Skip to main content

NIS2 Compliance with Gover

The NIS2 Directive strengthens cybersecurity requirements across the EU.

Overview

AttributeValue
Full NameNetwork and Information Security Directive 2
JurisdictionEuropean Union
Effective DateOctober 2024 (transposition deadline)
Applies ToEssential and important entities

Scope

Essential Entities

  • Energy
  • Transport
  • Banking
  • Health
  • Digital infrastructure
  • Public administration

Important Entities

  • Postal services
  • Waste management
  • Manufacturing
  • Digital providers
  • Research

Key Requirements

Risk Management (Article 21)

  • Risk analysis and security policies
  • Incident handling
  • Business continuity
  • Supply chain security
  • Security in acquisition
  • Vulnerability handling
  • Cybersecurity assessment
  • Cryptography and encryption
  • Human resources security
  • Access control

Incident Reporting (Article 23)

  • Early warning within 24 hours
  • Incident notification within 72 hours
  • Final report within one month

Governance

  • Management body approval
  • Cybersecurity training
  • Personal accountability

Using Gover for NIS2

1. Add the NIS2 Framework

  1. Go to FrameworksAdd Framework
  2. Select NIS2 from templates
  3. Add to your workspace

2. Assess Your Scope

Determine if you're an essential or important entity based on:

  • Sector
  • Size
  • Criticality

3. Map Controls to Requirements

Map your security controls to NIS2 Article 21 requirements:

  • Risk management policies
  • Incident response procedures
  • Business continuity plans
  • Supply chain security measures

4. Implement Reporting

Ensure you can meet reporting timelines:

  • 24-hour early warning capability
  • 72-hour notification process
  • Final report procedures
NIS2 AreaRecommended Controls
Risk ManagementRisk Assessment Process, Security Policy
Incident HandlingIncident Response Plan, SIEM
Business ContinuityBCP, Disaster Recovery
Supply ChainVendor Assessment, Third-party Risk
Access ControlIAM, MFA, Privileged Access
CryptographyEncryption Policy, Key Management

Penalties

NIS2 introduces significant penalties:

  • Essential entities: Up to €10M or 2% of global turnover
  • Important entities: Up to €7M or 1.4% of global turnover

Resources

Next Steps