NIS2
NIS2 Compliance, Governance and Cybersecurity Risk Management
From regulatory scope and management accountability to operational resilience, incident reporting and continuing compliance.
NIS2 brings cybersecurity into the governance and risk-management framework of organisations operating across critical and digitally important sectors.
OSTRAI helps organisations determine whether NIS2 applies, establish the appropriate governance and cybersecurity framework, implement the required technical, operational and organisational measures and prepare for incident reporting, supervision and continuing compliance.
NIS2 SCOPE
Does NIS2 apply to your organisation?
NIS2 applicability depends on more than sector alone.
The assessment can require analysis of the services and activities performed, the relevant sector and entity type, organisational size, group structure, establishment, jurisdiction and any specific inclusion or exemption under EU or national law.
Certain entities can fall within scope regardless of size.
OSTRAI supports organisations in establishing and documenting the correct regulatory position before implementation begins.
SECTOR
Does the organisation operate within an NIS2 sector or subsector?
ENTITY TYPE
Does the organisation correspond to an entity type covered by the framework?
SIZE
Does the applicable size threshold bring the entity within scope?
SPECIAL INCLUSION
Does NIS2 apply regardless of size or because of criticality or national identification?
JURISDICTION
Which Member State or Member States have regulatory jurisdiction?
SECTOR-SPECIFIC REGIME
Does another EU cybersecurity regime apply instead for particular obligations?

REGULATORY ARCHITECTURE
Cybersecurity becomes an organisational obligation.
NIS2 requires essential and important entities to manage cybersecurity risk through appropriate and proportionate technical, operational and organisational measures.
The framework reaches beyond individual IT systems.
It connects cybersecurity with governance, risk, people, suppliers, continuity, incident management and regulatory accountability.
OSTRAI approaches NIS2 as an operational regulatory system rather than a documentation exercise.
GOVERN
Management responsibility · Roles · Policies · Oversight
ASSESS
Assets · Services · Threats · Vulnerabilities · Risk
PROTECT
People · Systems · Access · Supply chain · Physical environment
RESPOND
Detection · Incident handling · Reporting · Crisis management
REVIEW
Testing · Monitoring · Audit · Remediation · Continual improvement
SECTORS & ENTITIES
NIS2 extends across critical and digitally important sectors.
The Directive covers entity types across sectors of high criticality and other critical sectors, subject to the applicable scope rules and specific inclusions.
SECTORS OF HIGH CRITICALITY
- Energy
- Transport
- Banking
- Financial market infrastructures
- Health
- Drinking water
- Waste water
- Digital infrastructure
- ICT service management
- Public administration
- Space
OTHER CRITICAL SECTORS
- Postal and courier services
- Waste management
- Chemicals
- Food production, processing and distribution
- Selected manufacturing
- Online marketplaces
- Online search engines
- Social networking platforms
- Research organisations
ENTITY CLASSIFICATION
Essential and important entities share core obligations, but not the same supervisory model.
NIS2 classifies in-scope organisations as essential or important entities according to the applicable sector, entity type, size and identification rules.
The distinction does not mean that important entities have a separate light version of the cybersecurity risk-management obligations.
It is particularly relevant to the supervisory and enforcement framework.
ESSENTIAL ENTITIES
Core NIS2 cybersecurity and reporting obligations Subject to both proactive and reactive supervisory measures under the applicable national framework.
IMPORTANT ENTITIES
Core NIS2 cybersecurity and reporting obligations Generally subject to ex post supervision where evidence, indications or information suggest potential non-compliance.
Correct classification should therefore form part of the initial NIS2 scope analysis.
NIS2 ADVISORY
From scope determination to continuing compliance.
OSTRAI supports organisations across the full NIS2 implementation lifecycle.
SCOPE, CLASSIFICATION & JURISDICTION
NIS2 applicability, sector and entity-type analysis, size assessment, essential / important classification, establishment, jurisdiction and national implementation.
GOVERNANCE & MANAGEMENT ACCOUNTABILITY
Management-body responsibilities, governance structures, roles, reporting lines, policy approval, management oversight and cybersecurity training.
CYBERSECURITY RISK MANAGEMENT
Risk methodology, risk criteria, risk assessments, risk treatment, residual-risk acceptance and integration with enterprise risk management.
POLICIES, CONTROLS & IMPLEMENTATION
Cybersecurity policies, operational controls, access, cryptography, asset management, monitoring, testing, secure configuration, vulnerability and patch management.
