Frameworks
NIS2 — EU Network & Information Security Directive
Europe's baseline cybersecurity law for essential sectors — with personal management liability.
Book a demoNIS2 dramatically widens EU cybersecurity regulation: energy, transport, health, digital infrastructure, cloud providers, managed services, and more. It mandates risk-management measures, 24-hour incident early warnings, supply-chain security — and makes management personally liable for approving and overseeing compliance.
The measures and the teeth
Article 21's measures read like a GRC checklist: risk analysis, incident handling, continuity, supply-chain security, secure development, cryptography, access control, MFA. The teeth are new: fines up to 2% of global turnover for essential entities and explicit management accountability — boards can't delegate this away.
How Compriska helps
Compriska turns the Article 21 measures into owned, evidenced controls, runs incident workflows against NIS2's tight notification timeline, manages supplier security in vendor risk, and gives management the oversight dashboard the directive effectively requires them to have.
Frequently asked questions
Are non-EU companies in scope?
Yes, if you provide in-scope services within the EU — digital infrastructure and providers often qualify wherever headquartered, and member-state transpositions determine the details.
Other frameworks
Automate NIS2 with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo