M ManySignal

Guide · ManySignal

NIS2 Readiness Guide

NIS2 Directive entered into force across EU member states in October 2024, expanding the scope of mandatory cybersecurity requirements to essential and important entities in 18 sectors. Article 21 specifies security measures including incident detection, logging, and monitoring. This guide covers the NIS2 obligations relevant to security operations and how ManySignal supports compliance.

EN Elena Novak — Co-founder & CTO, ManySignal
13 min read Published Jun 5, 2026 Download PDF
01

NIS2 scope and applicability

NIS2 applies to essential entities (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and important entities (postal, waste management, chemicals, food, manufacturing, digital providers, research). Organisations with 50+ employees and €10M+ annual turnover in these sectors are likely in scope.

The penalty regime is significant: up to €10M or 2% of global annual turnover for essential entities, up to €7M or 1.4% of global annual turnover for important entities. The national competent authorities designated by member states are beginning supervision programmes — organisations should assume active oversight rather than passive transposition.

02

Article 21 security measures relevant to monitoring

Article 21(2) specifies measures including: (b) incident handling; (d) supply chain security; (e) security in network and information systems acquisition, development, and maintenance; (f) policies and procedures to assess the effectiveness of cybersecurity risk management measures; (h) basic cyber hygiene practices and cybersecurity training; (j) use of multi-factor authentication.

For security operations, the most directly relevant measures are (b) incident handling and (f) effectiveness assessment. NIS2 does not prescribe specific logging controls the way PCI DSS does, but the incident handling requirement implies detection and monitoring capabilities, and the effectiveness assessment requirement implies metrics and reporting.

03

Incident reporting obligations

NIS2 Article 23 requires early warning to the national CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a notification within 72 hours with an initial assessment, and a final report within 1 month. A 'significant incident' is one that causes severe operational disruption or financial loss, or that affects other persons by causing considerable material or non-material damage.

The ManySignal case timeline is the primary evidence source for incident reports. When a case is classified as a significant incident, the investigate agent generates a preliminary incident report — incident timeline, affected systems and identities, probable attack vector, and initial impact assessment. This draft is the starting point for the 72-hour notification.

04

Supply chain security monitoring

NIS2 Article 21(2)(d) requires security measures addressing supply chain security. For security operations, this means monitoring the security posture of critical suppliers and the access your suppliers have to your systems. ManySignal's entity graph models supplier identities (contractors, managed service providers) as a distinct identity class with their own baselines.

Monitor supplier-identity activity for the same patterns you monitor for privileged internal identities: first-access to new systems, access outside contracted hours, volume anomalies, and privilege escalation. Third-party access is the most common supply chain attack vector.

05

Building the NIS2 compliance evidence package

For national competent authority inspections, prepare: the risk assessment methodology, the incident handling procedure (referencing ManySignal's case lifecycle), the incident log (all cases from the past 12 months with classification and disposition), and the effectiveness metrics (the weekly metrics report archive).

NIS2 does not have a certification scheme like ISO 27001, but some member states are developing national equivalents. ISO 27001 certification is explicitly referenced as a way to demonstrate partial compliance with Article 21 measures. Treating the NIS2 compliance evidence as a subset of your ISO 27001 ISMS evidence is the most efficient approach.

Key takeaways

  • NIS2 applies to essential and important entities in 18 sectors with 50+ employees and €10M+ turnover.
  • Article 21 incident handling and effectiveness assessment measures require detection and monitoring capabilities.
  • Article 23: 24-hour early warning, 72-hour notification, 1-month final report for significant incidents.
  • The 24-hour early warning requirement demands fast triage — not a days-long investigation process.
  • Supplier identities should be monitored with the same intensity as privileged internal identities.
  • ISO 27001 certification is explicitly referenced in NIS2 as evidence of Article 21 compliance.

Further reading

Frequently asked questions

What is NIS2 Readiness Guide in an agentic SOC?

NIS2 Readiness Guide is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle nis2 readiness guide?

ManySignal grounds nis2 readiness guide in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for nis2 readiness guide?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.