NIS2 Directive
NIS2 replaced the 2016 NIS Directive and widened the sectors covered. It is a directive, not a regulation: it binds you through your member state’s transposing law rather than directly, and member states were required to transpose it by 17 October 2024. It applies to named sectors above a size threshold — not to businesses in general.
Does this apply to you?
Two tests must both be met: sector and size. If either fails, and you are not in one of the size-independent categories, you are very likely outside the directive. Most vendor pages skip this section, which is why most readers arrive believing NIS2 covers them.
You are likely in scope if
- Your organisation operates in a sector listed in Annex I — energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, or space.
- Or in a sector listed in Annex II — postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing (including medical devices, computers and electronics, machinery, motor vehicles), digital providers such as online marketplaces, search engines and social networking platforms, or research organisations.
- AND you meet the Article 2(1) size threshold: at least a medium-sized enterprise, meaning 50 or more employees, or annual turnover and annual balance sheet total both above €10 million.
- Or, regardless of size, you fall in one of the Article 2(2) categories: providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers, the sole provider in a member state of a service essential for societal or economic activity, or central public administration entities.
You are probably not in scope if
- You are below the size threshold — fewer than 50 employees and not above both €10 million figures — and you are not in an Article 2(2) size-independent category. Most small businesses land here, and the honest answer is that NIS2 does not apply to you.
- Your sector appears in neither Annex I nor Annex II, whatever your size.
- You supply an in-scope entity but are not yourself in a listed sector. Being in someone else’s supply chain does not put you in scope. Article 21(2)(d) makes supply-chain risk their obligation, and it reaches you through their contract and their questionnaire — which is a commercial requirement to answer, not a legal one under NIS2.
What the framework asks for.
Named as the framework names them, with its own references, so you can check this page against the source below.
Policies on risk analysis and information system security
The baseline governance requirement: a documented approach to analysing risk to network and information systems.
Incident handling
Detection, response, and the handling process itself — distinct from the reporting duties in Article 23.
Business continuity
Named in the directive as including backup management, disaster recovery, and crisis management.
Supply chain security
Security-related aspects of the relationship between the entity and its direct suppliers or service providers. This is the clause that reaches suppliers contractually.
Security in acquisition, development and maintenance
Covering network and information system acquisition, development and maintenance, including vulnerability handling and disclosure.
Policies and procedures to assess effectiveness
Assessing whether the cybersecurity risk-management measures actually work. This is an effectiveness-review duty, and it is frequently misread as part of (e).
Basic cyber hygiene practices and cybersecurity training
Both the hygiene practices and the training obligation sit in the same point.
Policies on the use of cryptography and, where appropriate, encryption
A policy requirement, qualified by appropriateness rather than mandating encryption everywhere.
Human resources security, access control policies and asset management
Three organisational strands in one point.
Multi-factor or continuous authentication, and secured communications
Use of MFA or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems.
Incident reporting deadlines
For significant incidents: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month, to the CSIRT or competent authority.
Management body accountability
Management bodies must approve the risk-management measures and oversee their implementation, and can be held liable for failing to do so. They are also required to follow training.
What Fortoxa puts against each requirement.
Fortoxa evidences six of the ten Article 21(2) measures in part, from server telemetry. The remaining four are organisational and appear below under what stays your job rather than as rows Fortoxa can fill.
NIS2 Directive — control register
Risk analysis and information system security policies
CalculatedIncident handling
LiveSecurity in acquisition, development and maintenance
StaleBasic cyber hygiene practices
LiveCryptography and encryption
LiveMulti-factor authentication
Not configured
What stays your job.
Fortoxa evidences what it can observe on the servers you install the agent on. Everything below is outside that, and the register marks it as not measured rather than as a pass.
21(2)(c) — business continuity
Backup management, disaster recovery and crisis management. Fortoxa does not run, hold or test your backups, and does not evidence that a restore has ever succeeded.
21(2)(d) — supply chain security
Supplier contracts, assurance activity and the security terms you impose downstream. These are commercial artifacts, not telemetry.
21(2)(f) — assessing effectiveness
Fortoxa records that a control check ran and what it returned. Judging whether your measures are effective overall, and changing them when they are not, is a review you own.
21(2)(i) — human resources security
Vetting, joiners and leavers processes, and asset management beyond the servers the agent runs on.
Article 23 — the reports themselves
Fortoxa’s incident timeline is evidence you can attach to a 24-hour early warning or a 72-hour notification. Judging whether an incident is “significant”, and filing with your CSIRT or competent authority, is yours and is time-bound.
Article 20 — management accountability
Approval and oversight by the management body, and the training obligation on it, sit with your directors. No monitoring product can discharge a personal accountability duty.
Check this page against the text.
Everything above is Fortoxa's reading of the framework. It is not the framework, and it is not advice about your obligations. The publishers below are authoritative; this page is not.
See what your own servers produce.
Install the agent on one server and the register builds itself from what it finds — including the requirements it cannot see.