Framework · NIS2

NIS2 tripled the scope. Your security program needs to keep up.

The NIS2 Directive came into force in October 2024, expanding mandatory cybersecurity requirements to 18 sectors and tens of thousands of new “essential” and “important” entities across the EU. Management bodies now face personal liability. Sentrix maps NIS2’s ten security measures to your existing controls and closes gaps before your national authority comes looking.

18
Sectors now covered by NIS2—including digital infrastructure, cloud, managed services, and manufacturing
Personal
Management liability under NIS2—directors can be held personally liable for cybersecurity failures
24 hrs
Early warning deadline to your national CSIRT for significant incidents under NIS2
10
Minimum security measures required under NIS2 Article 21—all pre-mapped in Sentrix
NIS2 Article 21 requirements

Ten security measures. Board accountability. Proportionate to your risk.

NIS2 Article 21 requires essential and important entities to implement “appropriate and proportionate” technical and organisational measures. The ten minimum measures cover everything from risk analysis and incident handling to supply chain security and cryptography.

  • Art. 21(2)(a): Risk analysis and information system security policies
  • Art. 21(2)(b): Incident handling, detection, and response
  • Art. 21(2)(c): Business continuity and crisis management
  • Art. 21(2)(d): Supply chain security including supplier relationships
  • Art. 21(2)(e): Security in network and information systems acquisition
  • Art. 21(2)(f–j): Access control, cryptography, HR security, MFA, communications

NIS2 Art. 21 · Security measure coverage

10 MEASURES
(a) Risk analysis & security policies✓ PASS
(b) Incident handling✓ PASS
(c) Business continuity✓ PASS
(d) Supply chain security▲ 3 vendors
(h) Cryptography & encryption✓ PASS
(i) HR security & access control✓ PASS
(j) MFA & secure communications✓ PASS
Full NIS2 capabilities

From management accountability to incident reporting—automated.

Management body accountability

NIS2 requires management bodies to approve security measures and oversee implementation. Sentrix provides board-level dashboards, risk appetite documentation, and management sign-off workflows that demonstrate governance oversight.

Incident notification workflow

NIS2 requires a 24-hour early warning, 72-hour incident notification, and 1-month final report to your national CSIRT. Sentrix automates the classification, timeline tracking, and regulatory template generation for each stage.

Supply chain security (Art. 21(d))

NIS2 requires security measures that address risks in supplier and service provider relationships. Sentrix maps your vendor risk program to Art. 21(d) and continuously monitors your supply chain posture.

Business continuity

Art. 21(c) requires backup management, disaster recovery, and crisis management. Sentrix tracks BCP/DR test evidence, recovery time objectives, and backup verification with continuous monitoring.

DORA crosswalk

Financial entities subject to both NIS2 and DORA manage both from one Sentrix program. Where DORA is the lex specialis for financial entities, Sentrix identifies the controls that satisfy both simultaneously.

ISO 27001 alignment

Organizations using ISO 27001 as their security framework already satisfy a significant portion of NIS2. Sentrix maps your ISO evidence to NIS2 measures and shows exactly what remains—typically less than 30% new work.

See your NIS2 compliance posture against your real infrastructure.

We map your ten security measures live in the demo using your actual environment.