CloudSignLab

NIS2 Directive (EU) 2022/2555

Get ready for NIS2, measure by measure

NIS2 asks essential and important entities for cybersecurity risk management, incident reporting and accountable management. CloudSignLab turns the ten measures of Article 21 into controls with owners, evidence and a readiness score, so you know where you stand and what to do next.

Get ready for NIS2, measure by measure

What NIS2 asks of you

  • Risk management measures (Article 21)

    Ten areas of measures, from risk analysis and incident handling to supply chain security, cryptography, access control and multi-factor authentication, appropriate to your risks.

  • Incident reporting (Article 23)

    Significant incidents are reported to the CSIRT or authority: an early warning within 24 hours, a notification within 72 hours and a final report within one month.

  • Management accountability (Article 20)

    The management body approves the measures, oversees them and can be held liable; its members follow training on cybersecurity risks.

  • Supply chain security

    The security of your direct suppliers and service providers is part of the measures: their practices, vulnerabilities and the quality of their products.

How CloudSignLab helps

  • Readiness per measure

    Controls are mapped to NIS2 Article 21(2) and Regulation 2024/2690; the readiness score shows each measure and what is still missing.

  • The reporting clock

    Incidents show the 24-hour, 72-hour and one-month deadlines from the moment you became aware, with reminders before each one.

  • Suppliers under control

    A supplier register with criticality, security checks your suppliers answer online, and the next review date for each one.

  • Proof for management and auditors

    Evidence linked to every control, a management summary with the Article 20 sign-off, and Excel reports for auditors.

Read the guide to frameworks and readiness →

Questions about NIS2

Does NIS2 apply to my company?

It applies to medium and large companies in the sectors of Annex I and II of the directive, and to some smaller ones designated by the authorities. The free NIS2 check answers it in about a minute; national laws can add more.

Can a small supplier use CloudSignLab without being under NIS2?

Yes. Many customers under NIS2 ask their suppliers for security answers; the supplier package covers the controls, answer library and trust page they need for that.

See your NIS2 readiness today

Start free, run the setup and get your first readiness score in minutes. No credit card.

Start free