements, redundancy and formal crisis-management processes.

  1. BUSINESS IMPACT

    Critical operations · Dependencies · Consequences

  2. RECOVERY

    RTO · RPO · Restoration priorities · Resources

  3. BACKUP & REDUNDANCY

    Integrity · Separation · Testing · Alternative resources

  4. CRISIS GOVERNANCE

    Roles · Communications · Authorities · Exercises

SUPPLY CHAIN

Cybersecurity risk extends beyond the organisation.

NIS2 requires organisations to address cybersecurity risks arising from suppliers and service providers.

For entities subject to the detailed Implementing Regulation, supply-chain governance can extend into supplier-selection criteria, contractual security requirements, incident notification, vulnerability handling, audit rights, subcontracting and termination arrangements.

  1. DUE DILIGENCE

    Supplier practices · Resilience · Secure development

  2. CONTRACTING

    Security requirements · SLAs · Responsibilities

  3. INCIDENTS & VULNERABILITIES

    Notification · Remediation · Cooperation

  4. ASSURANCE

    Audit rights · Audit reports · Monitoring

  5. DEPENDENCIES

    Subcontracting · Concentration · Vendor lock-in · Exit

See Cybersecurity & Product Regulation

REGULATORY INTERSECTIONS

NIS2 does not always operate alone.

Some sectors are subject to separate EU cybersecurity frameworks.

Where a sector-specific Union legal act imposes cybersecurity risk-management or significant-incident reporting requirements that are at least equivalent in effect to the relevant NIS2 obligations, the corresponding NIS2 provisions can give way to that sector-specific framework.

  1. DORA

    For financial entities within its scope, DORA operates as the sector-specific framework for the relevant ICT risk-management, incident-reporting, resilience-testing and third-party-risk obligations.

  2. CYBERSECURITY ACT & CERTIFICATION

    NIS2 already connects cybersecurity risk management with the European cybersecurity certification framework.

    The current Cybersecurity Act provides the European framework for cybersecurity certification of ICT products, ICT services and ICT processes, and its scope has also been extended to managed security services.

    The proposed Cybersecurity Act 2 and accompanying proposed amendments to NIS2 would deepen this relationship, including through a renewed certification framework and the proposed certification of the cybersecurity posture of organisations.

    Current certification framework · Managed security services · Cybersecurity Act 2 proposal · NIS2 alignment

    See Standards & Standardisation
  3. CRITICAL ENTITIES

    NIS2 interacts with the Critical Entities Resilience framework across cyber and physical resilience.

  4. OTHER SECTOR-SPECIFIC RULES

    Sectoral cybersecurity obligations must be assessed to determine whether and to what extent the NIS2 framework continues to apply.

OSTRAI assesses these intersections before designing the compliance programme.

NATIONAL IMPLEMENTATION

NIS2 is European. Implementation remains national.

NIS2 is a Directive implemented through national law.

Organisations operating across Europe must therefore consider the applicable national transposition rules, competent authorities, registration mechanisms, supervisory procedures and enforcement framework.

  1. EU FRAMEWORK

    Common NIS2 baseline

  2. NATIONAL LAW

    Transposition · Additional detail · Procedures

  3. COMPETENT AUTHORITY

    Registration · Supervision · Reporting

  4. CROSS-BORDER POSITION

    Establishment · Main establishment · Representative · Jurisdiction

CYPRUS

NIS2 has been transposed into Cyprus law.

Cyprus transposed NIS2 through Law 60(I)/2025, amending the Security of Networks and Information Systems Law 89(I)/2020.

The national framework includes the identification and maintenance of lists of essential and important entities, regulatory information requirements and supervisory powers.

It also contains specific mechanisms relevant to newly established or potentially in-scope entities.

OSTRAI supports Cyprus-based and international organisations in assessing the EU NIS2 framework together with the applicable Cyprus implementation.

  1. SCOPE & IDENTIFICATION

    Essential / important status · National assessment

  2. REGISTRATION & INFORMATION

    Entity information · Changes · Authority engagement

  3. IMPLEMENTATION & SUPERVISION

    Cybersecurity measures · Incident reporting · Regulatory readiness

NON-EU PROVIDERS

Certain non-EU digital providers require an EU representative.

NIS2 requires specified non-EU digital and infrastructure service providers offering services in the Union to designate a representative in the EU.

The representative is appointed through a written mandate and can be addressed by competent authorities or CSIRTs in relation to the entity's NIS2 obligations, including incident reporting.

This role is distinct from GDPR, DSA and other EU representative mandates.

NIS2 Representative

SUPERVISION & ENFORCEMENT

Compliance must be ready for regulatory scrutiny.

NIS2 strengthens the supervisory framework for cybersecurity compliance.

Essential and important entities are subject to different supervisory models, but both must be capable of demonstrating compliance with their applicable obligations.

OSTRAI supports organisations in preparing for regulatory interaction and responding where supervisory issues arise.

  1. INFORMATION REQUESTS

    Policies · Risk · Evidence · Documentation

  2. AUDITS & REVIEWS

    Controls · Findings · Corrective action

  3. REMEDIATION

    Governance · Measures · Timelines · Evidence

  4. REGULATORY RESPONSE

    Authority communications · Investigation · Follow-up

IMPLEMENTATION

From regulatory scope to operational resilience.

  1. SCOPE

    Sector · Entity type · Size · Jurisdiction

  2. BASELINE

    Existing governance · Controls · Evidence

  3. GAP ASSESSMENT

    Legal requirements · Technical requirements · Deficiencies

  4. TARGET STATE

    Governance · Controls · Priorities · Ownership

  5. IMPLEMENTATION

    Policies · Processes · Technology · Contracts

  6. TEST & EVIDENCE

    Exercises · Testing · Review · Documentation

  7. CONTINUING COMPLIANCE

    Monitoring · Incidents · Changes · Improvement

WHY OSTRAI

Cybersecurity regulation requires legal and operational integration.

NIS2 implementation sits at the intersection of regulation, governance, cybersecurity, operational resilience and standards.

OSTRAI connects those disciplines so that legal obligations can be translated into implementable requirements and evidence.

  1. REGULATORY SCOPE

    Determine what applies before implementation begins.

  2. GOVERNANCE

    Connect cybersecurity requirements with management accountability.

  3. IMPLEMENTATION

    Translate regulatory requirements into operational controls and evidence.

  4. CROSS-REGIME VIEW

    Coordinate NIS2 with privacy, digital regulation, product cybersecurity and other sector-specific frameworks.

NIS2

Build cybersecurity governance around the organisation that actually operates.

OSTRAI helps organisations determine whether NIS2 applies, establish accountable cybersecurity governance and translate regulatory requirements into operational measures, evidence and continuing compliance.