Frameworks

NIS2 — EU Network & Information Security Directive

Europe's baseline cybersecurity law for essential sectors — with personal management liability.

Book a demo

NIS2 dramatically widens EU cybersecurity regulation: energy, transport, health, digital infrastructure, cloud providers, managed services, and more. It mandates risk-management measures, 24-hour incident early warnings, supply-chain security — and makes management personally liable for approving and overseeing compliance.

The measures and the teeth

Article 21's measures read like a GRC checklist: risk analysis, incident handling, continuity, supply-chain security, secure development, cryptography, access control, MFA. The teeth are new: fines up to 2% of global turnover for essential entities and explicit management accountability — boards can't delegate this away.

How Compriska helps

Compriska turns the Article 21 measures into owned, evidenced controls, runs incident workflows against NIS2's tight notification timeline, manages supplier security in vendor risk, and gives management the oversight dashboard the directive effectively requires them to have.

Frequently asked questions

Are non-EU companies in scope?

Yes, if you provide in-scope services within the EU — digital infrastructure and providers often qualify wherever headquartered, and member-state transpositions determine the details.

Other frameworks

Automate NIS2 with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo