Quanovio

Directive (EU) 2022/2555CIR (EU) 2024/2690 · Annex

What NIS2 requires, and which parts a system can evidence.

Article 21(2) of the directive names ten risk-management measures in prose. Commission Implementing Regulation (EU) 2024/2690 turns them into an Annex of thirteen numbered points with sub-requirements — the only EU-wide enumeration specific enough to measure against, and the one an assessor cites.

Who it binds

CIR (EU) 2024/2690 applies directly to DNS providers, TLD name registries, cloud, data centre and content delivery providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers. Other essential and important entities meet Article 21 through the national law that transposes it. In either case the numbered controls are the technical reading of Article 21, which is why they are used here.

The thirteen points

Against each one, what a monitoring system can honestly say. Six are documents and decisions rather than events, and are reported as open with the evidence an assessor will request.

PointRequirementEvidenced by
1Policy on the security of network and information systemsDocuments and decisions
2Risk management policyDocuments and decisions
3Incident handlingMeasurement
4Business continuity and crisis managementPartly measurable
5Supply chain securityDocuments and decisions
6Security in network and information systems acquisition, development and maintenanceMeasurement
7Policies and procedures to assess the effectiveness of cybersecurity risk-management measuresDocuments and decisions
8Basic cyber hygiene practices and security trainingPartly measurable
9CryptographyPartly measurable
10Human resources securityDocuments and decisions
11Access controlMeasurement
12Asset managementPartly measurable
13Environmental and physical securityDocuments and decisions

Approximately one third of the numbered controls are evidenced by measurement. A coverage claim that exceeds what a monitoring system can observe does not survive an assessment, so the remainder are reported as open rather than quietly counted as met.

ReportingArticle 23

The clock starts at awareness, not at detection.

A significant incident must be reported to the national CSIRT or competent authority in three stages. The deadlines run from the moment the entity becomes aware of the incident.

24 hours without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;
72 hours without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;
1 month a final report not later than one month after the submission of the incident notification under point (b), including the following:

Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 23(4)

Quanovio records first detection with its timestamp, which is what an assessor compares the filing against. Filing itself is a process you operate; no monitoring system can do it for you, and one that claims to is describing an alert.

Penalties

Essential entities €10,000,000 or 2%
4. Member States shall ensure that where they infringe Article 21 or 23, essential entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher.
Important entities €7,000,000 or 1.4%
5. Member States shall ensure that where they infringe Article 21 or 23, important entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 7 000 000 or of a maximum of at least 1,4 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the important entity belongs, whichever is higher.

Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 34(4) and (5)

Article 20(1)
1. Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.

ReferencesEUR-Lex · ENISA

Sources

Every figure, deadline and requirement title on this site is taken from the texts below. Where this site quotes, it quotes the official language version you are reading it in.

Which points can you currently evidence?

Describe your environment and you will receive a point-by-point statement, including the ones no system can measure for you.

See your coverage