INCIDENT RESPONSE & REPORTING
Incident classification, escalation, response processes, significant-incident assessment, notification workflows, authority communications and reporting readiness.
BUSINESS CONTINUITY & CRISIS MANAGEMENT
Business impact analysis, recovery objectives, backups, redundancy, disaster recovery, crisis governance and testing.
SUPPLY-CHAIN SECURITY
Supplier risk, contractual cybersecurity requirements, due diligence, third-party monitoring, vulnerability obligations, audit rights and subcontracting controls.
SUPERVISION & REGULATORY RESPONSE
Registration, authority engagement, information requests, audits, remediation, supervisory readiness and continuing compliance.
MANAGEMENT ACCOUNTABILITY
Cybersecurity oversight belongs at management level.
NIS2 places responsibility for cybersecurity risk management within organisational governance.
Management bodies are required to approve the cybersecurity risk-management measures and oversee their implementation.
Members of management bodies are also required to receive cybersecurity training under the applicable national framework.
For organisations subject to the detailed Implementing Regulation, management oversight extends into formal security policies, risk acceptance, compliance reporting and review.
APPROVE
Cybersecurity framework · Policies · Risk-management measures
OVERSEE
Implementation · Compliance · Remediation · Resources
UNDERSTAND
Cyber risks · Operational impact · Regulatory obligations
REVIEW
Risk position · Incidents · Effectiveness · Material change
OSTRAI supports management bodies in establishing the governance, information flows and evidence needed to exercise meaningful cybersecurity oversight.

RISK MANAGEMENT
NIS2 requires an all-hazards approach to cybersecurity risk.
Cybersecurity risk management under NIS2 extends across network and information systems, people, processes, third parties and the physical environment supporting those systems.
Measures must be appropriate and proportionate to the organisation's risk exposure.
RISK ANALYSIS & INFORMATION SECURITY
INCIDENT HANDLING
BUSINESS CONTINUITY & CRISIS MANAGEMENT
SUPPLY-CHAIN SECURITY
SECURE ACQUISITION, DEVELOPMENT & MAINTENANCE
CONTROL EFFECTIVENESS & TESTING
CYBER HYGIENE & TRAINING
CRYPTOGRAPHY & ENCRYPTION
HR SECURITY, ACCESS CONTROL & ASSET MANAGEMENT
MULTI-FACTOR & SECURE COMMUNICATIONS
IMPLEMENTING REGULATION
For specified digital providers, NIS2 is considerably more granular.
Commission Implementing Regulation (EU) 2024/2690 establishes detailed technical and methodological cybersecurity requirements for specified digital and trust-service providers.
It applies to:
- DNS service providers
- TLD name registries
- Cloud computing service providers
- Data centre service providers
- Content delivery network providers
- Managed service providers
- Managed security service providers
- Online marketplaces
- Online search engines
- Social networking service platforms
- Trust service providers
For these organisations, the regulatory framework reaches into detailed governance, operational and technical controls.
GOVERNANCE & RISK
Security policy · Roles · Risk framework · Risk treatment · Compliance monitoring
DETECTION & INCIDENT HANDLING
Monitoring · Logging · Event assessment · Incident response · Post-incident review
CONTINUITY & CRISIS
Business impact analysis · Recovery · Backups · Redundancy · Crisis management
SUPPLY CHAIN
Supplier selection · Security clauses · Incident notification · Audit rights · Subcontracting
SECURE TECHNOLOGY LIFECYCLE
Acquisition · Secure development · Configuration · Change · Testing · Patching · Vulnerability handling
NETWORK & ACCESS
Network security · Segmentation · Identity · Privileged access · Authentication · MFA
PEOPLE & SECURITY CULTURE
Cyber hygiene · Training · HR security · Responsibilities
ASSETS & PHYSICAL ENVIRONMENT
Asset classification · Inventory · Physical access · Utilities · Environmental security
Where a requirement is framed as applicable only where appropriate, applicable or feasible, a decision not to implement it can itself require a comprehensible documented justification.
European and international standards can support implementation and evidence of compliance, but the applicable legal requirements remain determined by NIS2, national law and, where relevant, Commission Implementing Regulation (EU) 2024/2690.
See Standards & StandardisationCOMPLIANCE EVIDENCE
Implementation must be capable of being demonstrated.
NIS2 compliance requires more than the existence of policies.
Governance decisions, risk assessments, control implementation, tests, incidents, reviews and corrective action should create a coherent evidence trail capable of supporting management oversight and regulatory supervision.
