NIS2

NIS2 is not one law. It is 27 of them.

The directive sets the shape. Your member state writes the law that actually binds you, picks the deadlines, names the regulator and decides which register you file with. That is why generic NIS2 tooling stops being useful right at the point it gets hard. We started with the Polish transposition, in Polish, and we will say plainly where that leaves everyone else.

See ISO 27001
Ten measure areas, mapped to controls Evidence pulled from your stack Poland supported first, in Polish

AuditBadger is $250/month flat, no per-user fees. NIS2 support is early access and we switch it on after a conversation.

01 / Who it catches

Essential, important, or genuinely out

NIS2 sorts in-scope organizations into two classes, mostly by sector and size. The class does not change the security measures much. It changes how closely you are supervised and what a regulator can do before something goes wrong rather than after.

Essential entities

Large, in a high-criticality sector

Generally large organizations in the Annex I sectors: energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration and space. Large usually means 250 staff or more, or turnover above 50 million euro.

  • Proactive supervision, not only after an incident
  • Audits and inspections a regulator can require
  • Higher maximum penalties once your national law starts applying them
  • Management bodies approve the measures and can be held personally responsible
Important entities

Medium sized, or an Annex II sector

Medium organizations in Annex I sectors, plus medium and large organizations in Annex II: postal services, waste, chemicals, food, manufacturing, digital providers and research. Medium usually means 50 staff or more, or turnover above 10 million euro.

  • The same measure areas under article 21
  • Supervision that mostly kicks in after evidence of a problem
  • Lower maximum penalties
  • Still registered, still reporting incidents on the same clocks
The exceptions that catch people out

Size is not the whole test. Some organizations are in scope no matter how small they are, including providers of public electronic communications networks and services, DNS service providers, TLD name registries and trust service providers. A one person internet provider is in scope. So is an organization that is the sole provider of a critical service in its country. Member states can also designate entities individually, and several have widened the sector list beyond the directive minimum. Check your own country's list before assuming you are out.

02 / Dates

The EU dates are history. Yours are national

The directive's own milestones have passed. What is still ahead of you sits in your member state's law, which is where the deadlines diverge. Below: the EU timeline, and then Poland as a worked example, because that is the transposition we built for first.

  • The directive entered into force

    Directive (EU) 2022/2555 replaced the original NIS directive, widened the sectors substantially and added management accountability.

  • Transposition deadline

    Member states were supposed to have national law in place. A lot of them did not make it, which is exactly why the useful question is what your country passed, and when.

  • National entity lists

    Member states had to establish their lists of essential and important entities. In practice this is where many organizations first learned they were in scope.

  • Poland: the amending act took effect

    The Polish transposition arrived through the act on the national cybersecurity system, published as Dz.U. 2026 poz. 252. Every Polish deadline below counts from here.

  • Poland: security management system in place

    The information security management system and the operational duties around it, plus mandatory incident reporting through the national S46 system.

  • Poland: first audits, and penalties become available

    First audits for essential entities, then at least every three years. The same date ends the moratorium on the new penalties. We mention it because runway is worth knowing about, not because a deadline is a sales argument.

If you are not in Poland

The framework catalog, evidence collection and document generation work the same way for any national transposition, because article 21 is the common shape. What we do not have yet is your country's specific classification rules, registration duties and reporting routing modelled as data, the way we did for Poland. Tell us which country you need and it goes into the queue with a real answer about timing, not a maybe.

03 / The measures

What article 21 actually asks for

Ten measure areas, plus the reporting duties that sit next to them. It reads like a shorter, blunter ISO 27001, which is not a coincidence and turns out to be good news if you have done ISO work already.

21(2)(a)

Risk analysis and security policies

A documented approach to risk, and information system security policies that follow from it rather than from a template.

21(2)(b)

Incident handling

Detection, response, records, and the process that produces a report a regulator will accept.

21(2)(c)

Continuity and crisis management

Business continuity, backup management, disaster recovery, and who decides what during a bad week.

21(2)(d)

Supply chain security

Security in your direct supplier relationships, including the specific vulnerabilities of each supplier.

21(2)(e)

Secure acquisition and development

Security across acquisition, development and maintenance, including vulnerability handling and disclosure.

21(2)(f)

Measuring effectiveness

Policies and procedures to assess whether your risk management measures actually work. This is the one most programs skip.

21(2)(g)

Cyber hygiene and training

Basic practices and security awareness training, for everyone rather than for the security team.

21(2)(h)

Cryptography

Policies on cryptography and, where appropriate, encryption. Written down, not assumed.

21(2)(i)

HR security, access control, assets

Human resources security, access control policies, and knowing what you actually own.

21(2)(j)

MFA and secured communications

Multi factor or continuous authentication, secured voice, video and text, and secured emergency communications.

article 23

The reporting clocks

Early warning within 24 hours of becoming aware, incident notification within 72 hours, and a final report within one month.

article 20

Management accountability

Management bodies approve the risk measures, oversee implementation, can be held responsible, and are required to follow training themselves.

Ten measure areas 24 and 72 hour clocks Management on the hook by name National law fills in the rest
04 / What carries over

If you have done ISO 27001, most of this is filing

Article 21 is ISO 27001 shaped. Not identical, and definitely not a free pass, but the overlap is large enough that the honest job is mapping and gap filling rather than starting again.

