secria.eu
Knowledge base

What does NIS2 require of your organisation?

Explained for those encountering it for the first time. Every acronym is explained where it appears.

Do you know whether you fall under it?

Start here. Three questions, no account, and you will know whether you are an essential entity, an important one, or whether you receive the requirements through your customers.

Do the free NIS2 check

The ten measures from the duty of care

Article 21, second paragraph of the directive lists them as a through j. This is what a dossier consists of, and what your customer's security questionnaire is based on.

  1. Risk analysis and information security policy (sub a)
    A documented assessment of what can go wrong, and the policy that responds to it. This is the foundation on which the other nine rest.
  2. Incident handling (sub b)
    How you notice something is wrong, who does what then, and how you document it. Also the question of who decides whether reporting is required.
  3. Business continuity and crisis management (sub c)
    Back-ups, recovery from an outage, and what happens if your most important system is down for a week. Including the recovery tested, not just described.
  4. Security in the supply chain (sub d)
    The security of your suppliers and service providers, insofar as it affects your own systems. This is the provision that causes your own customers to send you a questionnaire.
  5. Security in procurement, development and maintenance (sub e)
    How you factor security into buying or building systems, and how vulnerabilities are handled as soon as they become known.
  6. Assessment of effectiveness (sub f)
    Measuring whether what you have arranged actually works. Without this, a list of measures remains an intention.
  7. Basic hygiene and awareness (sub g)
    Updates, password policy, rights that are no broader than necessary — and people who know what to watch for. Training is attached to this.
  8. Cryptography and encryption (sub h)
    When data is encrypted, in transit and at rest, and under what agreements.
  9. Personnel security, access policies and management of company assets (sub i)
    Who has access to what, what happens when someone leaves the organization, and which devices and systems you actually have.
  10. Multi-factor authentication and secure communications (sub j)
    Two-step verification where it matters, and secure voice, video and text communications. Also emergency communications if normal channels fail.

When must you report?

Three moments, and none of them is "the duty to report within 24 hours" that is often referred to. This only applies if you are yourself subject to the law.

StepDeadlineWhat it contains
Early warning 24 hours An initial signal: something serious is happening, possibly malicious, possibly crossing a boundary. More does not need to be included yet.
Incident report 72 hours The initial assessment: severity, consequences and, if you have them, indications of how it happened.
Final report 1 month What it was, what the cause was, what measures were taken and what the cross-border consequences were.

The deadlines run from the moment you become aware of the incident. We prepare the texts; you submit them yourself, via your own regulator's portal.