Solution · NIS2

NIS2, start to finish.

CloudSoul tells you whether you are in scope, maps every obligation the directive sets, ranks the gaps worst first, and gives you the tooling to close them.

Check your scope
Scope

Are you in scope?

Essential entities

Large operators in the eleven Annex I sectors classified as highly critical: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Proactive supervision. Full fine bracket.

EnergyTransportBankingFinancial market infraHealthDrinking waterWastewaterDigital infraICT servicesPublic adminSpace

Important entities

Medium and large entities in other critical sectors: postal, waste management, chemicals, food, manufacturing of critical products, digital providers, research.

Reactive supervision. Reduced fine bracket.

PostalWaste mgmtChemicalsFoodManufacturingDigital providersResearch

Most mid-market EU operators with over 50 employees in a covered sector will be in scope, as either essential or important. The specific classification turns on sector, size, turnover, and whether you operate critical infrastructure.

Check your scope →

Obligations

The measures you must implement.

The directive demands risk-management measures (Article 21), board-level accountability (Article 20), and rapid incident reporting (Article 23). CloudSoul maps every line to a control, and shows you which ones are still open.

Art. Measure What the directive says (plain English) How CloudSoul covers it
21(a) Risk analysis & security policies Establish written policies covering risk analysis and information system security. Risk and Compliance ships policy templates already mapped to NIS2 articles. Your risk register is built from your business profile and updates as that profile changes.
21(b) Incident handling Detect, classify, contain, recover from, and learn from cybersecurity incidents. SIEM and EDR signals are ingested continuously and triaged against your business context, your IT estate and the risks already on your register. Findings reach the person you designate, prioritised, with a recommended action. Post-incident report and lessons learned land in the evidence engine.
21(c) Business continuity & crisis management Maintain backups, test recovery, and have a crisis-management plan. Backups are checked continuously against your recovery point objectives, and drift surfaces as a finding. BCP/DRP plans are version-controlled, with test dates and results tracked as evidence.
21(d) Supply chain security Assess and monitor security risks from suppliers and direct service providers. Vendor register and assessment workflow, with every supplier in your dependency graph tracked against your risk register. Continuous supplier posture monitoring and supply-chain incident alerts.
21(e) Secure acquisition, development & maintenance Build security into procurement, development, and ongoing maintenance, including vulnerability handling and disclosure. Continuous vulnerability scanning, patch oversight, and cloud posture tracking (CSPM). Findings flow into the gap list automatically, prioritised, with a recommended action.
21(f) Effectiveness assessment Have policies and procedures to assess whether your cybersecurity measures actually work. Recurring control testing, KPI dashboards, and audit-ready evidence reports. As the company grows, the record keeps describing what you actually run.
21(g) Cyber hygiene & training Train staff in basic cybersecurity practices, including phishing awareness. Training tracking and attestation records, from staff awareness to board-level NIS2 training. Completion records land in the evidence engine automatically.
21(h) Cryptography & encryption Use cryptography appropriately, including encryption where applicable. Continuous encryption posture checks (in-transit, at-rest), key rotation tracking, certificate inventory with expiry dates. Gaps surface as risks.
21(i) HR security, access control & asset management Background checks, role-based access control, and a complete asset inventory. Continuous IAM checks, joiner/mover/leaver workflows, asset discovery and inventory tracking against your IT profile.
21(j) MFA & secured communications Use multi-factor authentication and secured voice / video / text where appropriate. MFA coverage scanning across your IT estate, secure-comms inventory, gap reporting. Recommendations surface in the gap list.
20 Management accountability Boards approve cybersecurity risk-management measures and oversee how they are carried out. Members face personal liability for non-compliance. Board pack auto-generated from the gap list: risk posture, control coverage, residual risk, decisions log. Sign-off captured in the evidence engine.
23 Incident reporting (24h / 72h / 1 month) Report significant incidents in three stages: early warning within 24 hours, full notification within 72 hours, final report within 1 month. The platform proposes a significance classification for you to confirm. Incident detail is aggregated into submission-ready, member-state-specific templates, with the 24h, 72h and one-month deadlines tracked and flagged to you before each one falls due. You submit to your CSIRT; the full trail is captured in the evidence engine.

