> ## Documentation Index
> Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with NIS2

> A practical guide to meeting NIS2 obligations for essential and important entities using Matproof.

# Getting Started with NIS2

The NIS2 Directive (EU 2022/2555) expands EU cybersecurity obligations to a much wider range of sectors than the original NIS Directive. Member states were required to transpose NIS2 into national law by **October 17, 2024**. If you are an **essential** or **important entity**, you are now subject to enforceable cybersecurity requirements — including mandatory incident reporting and potential personal liability for management.

Matproof maps NIS2 requirements to a set of controls, policies, and incident workflows so you can demonstrate compliance to your national competent authority (NCA).

<Note>
  Activate NIS2 under **Settings → Frameworks → NIS2**. Your control set will be pre-populated and mapped to the 10 minimum security measures under Article 21.
</Note>

***

## Am I in Scope?

NIS2 distinguishes two tiers of entities:

### Essential Entities (EE)

Subject to proactive supervision and higher penalties (up to €10M or 2% of global annual turnover, whichever is higher):

* Energy (electricity, oil, gas, hydrogen, district heating and cooling)
* Transport (air, rail, water, road)
* Banking (credit institutions)
* Financial market infrastructures
* Health (hospitals, laboratories, pharma manufacturers)
* Drinking water supply and distribution
* Wastewater collection, disposal, and treatment
* Digital infrastructure (DNS, TLDs, cloud computing services, data centres, CDNs, trust services, IXPs, electronic communications networks and services)
* ICT service management (MSPs, MSSPs)
* Public administration (central government)
* Space

### Important Entities (IE)

Subject to reactive supervision (lower penalties — €7M or 1.4% of global annual turnover, whichever is higher):

* Postal and courier services
* Waste management
* Chemicals manufacturing and distribution
* Food production and distribution
* Manufacturing (medical devices, computer/electronic products, electrical equipment, machinery, motor vehicles, other transport equipment)
* Digital providers (online marketplaces, search engines, social networks)
* Research

<Tip>
  Size thresholds apply: medium enterprises (50+ employees or €10M+ turnover) or large enterprises (250+ employees or €50M+ turnover) in these sectors are in scope. Smaller entities may be in scope if they are sole providers of critical services. Note: medium-sized entities in Annex I sectors are generally classified as Important entities, while large entities (250+ employees) in Annex I sectors are classified as Essential entities.
</Tip>

***

## The 10 NIS2 Minimum Security Measures

Article 21 requires essential and important entities to implement these 10 measures:

| #  | Measure                                                                                                                                             | Matproof Module           |
| -- | --------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------- |
| 1  | Policies on risk analysis and information system security                                                                                           | Policies, Risk Management |
| 2  | Incident handling                                                                                                                                   | Incidents                 |
| 3  | Business continuity (BCP, DR, crisis management)                                                                                                    | Policies, Controls        |
| 4  | Supply chain security (ICT product/service security)                                                                                                | Vendor Risk               |
| 5  | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure               | Controls                  |
| 6  | Policies to assess effectiveness of cybersecurity measures                                                                                          | Audit Programs            |
| 7  | Basic cyber hygiene practices and cybersecurity training                                                                                            | People, Policies          |
| 8  | Policies and procedures on cryptography and encryption                                                                                              | Policies, Controls        |
| 9  | Human resources security, access control policies, asset management                                                                                 | People, Controls          |
| 10 | Multi-factor authentication or continuous authentication, secured voice, video and text communications, and secured emergency communication systems | Controls, Evidence        |

***

## Management Accountability

NIS2 introduces **management accountability with potential personal liability**. Governing bodies:

* Must approve cybersecurity risk management measures
* Are liable for infringements by the entity
* Must undergo cybersecurity training
* The scope of personal liability depends on national transposition of the Directive.

<Warning>
  Document management sign-off on your NIS2 risk management measures and policies. Matproof tracks policy approvals with timestamps — this is your evidence that management has approved and reviewed the program.
</Warning>

***

## Recommended Implementation Plan

<Steps>
  ### Step 1 — Determine your entity classification and NCA

  Identify whether you are an **essential entity** or **important entity** based on your sector and size. Register with your national competent authority (NCA) — most member states require self-registration. Check your national NIS2 transposition law for deadlines and registration requirements.

  Document your entity classification in **Settings → Organization**.

  ### Step 2 — Conduct a risk assessment

  NIS2 Article 21(1) requires risk management measures proportionate to the risks. Start with a formal risk assessment:

  1. Go to **Risk Management → New Risk Assessment**
  2. Assess risks to your network and information systems
  3. Include supply chain risks (ICT vendors and service providers)
  4. Score each risk and assign treatment plans
  5. Document your risk acceptance criteria

  The risk assessment is the foundation for the policies you generate next.

