NIS2 tripled the scope. Your security program needs to keep up.
The NIS2 Directive came into force in October 2024, expanding mandatory cybersecurity requirements to 18 sectors and tens of thousands of new “essential” and “important” entities across the EU. Management bodies now face personal liability. Sentrix maps NIS2’s ten security measures to your existing controls and closes gaps before your national authority comes looking.
Ten security measures. Board accountability. Proportionate to your risk.
NIS2 Article 21 requires essential and important entities to implement “appropriate and proportionate” technical and organisational measures. The ten minimum measures cover everything from risk analysis and incident handling to supply chain security and cryptography.
- Art. 21(2)(a): Risk analysis and information system security policies
- Art. 21(2)(b): Incident handling, detection, and response
- Art. 21(2)(c): Business continuity and crisis management
- Art. 21(2)(d): Supply chain security including supplier relationships
- Art. 21(2)(e): Security in network and information systems acquisition
- Art. 21(2)(f–j): Access control, cryptography, HR security, MFA, communications
NIS2 Art. 21 · Security measure coverage
10 MEASURESFrom management accountability to incident reporting—automated.
Management body accountability
NIS2 requires management bodies to approve security measures and oversee implementation. Sentrix provides board-level dashboards, risk appetite documentation, and management sign-off workflows that demonstrate governance oversight.
Incident notification workflow
NIS2 requires a 24-hour early warning, 72-hour incident notification, and 1-month final report to your national CSIRT. Sentrix automates the classification, timeline tracking, and regulatory template generation for each stage.
Supply chain security (Art. 21(d))
NIS2 requires security measures that address risks in supplier and service provider relationships. Sentrix maps your vendor risk program to Art. 21(d) and continuously monitors your supply chain posture.
Business continuity
Art. 21(c) requires backup management, disaster recovery, and crisis management. Sentrix tracks BCP/DR test evidence, recovery time objectives, and backup verification with continuous monitoring.
DORA crosswalk
Financial entities subject to both NIS2 and DORA manage both from one Sentrix program. Where DORA is the lex specialis for financial entities, Sentrix identifies the controls that satisfy both simultaneously.
ISO 27001 alignment
Organizations using ISO 27001 as their security framework already satisfy a significant portion of NIS2. Sentrix maps your ISO evidence to NIS2 measures and shows exactly what remains—typically less than 30% new work.
See your NIS2 compliance posture against your real infrastructure.
We map your ten security measures live in the demo using your actual environment.