NIS2 scope and applicability
NIS2 applies to essential entities (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and important entities (postal, waste management, chemicals, food, manufacturing, digital providers, research). Organisations with 50+ employees and €10M+ annual turnover in these sectors are likely in scope.
The penalty regime is significant: up to €10M or 2% of global annual turnover for essential entities, up to €7M or 1.4% of global annual turnover for important entities. The national competent authorities designated by member states are beginning supervision programmes — organisations should assume active oversight rather than passive transposition.
Article 21 security measures relevant to monitoring
Article 21(2) specifies measures including: (b) incident handling; (d) supply chain security; (e) security in network and information systems acquisition, development, and maintenance; (f) policies and procedures to assess the effectiveness of cybersecurity risk management measures; (h) basic cyber hygiene practices and cybersecurity training; (j) use of multi-factor authentication.
For security operations, the most directly relevant measures are (b) incident handling and (f) effectiveness assessment. NIS2 does not prescribe specific logging controls the way PCI DSS does, but the incident handling requirement implies detection and monitoring capabilities, and the effectiveness assessment requirement implies metrics and reporting.
Incident reporting obligations
NIS2 Article 23 requires early warning to the national CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a notification within 72 hours with an initial assessment, and a final report within 1 month. A 'significant incident' is one that causes severe operational disruption or financial loss, or that affects other persons by causing considerable material or non-material damage.
The ManySignal case timeline is the primary evidence source for incident reports. When a case is classified as a significant incident, the investigate agent generates a preliminary incident report — incident timeline, affected systems and identities, probable attack vector, and initial impact assessment. This draft is the starting point for the 72-hour notification.
Supply chain security monitoring
NIS2 Article 21(2)(d) requires security measures addressing supply chain security. For security operations, this means monitoring the security posture of critical suppliers and the access your suppliers have to your systems. ManySignal's entity graph models supplier identities (contractors, managed service providers) as a distinct identity class with their own baselines.
Monitor supplier-identity activity for the same patterns you monitor for privileged internal identities: first-access to new systems, access outside contracted hours, volume anomalies, and privilege escalation. Third-party access is the most common supply chain attack vector.
Building the NIS2 compliance evidence package
For national competent authority inspections, prepare: the risk assessment methodology, the incident handling procedure (referencing ManySignal's case lifecycle), the incident log (all cases from the past 12 months with classification and disposition), and the effectiveness metrics (the weekly metrics report archive).
NIS2 does not have a certification scheme like ISO 27001, but some member states are developing national equivalents. ISO 27001 certification is explicitly referenced as a way to demonstrate partial compliance with Article 21 measures. Treating the NIS2 compliance evidence as a subset of your ISO 27001 ISMS evidence is the most efficient approach.
Key takeaways
- NIS2 applies to essential and important entities in 18 sectors with 50+ employees and €10M+ turnover.
- Article 21 incident handling and effectiveness assessment measures require detection and monitoring capabilities.
- Article 23: 24-hour early warning, 72-hour notification, 1-month final report for significant incidents.
- The 24-hour early warning requirement demands fast triage — not a days-long investigation process.
- Supplier identities should be monitored with the same intensity as privileged internal identities.
- ISO 27001 certification is explicitly referenced in NIS2 as evidence of Article 21 compliance.