Home › Frameworks › NIS2

NIS2 compliance software for essential and important entities.

NIS2 measures as recurring controls, an incident register with the 24-hour, 72-hour and one-month milestones, a significant-incident checker based on Implementing Regulation (EU) 2024/2690, supplier reviews and management-body approval tracking. EU-built, EU-hosted. Free for one framework; Basic from €29 a month.

Your sector and size

Annexes I and II of Directive (EU) 2022/2555, size per Commission Recommendation 2003/361/EC. Runs in your browser.

Article 21Cybersecurity risk-management measures: risk policy, incident handling, BCP, supply chain, vulnerability…
Article 23Incident notification: early warning within 24 hours, intermediate report within 72 hours, final report within…
Article 27Registration with the competent national authority, with the registration date and authority name on the…
Article 32-34Supervision and enforcement: evidence sampling and the activity log.

What is NIS2?

EU NIS2 Directive (Directive (EU) 2022/2555). Essential and important entities under NIS2: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, postal and courier, food, chemicals, manufacturing, research.

Who needs to comply

  • Energy and utilities (essential entity)
  • Banking, financial market infrastructure (essential entity)
  • Healthcare and drinking-water providers (essential entity)
  • Digital infrastructure and ICT service management (essential entity)
  • Manufacturing, food, chemicals, postal and research (important entity, depending on size)

Key NIS2 controls covered by Dazr

Article 21Cybersecurity risk-management measures: risk policy, incident handling, BCP, supply chain, vulnerability handling, cryptography, basic cyber hygiene, MFA.
Article 23Incident notification: early warning within 24 hours, intermediate report within 72 hours, final report within 1 month.
Article 27Registration with the competent national authority, with the registration date and authority name on the workspace profile.
Article 32-34Supervision and enforcement: evidence sampling and the activity log.

National transposition

As of 1 October 2026. NIS2 is a directive, so the duties you actually face come from your national law and authority.

Netherlands: CyberbeveiligingswetIn force since 15 August 2026, with the Cyberbeveiligingsbesluit (Stb. 2026, 189). Supervision is organised per sector. Valt mijn organisatie eronder?
Italy: D.Lgs. 138/2024In force since 16 October 2024. The Agenzia per la Cybersicurezza Nazionale (ACN) is the competent authority. Si applica alla mia azienda?
Belgium: NIS2 law of 26 April 2024In force since 18 October 2024. Entities register with the Centre for Cybersecurity Belgium (CCB).
Germany: NIS2UmsuCGIn force since 6 December 2025, amending the BSI Act. The BSI is the competent authority.

Implementing Regulation (EU) 2024/2690. For DNS service providers, TLD registries, cloud and data-centre providers, content delivery networks, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers, this Commission regulation spells out the technical and methodological requirements behind the Article 21 measures and when an incident counts as significant. See the 2024/2690 checklist and the significant-incident checker.

Sources: Directive (EU) 2022/2555, Implementing Regulation (EU) 2024/2690, Forvis Mazars on the Cbw, D.Lgs. 138/2024, CCB, NIS2UmsuCG.

What auditors look for

NIS2 specifically requires evidence of management body approval, supply-chain risk assessments, and the 24-hour early warning / 72-hour intermediate / 1-month final report incident notification cycle. Dazr holds the evidence for all three.

How Dazr helps with NIS2

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. NIS2 is one of its eleven frameworks, available from the free plan. In practice that means:

  • Maintain the Article 21 cybersecurity risk-management measures as recurring controls
  • Run the incident register with the 24h / 72h / 1-month notification timestamps and authority case references
  • Review suppliers in the vendor register with DPA and certificate links, review and expiry dates (Pro and Enterprise)
  • Hold the management body approval date on the compliance profile, refreshed annually
  • Hand the competent authority a single-PDF audit trail or a read-only view

Back to the full Dazr Compliance overview › | Sign up free ›

NIS2 questions, answered.

Are we essential or important?

It depends on sector and size. NIS2 lists the sectors in Annexes I and II; national laws set the details. The Italian, Belgian, German and Dutch transpositions are all in force; check your national authority. Dazr does not classify you, but the workspace records which classification applies. Try the free NIS2 scope checker at compliance.dazr.eu/tools/nis2-scope-checker.

Does Dazr file the 24-hour early warning for me?

No. The early warning, intermediate and final reports go through your competent authority's portal. Dazr holds the notification fields and timestamps for each stage, and the activity log shows who did what when.

What if we are also doing ISO 27001?

Enable both frameworks; Dazr creates separate but related controls. Article 21 measures share a lot with ISO 27001 Annex A, so the same evidence often serves both.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption. Italian entity.

Ready to start your NIS2 program?

Free for one user and one framework (ISO 27001, GDPR or NIS2). Basic €29/mo covers two of those for one user; Pro €99/mo covers five frameworks (from ISO 27001, GDPR, NIS2, NEN 7510, ISO 27701, ISO 22301 and SOC 2) for up to five users; Enterprise €499/mo adds all eleven. Self-serve via Mollie, prices excl. VAT. Custom is the only tier on a contract, priced on request.