What is NIS2?
EU NIS2 Directive (Directive (EU) 2022/2555). Essential and important entities under NIS2: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, postal and courier, food, chemicals, manufacturing, research.
Who needs to comply
- Energy and utilities (essential entity)
- Banking, financial market infrastructure (essential entity)
- Healthcare and drinking-water providers (essential entity)
- Digital infrastructure and ICT service management (essential entity)
- Manufacturing, food, chemicals, postal and research (important entity, depending on size)
Key NIS2 controls covered by Dazr
National transposition
As of 1 October 2026. NIS2 is a directive, so the duties you actually face come from your national law and authority.
Implementing Regulation (EU) 2024/2690. For DNS service providers, TLD registries, cloud and data-centre providers, content delivery networks, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers, this Commission regulation spells out the technical and methodological requirements behind the Article 21 measures and when an incident counts as significant. See the 2024/2690 checklist and the significant-incident checker.
Sources: Directive (EU) 2022/2555, Implementing Regulation (EU) 2024/2690, Forvis Mazars on the Cbw, D.Lgs. 138/2024, CCB, NIS2UmsuCG.
What auditors look for
NIS2 specifically requires evidence of management body approval, supply-chain risk assessments, and the 24-hour early warning / 72-hour intermediate / 1-month final report incident notification cycle. Dazr holds the evidence for all three.
How Dazr helps with NIS2
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. NIS2 is one of its eleven frameworks, available from the free plan. In practice that means:
- Maintain the Article 21 cybersecurity risk-management measures as recurring controls
- Run the incident register with the 24h / 72h / 1-month notification timestamps and authority case references
- Review suppliers in the vendor register with DPA and certificate links, review and expiry dates (Pro and Enterprise)
- Hold the management body approval date on the compliance profile, refreshed annually
- Hand the competent authority a single-PDF audit trail or a read-only view
Back to the full Dazr Compliance overview › | Sign up free ›