Map your obligations, structure your risk management measures and keep your evidence ready for the supervisory authority.
Directive (EU) 2022/2555, known as NIS2, widens the scope of its predecessor considerably: it covers eighteen sectors and separates essential entities from important entities, under different supervisory regimes. Article 21 mandates cybersecurity risk management measures, including risk analysis, incident handling, business continuity, supply chain security and assessment of how effective those measures are. Article 23 governs the reporting of significant incidents, with an early warning within 24 hours and a notification within 72 hours. Management bodies are explicitly accountable, which moves the topic from the IT department to the board.
Reaching NIS2 compliance without a dedicated platform means maintaining, by hand, the mapping between the Article 21 measures, your existing controls and your evidence. A useful NIS2 solution therefore carries four things: the risk assessment that justifies your measures, the register of measures and their effectiveness, the assessment of your critical suppliers, and an evidence file you can produce on demand. Most entities in scope are already running ISO 27001 or EBIOS RM work, so the point is to reuse it rather than start from a blank page.
Vailor automatically reconciles NIS2 requirements with the ISO 27001 controls and EBIOS RM assessments you have already produced, so you only work the real gap. Agentic AI drafts the risk assessments and prepares the deliverables, with every output explainable and traceable in front of an auditor or an authority. Your data is hosted in France and the European Union, which is consistent with a directive whose whole purpose is European resilience.
AI runs your EBIOS RM workshops and produces the risk assessment that justifies your management measures.
The Article 21 register of measures, their implementation and the assessment of their effectiveness, in one place.
Every measure, piece of evidence and decision is timestamped and documented, so you answer the authority without reconstruction.
The assessment of your critical suppliers, required by Article 21, runs from the same platform.
Two criteria combine: sector and size. An organisation has to operate in one of the sectors listed in the directive's annexes and reach at least the size of a medium-sized enterprise under the European definition, in practice fifty staff or ten million euros of turnover or balance sheet total. The directive itself sets that size test aside in several cases: DNS service providers, trust service providers, and any organisation that is the sole provider in its country of an essential service. The European transposition deadline was 17 October 2024, with the detail then set by each national law.
The classification follows sector and size: large companies in the sectors of high criticality are essential entities, the other organisations in scope are important entities. The risk management measures expected of them are the same; what changes is supervision. An essential entity is supervised proactively, with inspections and audits possible without any prior suspicion. An important entity is supervised after the fact, once there is an indication of non-compliance or an incident. The penalty ceilings differ as well.
No. NIS2 is a directive, not a certifiable standard: no body issues a NIS2 certificate, and a supplier promising you one is selling something else. What the supervisory authority expects is evidence that your risk management measures are defined, implemented, assessed and documented. An ISO 27001 certificate, or a European certification covering a product or a service, can support that case, but it does not replace the demonstration itself.
No, but it covers a good part of the ground. A certified management system already delivers risk assessment, incident handling, business continuity and supplier oversight. What remains is what belongs to the directive: the reporting deadlines towards the authority, the formal accountability of management bodies and their training obligation, and above all the scope, which is that of your regulated activities and not only the one you chose to certify. The useful work is measuring that gap, not starting again.
The directive requires member states to provide for minimum ceilings: for an essential entity, at least ten million euros or 2% of worldwide annual turnover, whichever is higher; for an important entity, at least seven million euros or 1.4%. Fines are not the only lever. An authority can order corrective measures, make a breach public and, for essential entities only, temporarily suspend an authorisation or act on managerial responsibilities.
Not necessarily, and that is where the difficulty sits. The directive only binds the organisations within its scope, yet it makes you accountable for the security of your supply chain, including for providers that carry no direct obligation of their own. You are expected to assess the risk attached to each supplier, take the quality of their security practices into account and carry your requirements into the contracts. A supplier outside the scope is not a supplier outside the analysis.
Because NIS2 compliance is demonstrated through links, not through a list. The authority wants to see which measure covers which requirement, which risk justifies it, which evidence supports it and when it was last reviewed. A spreadsheet loses those links as soon as a scope shifts or an owner changes role, and it keeps no history of the decisions taken. A platform maintains them, flags what has gone stale and produces the deliverables without re-keying. With Vailor, AI also cuts the time spent on risk assessments by 70%.
Discover all our resources on governance, risk, and compliance powered by artificial intelligence.
Everything you need to know about AI GRC: definition, benefits, implementation, and best practices to transform your governance with artificial intelligence.
Essential criteria for selecting the best cyber AI GRC platform. Architecture, sovereignty, features: the complete buying guide.
Book a demo and see where you actually stand against the Article 21 measures.