Skip to main content
—
Framework library
Framework module · nis2

NIS2 Directive

The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.

Directive (EU) 2022/2555 · European Commission — NIS2 · published 2022-12-27

Standing today
Directory entry

00Answer

from the registry record
What is NIS2 Directive?
The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.
Who does NIS2 Directive apply to?
NIS2 Directive applies to critical sectors, EU, per European Commission — NIS2.
What is the current version of NIS2 Directive?
The current edition is Directive (EU) 2022/2555, issued by European Commission — NIS2 and published 2022-12-27. Source: https://digital-strategy.ec.europa.eu/en/policies/nis2-directive.
What does an assessment under NIS2 Directive require?
No control catalog has been ingested for NIS2 Directive yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIS2 Directive is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog. National transpositions differ.

02Registry record

checked 2026-08-30
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Governance · Risk management measures · Incident reporting · Supply chain security
Applies to
critical sectors · EU
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
Directive (EU) 2016/1148 (NIS1)Supersededdate not published
Directive (EU) 2022/2555Current edition · supersedes Directive (EU) 2016/1148 (NIS1)2022-12-27

05Change history

06Related frameworks

scored from registry facts
  1. NERC CIPCIP-002 through CIP-015 (per-standard versions)

    Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.

  2. Digital Operational Resilience ActRegulation (EU) 2022/2554

    Commonly assessed together · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

  3. Commonly assessed together · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.

  4. SOC for CybersecurityAICPA cybersecurity risk management reporting framework

    Same framework family · AICPA's board- and enterprise-risk-oriented cybersecurity examination, distinct from SOC 2 — a description of an entity's cybersecurity risk-management program plus an opinion on its effectiveness, rather than a controls report for a specific service.

NIS2 Directive | ControlFrame