NIS2 is the EU directive on security of network and information systems. XIRIQ covers it as an obligations check: are you doing what the directive requires of essential and important entities?
Obligations covered
The assessment presents 15 obligations drawn from the directive's cybersecurity risk-management measures and reporting duties, including risk analysis and security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, assessing the effectiveness of measures, cyber hygiene and training, cryptography, personnel and access security, multi-factor authentication, and incident notification duties. Each is judged implemented, partially implemented or not implemented, with notes for how you meet it.
How it differs from a control framework
NIS2 obligations are legal requirements written at a higher level than CAF outcomes or 62443 controls: the directive says you must manage supply chain risk, not how. Expect your evidence and justification notes to carry more of the weight here; the status alone says little without them. Member state transposition varies, so check your national implementing law for specifics such as notification timelines. Many organisations pair a NIS2 obligations check with a CAF or 62443 assessment: the obligations say what must be true, the control frameworks help demonstrate it.