Read the directive on the European Commission site →

Article 23 reporting

Three clocks you cannot miss.

CloudSoul tracks the deadlines and aggregates the incident data as it arrives.

T + 0

Incident detected

Clocks start. Evidence collection begins.

T + 24h

Early warning

To CSIRT / competent authority. Initial description only.

T + 72h

Full notification

Impact, indicators, severity, mitigation applied.

T + 1 month

Final report

Lessons learned, remediation, residual risk.

Enforcement

The cost of non-compliance.

€10M or 2%

Maximum fine for essential entities, whichever of the two is higher. The percentage is taken on global annual turnover.

€7M or 1.4%

Maximum fine for important entities.

Personal liability

Management bodies can be held personally liable when the measures are not in place.

ISO 27001 overlap

Already ISO 27001 certified? You’re close, not done.

ISO 27001 gives you most of the ten measures.

Article 21 measures overlap heavily with ISO 27001 Annex A controls. If ISO 27001 is live in your business, you likely already satisfy most of the NIS2 technical requirements. CloudSoul maps what you have, and shows you the remainder in priority order.

NIS2 adds four gaps ISO 27001 does not close.

Personal management liability (Art. 20). The 24h/72h/1-month reporting workflow (Art. 23). Supply-chain security depth (Art. 21(d)). Jurisdictional reporting: each member state has its own CSIRT and its own submission format.

FAQ

Questions.

Is my organisation in scope for NIS2?

Two tests apply. First, you operate in one of the 18 critical sectors listed in Annexes I and II. Second, you have at least 50 employees or €10M annual turnover. Meet both and you are likely in scope, as either an essential or an important entity. Some digital infrastructure providers are in scope regardless of size.

What is the difference between essential and important entities?

Essential entities (Annex I, e.g. energy, transport, healthcare) face proactive supervision and the higher fine bracket: up to €10M or 2% of global turnover. Important entities (Annex II, e.g. postal, food, manufacturing) face reactive supervision and a reduced bracket: up to €7M or 1.4%.

How quickly do I have to report an incident?

Article 23 imposes three deadlines: an early warning within 24 hours of awareness, a full notification within 72 hours, and a final report within 1 month. CloudSoul aggregates the incident detail, suggests a significance classification for you to confirm, formats the member-state submission, tracks every deadline and notifies you before it falls due. You submit to your competent authority.

We already have ISO 27001. Does that cover NIS2?

ISO 27001 covers most of the NIS2 Article 21 technical requirements. The four remaining gaps are: personal liability of management (Art. 20), the 24h/72h/1-month reporting workflow (Art. 23), supply-chain oversight depth (Art. 21(d)), and per-member-state CSIRT reporting formats.

What are the fines for NIS2 non-compliance?

Up to €10 million or 2% of global annual turnover (whichever is higher) for essential entities; up to €7 million or 1.4% for important entities. Member states can also suspend certifications and impose temporary management bans.

Do we need to run NIS2 tooling in our own environment?

There is no stack for you to host. Everything runs from the platform, on EU-owned infrastructure, and adapts to your estate automatically. Endpoint detection is the one exception: it needs an agent on the machines you want covered.

When does NIS2 enforcement actually begin?

The EU deadline was October 2024, but most countries ran late: national laws have been landing through 2024 to 2026. Once yours is in force, enforcement sits with your national authority, typically the CSIRT or a sector regulator.

How quickly can we get started?

Risk and Compliance runs from day one. You build the profile, the gap list comes back in priority order, and there is no project to run first: nothing to host, nothing to configure. The security tooling is already in the platform and switches on when the gap list calls for it.

NIS2 is not a checklist. It is an operational programme.
Check your scope