NIS2 Directive

The NIS2 Software That Drives Your Compliance

Map your obligations, structure your risk management measures and keep your evidence ready for the supervisory authority.

Discover the platform

What the NIS2 directive requires

Directive (EU) 2022/2555, known as NIS2, widens the scope of its predecessor considerably: it covers eighteen sectors and separates essential entities from important entities, under different supervisory regimes. Article 21 mandates cybersecurity risk management measures, including risk analysis, incident handling, business continuity, supply chain security and assessment of how effective those measures are. Article 23 governs the reporting of significant incidents, with an early warning within 24 hours and a notification within 72 hours. Management bodies are explicitly accountable, which moves the topic from the IT department to the board.

What a NIS2 tool has to give you

Reaching NIS2 compliance without a dedicated platform means maintaining, by hand, the mapping between the Article 21 measures, your existing controls and your evidence. A useful NIS2 solution therefore carries four things: the risk assessment that justifies your measures, the register of measures and their effectiveness, the assessment of your critical suppliers, and an evidence file you can produce on demand. Most entities in scope are already running ISO 27001 or EBIOS RM work, so the point is to reuse it rather than start from a blank page.

Why Vailor for your NIS2 compliance

Vailor automatically reconciles NIS2 requirements with the ISO 27001 controls and EBIOS RM assessments you have already produced, so you only work the real gap. Agentic AI drafts the risk assessments and prepares the deliverables, with every output explainable and traceable in front of an auditor or an authority. Your data is hosted in France and the European Union, which is consistent with a directive whose whole purpose is European resilience.

What Vailor's NIS2 software covers

Article 21 risk assessment

AI runs your EBIOS RM workshops and produces the risk assessment that justifies your management measures.

Measures and effectiveness

The Article 21 register of measures, their implementation and the assessment of their effectiveness, in one place.

Evidence ready for review

Every measure, piece of evidence and decision is timestamped and documented, so you answer the authority without reconstruction.

Supply chain security

The assessment of your critical suppliers, required by Article 21, runs from the same platform.

What a dedicated NIS2 tool gives you

Know whether you are an essential or an important entity, and what that changes
Reuse your ISO 27001 controls instead of starting from scratch
Justify your measures with a risk assessment, not a statement
Keep an evidence file you can produce at any moment
Drive the security of your supply chain
Keep your compliance data in France and the EU

Frequently asked questions about NIS2

Who falls within the scope of the NIS2 directive?

Two criteria combine: sector and size. An organisation has to operate in one of the sectors listed in the directive's annexes and reach at least the size of a medium-sized enterprise under the European definition, in practice fifty staff or ten million euros of turnover or balance sheet total. The directive itself sets that size test aside in several cases: DNS service providers, trust service providers, and any organisation that is the sole provider in its country of an essential service. The European transposition deadline was 17 October 2024, with the detail then set by each national law.

Essential or important entity: what is the difference?

The classification follows sector and size: large companies in the sectors of high criticality are essential entities, the other organisations in scope are important entities. The risk management measures expected of them are the same; what changes is supervision. An essential entity is supervised proactively, with inspections and audits possible without any prior suspicion. An important entity is supervised after the fact, once there is an indication of non-compliance or an incident. The penalty ceilings differ as well.

Is there such a thing as NIS2 certification?

No. NIS2 is a directive, not a certifiable standard: no body issues a NIS2 certificate, and a supplier promising you one is selling something else. What the supervisory authority expects is evidence that your risk management measures are defined, implemented, assessed and documented. An ISO 27001 certificate, or a European certification covering a product or a service, can support that case, but it does not replace the demonstration itself.

Is ISO 27001 certification enough for NIS2?

No, but it covers a good part of the ground. A certified management system already delivers risk assessment, incident handling, business continuity and supplier oversight. What remains is what belongs to the directive: the reporting deadlines towards the authority, the formal accountability of management bodies and their training obligation, and above all the scope, which is that of your regulated activities and not only the one you chose to certify. The useful work is measuring that gap, not starting again.

What penalties apply if NIS2 obligations are breached?

The directive requires member states to provide for minimum ceilings: for an essential entity, at least ten million euros or 2% of worldwide annual turnover, whichever is higher; for an important entity, at least seven million euros or 1.4%. Fines are not the only lever. An authority can order corrective measures, make a breach public and, for essential entities only, temporarily suspend an authorisation or act on managerial responsibilities.

Are my suppliers covered by NIS2?

Not necessarily, and that is where the difficulty sits. The directive only binds the organisations within its scope, yet it makes you accountable for the security of your supply chain, including for providers that carry no direct obligation of their own. You are expected to assess the risk attached to each supplier, take the quality of their security practices into account and carry your requirements into the contracts. A supplier outside the scope is not a supplier outside the analysis.

Why use NIS2 software rather than a spreadsheet?

Because NIS2 compliance is demonstrated through links, not through a list. The authority wants to see which measure covers which requirement, which risk justifies it, which evidence supports it and when it was last reviewed. A spreadsheet loses those links as soon as a scope shifts or an owner changes role, and it keeps no history of the decisions taken. A platform maintains them, flags what has gone stale and produces the deliverables without re-keying. With Vailor, AI also cuts the time spent on risk assessments by 70%.

See Vailor's NIS2 software in action

Book a demo and see where you actually stand against the Article 21 measures.