Carries over directly
  • Risk assessment, risk register and treatment plan
  • Policies, training records and access reviews you already keep
  • Backups, MFA, asset inventory and vulnerability handling, with evidence pulled from your stack
  • Supplier reviews, if you are already running vendor assessments
  • In AuditBadger, 25 shared subcontrols count under SOC 2, ISO 27001 and NIS2 at the same time
Genuinely new work
  • Registration with your national authority, and keeping those details current
  • Incident reporting on statutory clocks, through your country's system, not by email
  • Notifying affected users about significant incidents and serious threats
  • Management body approval and management training as a named, documented duty
  • Whatever your member state added on top, which is the part nobody can guess for you
One correction worth making

An ISO 27001 certificate does not automatically satisfy NIS2, and in Poland specifically there is no presumption of conformity in the enacted law, despite a lot of pages online saying otherwise. Treat ISO as an accelerator that removes most of the work, not as an exemption. Our ISO to NIS2 coverage view is our own mapping and the product labels it that way.

05 / What we do today

Honest scope, stated up front

We would rather lose a fit we cannot serve than win one and explain later. So here is exactly what exists, and the next section is what does not.

Framework

A NIS2 control catalog, not a PDF pack

The measure areas broken into controls with owners, evidence and status, so the program is a live thing rather than a folder someone updates before an audit.

Poland

The Polish transposition, in Polish

Thirty measures across ten areas, 75 broken out subpoints, each carrying its article reference, authored from the Polish statute rather than translated from English. Plus classification, the obligations calendar and a Polish document wizard.

Evidence

Evidence from the systems you already run

Over 120 automated checks across 12 integrations feed the measures: MFA posture, backups, encryption, logging, device posture, training completions. Checks run monthly and whenever you press the button. Scheduled checks, not continuous monitoring.

Documents

Policies drafted, then reviewed by you

AI writes the first version from answers about your actual setup. You edit and approve. Every change needs your confirmation and lands in the audit trail, because a policy nobody read is worse than no policy.

Coverage

See your ISO 27001 work against NIS2

Run an ISO project alongside and the coverage view grades each NIS2 measure covered, partial or not covered, so the gap list is short and specific.

Operations

Incidents, training, vendors, assets

An incident register with an anonymous tokenized reporting portal, a training LMS built from your own policies, vendor assessments through a portal that needs no vendor account, and an asset register. One tool, one price.

Honestly: this is early access

NIS2 support is not switched on for every account yet, and the statutory parameters we encoded are still going through legal review. We enable it for design partners after a conversation. If you are in scope and want to shape how this works, now is the useful moment. If you need a finished, certified NIS2 product this quarter, we are not that yet and we would rather you heard it here.

06 / Where we stop

The lines we do not cross

Most vendors keep this part vague. Ours is in writing, before you spend anything.

We do not file your reports

Regulatory notifications are submitted by you, through your country's system. We help draft the content, track the deadlines and keep the record. We do not press send on your behalf.

We are not a law firm

None of this is legal advice. Article references come from the published texts and we label them that way. Where it matters, get a lawyer. We do.

Poland first, other countries honestly

The Polish transposition is modelled properly, down to classification rules and statutory deadlines. Other member states get the common article 21 shape today. Ask us about yours and you will get a real answer about timing.

We do not call our checks continuous

They run monthly, plus whenever you trigger them. Your auditor will ask what continuous means, so we say it plainly first.

We do not audit you

Audits are done by qualified auditors and conformity assessment bodies. We prepare you and export the registers. If the same company prepared and graded you, the result would be worth nothing.

Some thresholds do not exist yet

In Poland the regulation setting numeric significant incident thresholds has not been issued, so classification rests on the statutory definition. The product says so, rather than inventing a number that looks reassuring.

07 / Questions

The ones we actually get asked

Does NIS2 apply to my company?

It depends on your sector, your size and your country. Broadly: large organizations in the Annex I sectors are essential entities, medium organizations there and medium or large ones in Annex II are important entities. Some organizations are in scope at any size, including providers of public electronic communications networks and services, DNS providers, TLD registries and trust service providers. Your member state publishes the list that actually decides it.

Does ISO 27001 make us NIS2 compliant?

No, but it does most of the heavy lifting. Article 21 is ISO 27001 shaped, so risk management, policies, access control, backups, supplier reviews and training mostly carry over. What does not carry over is registration, statutory incident reporting, user notification and management body duties. In Poland there is specifically no presumption of conformity in the enacted law, despite what several sites claim.

How fast do we have to report an incident?

Early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month, under article 23. Your member state decides the channel, the forms and who receives them, which is the part that varies most.

Can directors really be held personally responsible?

Article 20 puts approval of the risk management measures and oversight of their implementation on management bodies, and requires them to follow training. Several member states, Poland included, attached personal consequences to that. It is one of the few compliance duties you cannot delegate away.

Which countries do you support today?

Poland properly, in Polish, including classification and the statutory obligations calendar. Everywhere else you get the common article 21 catalog, evidence collection and document generation, without your national specifics modelled as data yet. We would rather say that than imply full coverage.

What does it cost?

$250 per month, flat, with no per-user fees and no usage limits. The same price covers SOC 2, ISO 27001 and NIS2. NIS2 support is early access, so we switch it on after a short conversation.

Start from what you already have

We will walk you through the catalog, the dates that apply to you, and how much of your existing work attaches as evidence on day one. The call is with a founder, not a sales team.

See pricing: $250/month

No long term contracts. The call is not legal advice.