NIS2 Compliance

NIS2 Directive compliance for EU startups and scaleups

NIS2 applies to your organisation. You have ten security measures to implement, 24-hour incident reporting timelines, and management accountability that is now personal liability. Complara maps every requirement into actionable checklists so nothing falls through the cracks.

10-day free trial · No credit card required · Setup in 3 minutes

What NIS2 requires from covered organizations

NIS2 mandates a risk-based approach to cybersecurity with ten minimum security measures, strict incident reporting timelines, and — for the first time — personal liability for management bodies. EU member states were required to transpose NIS2 into national law by October 2024.

Cybersecurity risk management

Policies on risk analysis and information system security, backed by a formal risk management process covering confidentiality, integrity, and availability.

Incident handling & reporting

Early warning to your national CSIRT within 24 hours, incident notification within 72 hours, and a final report within one month — including root cause and cross-border impact.

Supply chain security

Security policies for ICT suppliers and service providers, including assessments of supply chain risks and contractual security requirements.

Business continuity & backup

Backup management, disaster recovery, and crisis management procedures to ensure operational continuity following incidents.

Access control & MFA

Network access control, multi-factor authentication, and privileged access management across all critical systems.

Management accountability

Management bodies must approve, oversee, and take accountability for cybersecurity measures. Personal liability applies for non-compliance.

How Complara helps you track NIS2

NIS2 covers ten security measure categories. Complara maps each into specific, assignable tasks your team can track from gap assessment to ready-to-audit.

Gap assessment checklist

Import Complara's NIS2 checklist template and see instantly which of the ten security measure categories your organisation still needs to address.

Evidence collection

Attach risk registers, incident response plans, penetration test reports, and supplier security questionnaires to each requirement.

Board-level reporting

Generate a readiness report to present to your management body — satisfying the NIS2 requirement for executive oversight of your cybersecurity posture.

Multi-framework support

Map overlapping controls between NIS2, ISO 27001, and SOC 2 to avoid duplicate work when you're pursuing multiple frameworks.

Related compliance frameworks

NIS2 entities in financial services often also fall under DORA. Many use ISO 27001 as their underlying security framework to satisfy NIS2 requirements efficiently.

Frequently asked questions about NIS2

What is NIS2?

NIS2 (Network and Information Systems Directive 2) is the EU's updated cybersecurity framework that replaced the original NIS Directive in 2023. It expands coverage to more sectors, strengthens minimum security requirements, and introduces personal management liability for cybersecurity non-compliance.

Who does NIS2 apply to?

NIS2 applies to medium and large organizations in essential sectors (energy, transport, banking, health, digital infrastructure) and important sectors (postal, waste, chemicals, food, manufacturing, digital services). Generally: 50+ employees or €10M+ revenue in a covered sector.

What are the NIS2 incident reporting timelines?

Early warning within 24 hours → Incident notification within 72 hours → Final report within 1 month. All reports go to your national CSIRT or competent authority.

What are the ten NIS2 security measures?

Risk analysis · Incident handling · Business continuity and disaster recovery · Supply chain security · Procurement and vulnerability handling · Cyber hygiene and training · Cryptography · Human resources security and access control · Multi-factor authentication · Secure communications. Read the full NIS2 guide →

Start your NIS2 compliance journey today

All ten security measures. Plain-English tasks. Evidence storage and board-level reporting built in.