NIS2 is not one law. It is 27 of them.
The directive sets the shape. Your member state writes the law that actually binds you, picks the deadlines, names the regulator and decides which register you file with. That is why generic NIS2 tooling stops being useful right at the point it gets hard. We started with the Polish transposition, in Polish, and we will say plainly where that leaves everyone else.
AuditBadger is $250/month flat, no per-user fees. NIS2 support is early access and we switch it on after a conversation.
Essential, important, or genuinely out
NIS2 sorts in-scope organizations into two classes, mostly by sector and size. The class does not change the security measures much. It changes how closely you are supervised and what a regulator can do before something goes wrong rather than after.
Large, in a high-criticality sector
Generally large organizations in the Annex I sectors: energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration and space. Large usually means 250 staff or more, or turnover above 50 million euro.
- Proactive supervision, not only after an incident
- Audits and inspections a regulator can require
- Higher maximum penalties once your national law starts applying them
- Management bodies approve the measures and can be held personally responsible
Medium sized, or an Annex II sector
Medium organizations in Annex I sectors, plus medium and large organizations in Annex II: postal services, waste, chemicals, food, manufacturing, digital providers and research. Medium usually means 50 staff or more, or turnover above 10 million euro.
- The same measure areas under article 21
- Supervision that mostly kicks in after evidence of a problem
- Lower maximum penalties
- Still registered, still reporting incidents on the same clocks
Size is not the whole test. Some organizations are in scope no matter how small they are, including providers of public electronic communications networks and services, DNS service providers, TLD name registries and trust service providers. A one person internet provider is in scope. So is an organization that is the sole provider of a critical service in its country. Member states can also designate entities individually, and several have widened the sector list beyond the directive minimum. Check your own country's list before assuming you are out.
The EU dates are history. Yours are national
The directive's own milestones have passed. What is still ahead of you sits in your member state's law, which is where the deadlines diverge. Below: the EU timeline, and then Poland as a worked example, because that is the transposition we built for first.
-
The directive entered into force
Directive (EU) 2022/2555 replaced the original NIS directive, widened the sectors substantially and added management accountability.
-
Transposition deadline
Member states were supposed to have national law in place. A lot of them did not make it, which is exactly why the useful question is what your country passed, and when.
-
National entity lists
Member states had to establish their lists of essential and important entities. In practice this is where many organizations first learned they were in scope.
-
Poland: the amending act took effect
The Polish transposition arrived through the act on the national cybersecurity system, published as Dz.U. 2026 poz. 252. Every Polish deadline below counts from here.
-
Poland: security management system in place
The information security management system and the operational duties around it, plus mandatory incident reporting through the national S46 system.
-
Poland: first audits, and penalties become available
First audits for essential entities, then at least every three years. The same date ends the moratorium on the new penalties. We mention it because runway is worth knowing about, not because a deadline is a sales argument.
The framework catalog, evidence collection and document generation work the same way for any national transposition, because article 21 is the common shape. What we do not have yet is your country's specific classification rules, registration duties and reporting routing modelled as data, the way we did for Poland. Tell us which country you need and it goes into the queue with a real answer about timing, not a maybe.
What article 21 actually asks for
Ten measure areas, plus the reporting duties that sit next to them. It reads like a shorter, blunter ISO 27001, which is not a coincidence and turns out to be good news if you have done ISO work already.
Risk analysis and security policies
A documented approach to risk, and information system security policies that follow from it rather than from a template.
Incident handling
Detection, response, records, and the process that produces a report a regulator will accept.
Continuity and crisis management
Business continuity, backup management, disaster recovery, and who decides what during a bad week.
Supply chain security
Security in your direct supplier relationships, including the specific vulnerabilities of each supplier.
Secure acquisition and development
Security across acquisition, development and maintenance, including vulnerability handling and disclosure.
Measuring effectiveness
Policies and procedures to assess whether your risk management measures actually work. This is the one most programs skip.
Cyber hygiene and training
Basic practices and security awareness training, for everyone rather than for the security team.
Cryptography
Policies on cryptography and, where appropriate, encryption. Written down, not assumed.
HR security, access control, assets
Human resources security, access control policies, and knowing what you actually own.
MFA and secured communications
Multi factor or continuous authentication, secured voice, video and text, and secured emergency communications.
The reporting clocks
Early warning within 24 hours of becoming aware, incident notification within 72 hours, and a final report within one month.
Management accountability
Management bodies approve the risk measures, oversee implementation, can be held responsible, and are required to follow training themselves.
If you have done ISO 27001, most of this is filing
Article 21 is ISO 27001 shaped. Not identical, and definitely not a free pass, but the overlap is large enough that the honest job is mapping and gap filling rather than starting again.
