Skip to content
Cyber Horizon
All frameworks

// Cyber Hygiene

NIS2 Directive Compliance Software

EU Network and Information Security Directive 2. Cybersecurity requirements for essential and important entities.

Framework at a glance

Short name

NIS2

Version

2024

Category

Cyber Hygiene

Controls

29

What NIS2 covers

29 controls across 7 domains — every one tracked, owned and evidenced in Cyber Horizon.

Accountability & Reporting

5 controls
  • NIS2-ACC-01 Registration with National Authority
  • NIS2-ACC-02 Compliance Evidence & Audit
  • NIS2-ACC-03 Vulnerability Disclosure Policy
  • NIS2-ACC-04 Peer Review Mechanisms
  • NIS2-ACC-05 Reporting Obligations to Competent Authorities

Business Continuity

2 controls
  • NIS2-BC-01 Business Continuity Plan
  • NIS2-BC-02 Backup & Data Recovery

Governance & Oversight

3 controls
  • NIS2-GOV-01 Management Body Accountability
  • NIS2-GOV-02 Cybersecurity Policy Framework
  • NIS2-GOV-03 Security Roles & Responsibilities

Incident Management

3 controls
  • NIS2-INC-01 Incident Detection & Reporting
  • NIS2-INC-02 Incident Response Plan
  • NIS2-INC-03 Significant Incident Criteria

Risk Management

4 controls
  • NIS2-RM-01 Cybersecurity Risk Analysis
  • NIS2-RM-02 Vulnerability Management
  • NIS2-RM-03 Asset Management
  • NIS2-RM-04 Security of Network and Systems

Supply Chain Security

4 controls
  • NIS2-SC-01 Supply Chain Risk Assessment
  • NIS2-SC-02 Supplier Security Requirements
  • NIS2-SC-03 Supplier Monitoring
  • NIS2-SC-04 ICT Supply Chain Risk Policy

Security Measures

8 controls
  • NIS2-SEC-01 Access Control & Authentication
  • NIS2-SEC-02 Encryption & Cryptography
  • NIS2-SEC-03 Network Security
  • NIS2-SEC-04 Secure System Development
  • NIS2-SEC-05 Human Resources Security

How Cyber Horizon automates NIS2

Every NIS2 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is NIS2 Directive?

EU Network and Information Security Directive 2. Cybersecurity requirements for essential and important entities.

How many controls does NIS2 Directive have?

NIS2 Directive (2024) has 29 controls in Cyber Horizon's catalogue, organised across 7 domains.

How does Cyber Horizon help with NIS2 Directive?

Cyber Horizon maps NIS2 Directive into a shared control library alongside every other framework you run, so evidence collected once counts towards NIS2 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See NIS2 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of NIS2 in Cyber Horizon.