  ### Step 3 — Generate NIS2 policies

  Go to **Policies → Generate** and generate the NIS2 policy set. Key policies to prioritize:

  * Information Security Policy
  * Incident Response Policy
  * Business Continuity and Disaster Recovery Policy
  * Supply Chain Security Policy
  * Cryptography and Encryption Policy
  * Access Control Policy
  * Cybersecurity Training Policy

  Assign each policy to a member of the **management body** as owner — this documents management accountability.

  ### Step 4 — Configure the Incidents module

  NIS2 incident reporting requirements are strict:

  | Report Type           | Deadline                                                  | Recipient             |
  | --------------------- | --------------------------------------------------------- | --------------------- |
  | Early warning         | **24 hours** after becoming aware of significant incident | National CSIRT or NCA |
  | Incident notification | **72 hours**                                              | National CSIRT or NCA |
  | Final report          | **1 month** after incident notification                   | National CSIRT or NCA |

  If the incident is still ongoing when the final report is due, submit a progress report instead, then a final report within one month of handling the incident.

  1. Go to **Incidents → Settings** and configure your NIS2 incident classification criteria
  2. Define what constitutes a "significant incident" for your sector
  3. Set up escalation workflows so the right people are alerted within 24 hours
  4. Document your CSIRT/NCA contact details

  <Warning>
    The 24-hour early warning obligation is stricter than most other frameworks. Do not wait for full investigation — the early warning only requires that you are aware of the incident and its basic nature.
  </Warning>

  ### Step 5 — Map and assess your supply chain

  NIS2 Article 21(2)(d) specifically requires supply chain security. This is one of the most operationally demanding requirements.

  1. Go to **Vendor Risk** and import or add all ICT vendors and service providers
  2. Classify each vendor by criticality to your network and information systems
  3. Send a **NIS2 Supplier Assessment** to critical vendors
  4. Review vendors' own security practices and policies
  5. Document exit plans for critical single-source providers

  ### Step 6 — Complete Article 21 controls

  Work through the NIS2 control set in **Controls → NIS2**:

  * For each of the 10 minimum measures, link the relevant policies and evidence
  * Controls for human resources (Measure 9) should link to records in the **People** module
  * Controls for MFA and access (Measure 10) should be backed by integration evidence from your identity provider

  ### Step 7 — Cybersecurity training

  NIS2 requires cybersecurity awareness training for all staff and specialized training for management.

  1. Go to **People → Training**
  2. Assign cybersecurity awareness training to all employees
  3. Assign a management-level cybersecurity briefing to your governing body
  4. Track completion and link records as evidence against the relevant control

  ### Step 8 — Audit and ongoing monitoring

  1. Go to **Audit Programs → New Audit → NIS2**
  2. Run an internal audit against the 10 measures
  3. Document findings as Corrective Actions
  4. Set a recurring schedule — annual audit is the minimum for most entities
</Steps>

***

## Incident Reporting Quick Reference

| Trigger                       | Timeline  | Action                                                                                                                                                                                                                        |
| ----------------------------- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Significant incident detected | T+0       | Classify the incident, initiate internal escalation                                                                                                                                                                           |
| Within 24 hours               | T+24h     | Send early warning to NCA/CSIRT (whether suspected unlawful/malicious cause, whether cross-border impact possible)                                                                                                            |
| Within 72 hours               | T+72h     | Send incident notification (updated assessment, indicators of compromise)                                                                                                                                                     |
| Within 1 month                | T+1 month | Send final report (root cause, remediation, lessons learned). If the incident is still ongoing when the final report is due, submit a progress report instead, then a final report within one month of handling the incident. |

Use the **Incidents module** to track timeline, auto-generate draft notifications, and attach evidence to each report.

***

## Key Differences from NIS1

If you were already compliant with the original NIS Directive:

| Area                  | NIS1                  | NIS2                                 |
| --------------------- | --------------------- | ------------------------------------ |
| Scope                 | 7 sectors             | 18 sectors                           |
| Notification deadline | "Without undue delay" | 24h early warning + 72h notification |
| Management liability  | No                    | Yes — personal liability             |
| Supply chain          | Recommended           | Mandatory measure                    |
| Penalty               | National law          | Up to €10M/2% global turnover        |
| Enforcement           | Reactive              | Proactive for essential entities     |

***

## Next Steps

* [Incidents](/features/incidents) — configuring NIS2-compliant incident classification and multi-stage reporting
* [Vendor Risk](/features/vendor-risk) — supply chain security assessments and monitoring
* [People Module](/features/people) — employee training records and access management
* [Risk Management](/features/risk-management) — risk assessments proportionate to your sector