- Risk assessment, risk register and treatment plan
- Policies, training records and access reviews you already keep
- Backups, MFA, asset inventory and vulnerability handling, with evidence pulled from your stack
- Supplier reviews, if you are already running vendor assessments
- In AuditBadger, 25 shared subcontrols count under SOC 2, ISO 27001 and NIS2 at the same time
- Registration with your national authority, and keeping those details current
- Incident reporting on statutory clocks, through your country's system, not by email
- Notifying affected users about significant incidents and serious threats
- Management body approval and management training as a named, documented duty
- Whatever your member state added on top, which is the part nobody can guess for you
An ISO 27001 certificate does not automatically satisfy NIS2, and in Poland specifically there is no presumption of conformity in the enacted law, despite a lot of pages online saying otherwise. Treat ISO as an accelerator that removes most of the work, not as an exemption. Our ISO to NIS2 coverage view is our own mapping and the product labels it that way.
Honest scope, stated up front
We would rather lose a fit we cannot serve than win one and explain later. So here is exactly what exists, and the next section is what does not.
A NIS2 control catalog, not a PDF pack
The measure areas broken into controls with owners, evidence and status, so the program is a live thing rather than a folder someone updates before an audit.
The Polish transposition, in Polish
Thirty measures across ten areas, 75 broken out subpoints, each carrying its article reference, authored from the Polish statute rather than translated from English. Plus classification, the obligations calendar and a Polish document wizard.
Evidence from the systems you already run
Over 120 automated checks across 12 integrations feed the measures: MFA posture, backups, encryption, logging, device posture, training completions. Checks run monthly and whenever you press the button. Scheduled checks, not continuous monitoring.
Policies drafted, then reviewed by you
AI writes the first version from answers about your actual setup. You edit and approve. Every change needs your confirmation and lands in the audit trail, because a policy nobody read is worse than no policy.
See your ISO 27001 work against NIS2
Run an ISO project alongside and the coverage view grades each NIS2 measure covered, partial or not covered, so the gap list is short and specific.
Incidents, training, vendors, assets
An incident register with an anonymous tokenized reporting portal, a training LMS built from your own policies, vendor assessments through a portal that needs no vendor account, and an asset register. One tool, one price.
NIS2 support is not switched on for every account yet, and the statutory parameters we encoded are still going through legal review. We enable it for design partners after a conversation. If you are in scope and want to shape how this works, now is the useful moment. If you need a finished, certified NIS2 product this quarter, we are not that yet and we would rather you heard it here.
The lines we do not cross
Most vendors keep this part vague. Ours is in writing, before you spend anything.
We do not file your reports
Regulatory notifications are submitted by you, through your country's system. We help draft the content, track the deadlines and keep the record. We do not press send on your behalf.
We are not a law firm
None of this is legal advice. Article references come from the published texts and we label them that way. Where it matters, get a lawyer. We do.
Poland first, other countries honestly
The Polish transposition is modelled properly, down to classification rules and statutory deadlines. Other member states get the common article 21 shape today. Ask us about yours and you will get a real answer about timing.
We do not call our checks continuous
They run monthly, plus whenever you trigger them. Your auditor will ask what continuous means, so we say it plainly first.
We do not audit you
Audits are done by qualified auditors and conformity assessment bodies. We prepare you and export the registers. If the same company prepared and graded you, the result would be worth nothing.
Some thresholds do not exist yet
In Poland the regulation setting numeric significant incident thresholds has not been issued, so classification rests on the statutory definition. The product says so, rather than inventing a number that looks reassuring.
The ones we actually get asked
Does NIS2 apply to my company?
It depends on your sector, your size and your country. Broadly: large organizations in the Annex I sectors are essential entities, medium organizations there and medium or large ones in Annex II are important entities. Some organizations are in scope at any size, including providers of public electronic communications networks and services, DNS providers, TLD registries and trust service providers. Your member state publishes the list that actually decides it.
Does ISO 27001 make us NIS2 compliant?
No, but it does most of the heavy lifting. Article 21 is ISO 27001 shaped, so risk management, policies, access control, backups, supplier reviews and training mostly carry over. What does not carry over is registration, statutory incident reporting, user notification and management body duties. In Poland there is specifically no presumption of conformity in the enacted law, despite what several sites claim.
How fast do we have to report an incident?
Early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month, under article 23. Your member state decides the channel, the forms and who receives them, which is the part that varies most.
Can directors really be held personally responsible?
Article 20 puts approval of the risk management measures and oversight of their implementation on management bodies, and requires them to follow training. Several member states, Poland included, attached personal consequences to that. It is one of the few compliance duties you cannot delegate away.
Which countries do you support today?
Poland properly, in Polish, including classification and the statutory obligations calendar. Everywhere else you get the common article 21 catalog, evidence collection and document generation, without your national specifics modelled as data yet. We would rather say that than imply full coverage.
What does it cost?
$250 per month, flat, with no per-user fees and no usage limits. The same price covers SOC 2, ISO 27001 and NIS2. NIS2 support is early access, so we switch it on after a short conversation.
Start from what you already have
We will walk you through the catalog, the dates that apply to you, and how much of your existing work attaches as evidence on day one. The call is with a founder, not a sales team.
No long term contracts. The call is not legal advice.