Getting Started with NIS2
The NIS2 Directive (EU 2022/2555) expands EU cybersecurity obligations to a much wider range of sectors than the original NIS Directive. Member states were required to transpose NIS2 into national law by October 17, 2024. If you are an essential or important entity, you are now subject to enforceable cybersecurity requirements — including mandatory incident reporting and potential personal liability for management. Matproof maps NIS2 requirements to a set of controls, policies, and incident workflows so you can demonstrate compliance to your national competent authority (NCA).Activate NIS2 under Settings → Frameworks → NIS2. Your control set will be pre-populated and mapped to the 10 minimum security measures under Article 21.
Am I in Scope?
NIS2 distinguishes two tiers of entities:Essential Entities (EE)
Subject to proactive supervision and higher penalties (up to €10M or 2% of global annual turnover, whichever is higher):- Energy (electricity, oil, gas, hydrogen, district heating and cooling)
- Transport (air, rail, water, road)
- Banking (credit institutions)
- Financial market infrastructures
- Health (hospitals, laboratories, pharma manufacturers)
- Drinking water supply and distribution
- Wastewater collection, disposal, and treatment
- Digital infrastructure (DNS, TLDs, cloud computing services, data centres, CDNs, trust services, IXPs, electronic communications networks and services)
- ICT service management (MSPs, MSSPs)
- Public administration (central government)
- Space
Important Entities (IE)
Subject to reactive supervision (lower penalties — €7M or 1.4% of global annual turnover, whichever is higher):- Postal and courier services
- Waste management
- Chemicals manufacturing and distribution
- Food production and distribution
- Manufacturing (medical devices, computer/electronic products, electrical equipment, machinery, motor vehicles, other transport equipment)
- Digital providers (online marketplaces, search engines, social networks)
- Research
The 10 NIS2 Minimum Security Measures
Article 21 requires essential and important entities to implement these 10 measures:Management Accountability
NIS2 introduces management accountability with potential personal liability. Governing bodies:- Must approve cybersecurity risk management measures
- Are liable for infringements by the entity
- Must undergo cybersecurity training
- The scope of personal liability depends on national transposition of the Directive.
Recommended Implementation Plan
Incident Reporting Quick Reference
Use the Incidents module to track timeline, auto-generate draft notifications, and attach evidence to each report.
Key Differences from NIS1
If you were already compliant with the original NIS Directive:Next Steps
- Incidents — configuring NIS2-compliant incident classification and multi-stage reporting
- Vendor Risk — supply chain security assessments and monitoring
- People Module — employee training records and access management
- Risk Management — risk assessments proportionate to your sector