NIS-2 Directive
Cybersecurity for Critical Infrastructures
What is NIS-2?
Directive (EU) 2022/2555 replaces the original NIS Directive and establishes harmonized requirements for cybersecurity, risk and incident management. A unified framework for the European single market – from risk management to reporting obligations to supervision and sanctions.
Scope & Affected Entities
NIS-2 distinguishes between essential entities and important entities. Cloud and IT service providers like ayedo explicitly fall within the addressee scope.
Important Entities
Cloud & IT Service Providers
Thresholds & Size Classes
Governance & Responsibility
Art. 20 anchors cybersecurity as a management duty. Management bodies must approve and oversee risk management measures and can be held personally liable.
Board Responsibility
Mandatory Training
Oversight & Reporting
Security & Risk Management Measures
Art. 21 defines minimum requirements for technical, operational and organizational measures. These must be state-of-the-art, proportionate to risk and cover the entire lifecycle.
Risk Analysis & Security Concepts
Incident Handling
Business Continuity
Supply Chain Security
Secure Development & Maintenance
Effectiveness Assessment
Cyber Hygiene & Training
Cryptography & Key Management
Personnel Security & Access Control
MFA & Secure Communication
Supply Chain & Third-Party Management
Art. 21(3) explicitly requires consideration of cybersecurity practices of sub-providers. NIS-2 thus anchors a supply chain security mandate, similar to DORA.
Vendor Risk Register
Pre-Contract Due Diligence
Contractual Protection
Continuous Monitoring
Security Incident Reporting Obligations
Art. 23 ff. establishes a multi-tiered reporting system – structurally identical to DORA. Coordination via national CSIRTs and central contact points.
Early Warning: 24 Hours
Incident Report: 72 Hours
Final Report: 1 Month
Definition ‘Significant’
Supervision, Sanctions & Enforcement
Chapter VII grants national authorities extensive control and enforcement powers. Sanctions must be effective, proportionate and dissuasive.
Authority Powers
Sanction Mechanisms
Suspension Powers
Burden of Proof
ayedo and NIS-2
Our Software Delivery Platform and Managed Services are designed for NIS-2 compliance – from risk management to 24/7 incident response to supply chain transparency.
ISO 27001 Risk Management
Zero-Trust & MFA
24/7 Detection & Monitoring
Business Continuity & DR
Incident Response & NIS-2 Reporting
Security Testing & Audits
Supply Chain Transparency
Crypto & Secrets Management
NIS-2 Enablement Packages
NIS-2 in Regulatory Context
NIS-2 is the cross-cutting framework for cybersecurity in the EU. It integrates with DORA, CRA, Cloud Sovereignty Framework, Data Act and GDPR.
NIS-2 & DORA
NIS-2 & Cyber Resilience Act
NIS-2 & Cloud Sovereignty
NIS-2 & Data Act
NIS-2 & GDPR
ayedo Compliance Overview
Strategic Implications
NIS-2 fundamentally changes how digital infrastructures must be operated. From board responsibility to supply chain management to sanction risks – here are the core implications.
Cybersecurity Becomes Board-Level
Engineering Discipline Mandatory
24/7 Operations & Incident Response
Supply Chain Governance
Testing & Assurance
Sanction Risks Real
Start Your NIS-2 Compliance
Whether cloud provider, managed service provider or critical infrastructure – we support you with systematic implementation of all NIS-2 requirements. From gap assessment to full compliance.