Skip to main content

NIS2 Compliance with Gover

The NIS2 Directive strengthens cybersecurity requirements across the EU.

Overview

AttributeValue
Full NameNetwork and Information Security Directive 2
JurisdictionEuropean Union
Effective DateOctober 2024 (transition period ended)
Applies ToEssential and important entities

Scope

Essential Entities

  • Energy
  • Transport
  • Banking
  • Health
  • Digital infrastructure
  • Public administration

Important Entities

  • Postal services
  • Waste management
  • Manufacturing
  • Digital providers
  • Research

Key Requirements

Risk Management (Article 21)

  • Risk analysis and security policies
  • Incident handling
  • Business continuity
  • Supply chain security
  • Security in acquisition
  • Vulnerability handling
  • Cybersecurity assessment
  • Cryptography and encryption
  • Human resources security
  • Access control

Incident Reporting (Article 23)

  • Early warning within 24 hours
  • Incident notification within 72 hours
  • Final report within one month

Governance

  • Management approval
  • Cybersecurity training
  • Personal accountability

Using Gover for NIS2

1. Add the NIS2 Framework

  1. Go to FrameworksAdd Framework
  2. Select NIS2 from templates
  3. Add to your workspace

2. Assess Your Scope

Determine if you're an essential or important entity based on:

  • Sector
  • Size
  • Criticality

3. Map Controls to Requirements

Map your security controls to NIS2 Article 21 requirements:

  • Risk management policies
  • Incident management processes
  • Business continuity plans
  • Supply chain security measures

4. Implement Reporting

Ensure you can meet reporting timelines:

  • 24h early warning capability
  • 72h notification process
  • Final reporting procedures
NIS2 AreaRecommended Controls
Risk ManagementRisk assessment process, Information security policy
Incident HandlingIncident response plan, SIEM
Business ContinuityBCP, Disaster Recovery plan
Supply ChainVendor assessment, Third-party risk
Access ControlIAM, MFA, Privileged Access
CryptographyEncryption policy, Key management

Penalties

NIS2 introduces significant penalties:

  • Essential entities: Up to €10M or 2% of global turnover
  • Important entities: Up to €7M or 1.4% of global turnover

Resources

Next Steps