NIS2 Directive
The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.
Directive (EU) 2022/2555 · European Commission — NIS2 · published 2022-12-27
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NIS2 Directive is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely published; obligations not modelled as a control catalog. National transpositions differ.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Governance · Risk management measures · Incident reporting · Supply chain security
- Applies to
- critical sectors · EU
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| Directive (EU) 2016/1148 (NIS1) | Superseded | date not published |
| Directive (EU) 2022/2555 | Current edition · supersedes Directive (EU) 2016/1148 (NIS1) | 2022-12-27 |
05Change history
06Related frameworks
- NERC CIPCIP-002 through CIP-015 (per-standard versions)
Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.
- Digital Operational Resilience ActRegulation (EU) 2022/2554
Commonly assessed together · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
- NIST SP 800-172Rev. 3
Commonly assessed together · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
- SOC for CybersecurityAICPA cybersecurity risk management reporting framework
Same framework family · AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.