POLICY
Approved framework · Topic-specific policies · Responsibilities
RISK
Assessment · Treatment · Residual risk · Decisions
CONTROL
Implementation · Configuration · Testing · Monitoring
ASSURANCE
Review · Evidence · Corrective action · Management reporting
INCIDENT REPORTING
Significant incidents trigger a staged reporting process.
NIS2 requires essential and important entities to notify significant incidents without undue delay through a staged process.
24 HOURS
EARLY WARNING
Without undue delay and in any event within 24 hours of becoming aware of a significant incident.
Where applicable: suspected unlawful or malicious cause · possible cross-border impact
72 HOURS
INCIDENT NOTIFICATION
Without undue delay and in any event within 72 hours of awareness.
Updates the early warning and includes an initial assessment of severity and impact and, where available, indicators of compromise.
ONE MONTH
FINAL REPORT
Not later than one month after the incident notification.
Detailed description · Severity · Impact · Likely threat or root cause · Mitigation · Cross-border impact where applicable
Specific reporting timelines can apply to particular categories of entity, including trust service providers.
The reporting clock runs from awareness of a significant incident, making internal detection, escalation and legal assessment procedures important.
REPORTABILITY
The first question is whether the incident is significant.
Under NIS2, significant-incident assessment considers whether an incident has caused or is capable of causing severe operational disruption or financial loss for the entity, or considerable material or non-material damage to other persons.
For the digital and trust-service providers covered by Commission Implementing Regulation (EU) 2024/2690, additional horizontal and sector-specific significance criteria apply.
OPERATIONAL EFFECT
Availability · Service disruption · Duration · Users
FINANCIAL / THIRD-PARTY EFFECT
Financial loss · Material damage · Non-material damage · Health impacts
SECURITY EFFECT
Unauthorised access · Confidentiality · Integrity · Authenticity · Recurring incidents
OSTRAI supports incident triage, reportability assessment, regulatory notification preparation and coordination of the legal and operational response.
OPERATIONAL READINESS
Reporting only works if the incident process works first.
Organisations need processes capable of detecting, assessing, escalating, containing and documenting incidents quickly enough to support regulatory reporting.
DETECT
Monitoring · Logging · Event reporting
ASSESS
Nature · Severity · Impact · Significance
CONTAIN
Containment · Evidence · Stakeholder coordination
REPORT
24-hour warning · 72-hour notification · Regulatory communication
RECOVER
Eradication · Restoration · Business continuity
LEARN
Root cause · Post-incident review · Corrective action
OPERATIONAL RESILIENCE
Cybersecurity includes the ability to continue and recover.
NIS2 connects cybersecurity risk management with business continuity, disaster recovery, backup and crisis management.
For organisations subject to the detailed Implementing Regulation, this includes business-impact analysis, recovery requirements, tested backup arrangements, redundancy and formal crisis-management processes.
BUSINESS IMPACT
Critical operations · Dependencies · Consequences
RECOVERY
RTO · RPO · Restoration priorities · Resources
BACKUP & REDUNDANCY
Integrity · Separation · Testing · Alternative resources
CRISIS GOVERNANCE
Roles · Communications · Authorities · Exercises
SUPPLY CHAIN
Cybersecurity risk extends beyond the organisation.
NIS2 requires organisations to address cybersecurity risks arising from suppliers and service providers.
For entities subject to the detailed Implementing Regulation, supply-chain governance can extend into supplier-selection criteria, contractual security requirements, incident notification, vulnerability handling, audit rights, subcontracting and termination arrangements.
DUE DILIGENCE
Supplier practices · Resilience · Secure development
CONTRACTING
Security requirements · SLAs · Responsibilities
INCIDENTS & VULNERABILITIES
Notification · Remediation · Cooperation
ASSURANCE
Audit rights · Audit reports · Monitoring
DEPENDENCIES
Subcontracting · Concentration · Vendor lock-in · Exit
REGULATORY INTERSECTIONS
NIS2 does not always operate alone.
Some sectors are subject to separate EU cybersecurity frameworks.
Where a sector-specific Union legal act imposes cybersecurity risk-management or significant-incident reporting requirements that are at least equivalent in effect to the relevant NIS2 obligations, the corresponding NIS2 provisions can give way to that sector-specific framework.
DORA
For financial entities within its scope, DORA operates as the sector-specific framework for the relevant ICT risk-management, incident-reporting, resilience-testing and third-party-risk obligations.
CYBERSECURITY ACT & CERTIFICATION
NIS2 already connects cybersecurity risk management with the European cybersecurity certification framework.
