NIS2 · DIRECTIVE (EU) 2022/2555
NIS2 compliance software
NIS2 asks for evidence of how you manage risk. Secrato is where that evidence lives.
For essential and important entities, NIS2 means showing continuously that risk measures are in place, that significant incidents can be reported inside the directive’s deadlines, and that management can account for both.
IN SHORT
NIS2 is the EU directive setting cybersecurity risk management and incident reporting obligations for essential and important entities, with management bodies accountable for compliance. Secrato supports NIS2 readiness by connecting risk measures, controls, evidence and reporting records to the requirements they satisfy, so an organisation can maintain and demonstrate them over time.
NIS2 has applied since 18 October 2024 and sets baseline obligations for essential and important entities across the sectors in Annexes I and II. For scope, obligations and the reporting timelines in full, see the NIS2 hub. Directive (EU) 2022/2555, Articles 2 and 3.
HOW SECRATO SUPPORTS NIS2
Three things the directive expects, kept connected
Risk management measures
Evidence connected to the requirements it answers
NIS2 expects appropriate, proportionate risk management measures across the areas set out in Article 21, kept in place and reviewable over time. Secrato’s Risk Management module keeps each risk connected to the controls that treat it, the Unified Control Library holds those controls as reusable objects, and Policy Management connects the policies that govern them. The result is a documented line from a risk to the measure that addresses it.
Directive (EU) 2022/2555, Article 21.
INCIDENT REPORTING
Incident reporting readiness, before the clock starts
A significant incident under Article 23 triggers a staged sequence: an early warning within 24 hours, a notification within 72 hours, and a final report within one month of the notification. Meeting those deadlines depends on the records being ready in advance. Secrato supports this through Evidence Management, which keeps incident-relevant records connected to the controls and requirements they substantiate, so each submission draws on maintained evidence.
Directive (EU) 2022/2555, Article 23.
Governance and accountability
Management can account for the programme
NIS2 makes management bodies responsible for approving the risk measures, overseeing them and being trained, and they can be held liable. That rests on being able to see the current state. Secrato’s Dashboards and Reports give visibility into compliance status, risk posture and audit readiness, and the Audit Hub organises evidence and control readiness for review, so management can account for the programme and an auditor can follow it.
Directive (EU) 2022/2555, Article 20.
THE REST OF THE PLATFORM
More of Secrato, mapped to NIS2
Beyond the three above, these parts of the platform carry the rest of the NIS2 work, each tied to the requirement it serves.
Compliance Engine
Track every NIS2 obligation in one place. Manage requirements, controls, evidence, policies and status in a single working environment, moving from point-in-time checks to continuous visibility of where you stand.
Assessments
See where you stand against NIS2. Scope, score, assign and complete assessment work against the framework’s requirements, with each response connected to the evidence and records behind it.
Procedure Management
Keep the operational steps behind the measures. Define, maintain and review the procedures that support the controls, policies and risks NIS2 expects, so how the work is done is documented, not assumed.
Global Governance
Govern several in-scope entities consistently. Apply top-level decisions across workspaces, cascading them through the hierarchy, with approved local deviations where a workspace needs them.
API and integrations
Connect the systems the evidence comes from. Link internal and external systems through APIs and integrations to support reliable evidence automation, so records stay current without manual collection.
Trust Network
Show your posture to the partners who must assess you. Present selected security and compliance information to external stakeholders, with public or gated access, NDA flows and access logs.
UNIFIED CONTROL LIBRARY
Assess a control once. Reuse it across ISO 27001, NIS2 and DORA.
Most NIS2 measures overlap with controls an organisation already runs. Secrato supports NIS2 alongside the other frameworks on its confirmed coverage list, with controls mapped across them through the Unified Control Library, so overlapping obligations stop generating duplicate work.
EU DATA SOVEREIGNTY
GRC data is processed on self-managed infrastructure in a Belgian datacentre, within the EU legal and regulatory environment.
Belgium · EU
NIS2 questions
Who does NIS2 apply to?
Essential and important entities in the sectors listed in Annexes I and II, with classification setting which supervisory regime applies. Most in-scope entities meet at least medium-size thresholds, though some are in scope regardless of size.
Directive (EU) 2022/2555, Articles 2 and 3.
What are the reporting deadlines?
For a significant incident: an early warning within 24 hours, a notification within 72 hours, and a final report within one month of the notification.
Directive (EU) 2022/2555, Article 23.
Does ISO 27001 cover NIS2?
An ISO 27001 ISMS covers many of the Article 21 measures, but NIS2 adds obligations certification alone does not close, including the reporting timelines and management-body accountability under Article 20. A mapping exercise shows what is already evidenced and what remains.
Run NIS2 as a working method
NIS2 rewards organisations that can show their work, not just describe it. Secrato keeps the risk measures, evidence and governance records connected to the requirements they answer, so readiness is maintained between audits rather than rebuilt before each one.