The current Cybersecurity Act provides the European framework for cybersecurity certification of ICT products, ICT services and ICT processes, and its scope has also been extended to managed security services.
The proposed Cybersecurity Act 2 and accompanying proposed amendments to NIS2 would deepen this relationship, including through a renewed certification framework and the proposed certification of the cybersecurity posture of organisations.
Current certification framework · Managed security services · Cybersecurity Act 2 proposal · NIS2 alignment
See Standards & StandardisationCRITICAL ENTITIES
NIS2 interacts with the Critical Entities Resilience framework across cyber and physical resilience.
OTHER SECTOR-SPECIFIC RULES
Sectoral cybersecurity obligations must be assessed to determine whether and to what extent the NIS2 framework continues to apply.
OSTRAI assesses these intersections before designing the compliance programme.
NATIONAL IMPLEMENTATION
NIS2 is European. Implementation remains national.
NIS2 is a Directive implemented through national law.
Organisations operating across Europe must therefore consider the applicable national transposition rules, competent authorities, registration mechanisms, supervisory procedures and enforcement framework.
EU FRAMEWORK
Common NIS2 baseline
NATIONAL LAW
Transposition · Additional detail · Procedures
COMPETENT AUTHORITY
Registration · Supervision · Reporting
CROSS-BORDER POSITION
Establishment · Main establishment · Representative · Jurisdiction
CYPRUS
NIS2 has been transposed into Cyprus law.
Cyprus transposed NIS2 through Law 60(I)/2025, amending the Security of Networks and Information Systems Law 89(I)/2020.
The national framework includes the identification and maintenance of lists of essential and important entities, regulatory information requirements and supervisory powers.
It also contains specific mechanisms relevant to newly established or potentially in-scope entities.
OSTRAI supports Cyprus-based and international organisations in assessing the EU NIS2 framework together with the applicable Cyprus implementation.
SCOPE & IDENTIFICATION
Essential / important status · National assessment
REGISTRATION & INFORMATION
Entity information · Changes · Authority engagement
IMPLEMENTATION & SUPERVISION
Cybersecurity measures · Incident reporting · Regulatory readiness
NON-EU PROVIDERS
Certain non-EU digital providers require an EU representative.
NIS2 requires specified non-EU digital and infrastructure service providers offering services in the Union to designate a representative in the EU.
The representative is appointed through a written mandate and can be addressed by competent authorities or CSIRTs in relation to the entity's NIS2 obligations, including incident reporting.
This role is distinct from GDPR, DSA and other EU representative mandates.
SUPERVISION & ENFORCEMENT
Compliance must be ready for regulatory scrutiny.
NIS2 strengthens the supervisory framework for cybersecurity compliance.
Essential and important entities are subject to different supervisory models, but both must be capable of demonstrating compliance with their applicable obligations.
OSTRAI supports organisations in preparing for regulatory interaction and responding where supervisory issues arise.
INFORMATION REQUESTS
Policies · Risk · Evidence · Documentation
AUDITS & REVIEWS
Controls · Findings · Corrective action
REMEDIATION
Governance · Measures · Timelines · Evidence
REGULATORY RESPONSE
Authority communications · Investigation · Follow-up
IMPLEMENTATION
From regulatory scope to operational resilience.
SCOPE
Sector · Entity type · Size · Jurisdiction
BASELINE
Existing governance · Controls · Evidence
GAP ASSESSMENT
Legal requirements · Technical requirements · Deficiencies
TARGET STATE
Governance · Controls · Priorities · Ownership
IMPLEMENTATION
Policies · Processes · Technology · Contracts
TEST & EVIDENCE
Exercises · Testing · Review · Documentation
CONTINUING COMPLIANCE
Monitoring · Incidents · Changes · Improvement
WHY OSTRAI
Cybersecurity regulation requires legal and operational integration.
NIS2 implementation sits at the intersection of regulation, governance, cybersecurity, operational resilience and standards.
OSTRAI connects those disciplines so that legal obligations can be translated into implementable requirements and evidence.
REGULATORY SCOPE
Determine what applies before implementation begins.
GOVERNANCE
Connect cybersecurity requirements with management accountability.
IMPLEMENTATION
Translate regulatory requirements into operational controls and evidence.
CROSS-REGIME VIEW
Coordinate NIS2 with privacy, digital regulation, product cybersecurity and other sector-specific frameworks.
NIS2
Build cybersecurity governance around the organisation that actually operates.
OSTRAI helps organisations determine whether NIS2 applies, establish accountable cybersecurity governance and translate regulatory requirements into operational measures, evidence and continuing compliance.
