NIS2

NIS2 is the EU directive on security of network and information systems. XIRIQ covers it as an obligations check: are you doing what the directive requires of essential and important entities?

Obligations covered

The assessment presents 15 obligations drawn from the directive's cybersecurity risk-management measures and reporting duties, including risk analysis and security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, assessing the effectiveness of measures, cyber hygiene and training, cryptography, personnel and access security, multi-factor authentication, and incident notification duties. Each is judged implemented, partially implemented or not implemented, with notes for how you meet it.

Example
The implementation vocabulary used for IEC 62443 and NIS2 items, with partial selected.

How it differs from a control framework

NIS2 obligations are legal requirements written at a higher level than CAF outcomes or 62443 controls: the directive says you must manage supply chain risk, not how. Expect your evidence and justification notes to carry more of the weight here; the status alone says little without them. Member state transposition varies, so check your national implementing law for specifics such as notification timelines. Many organisations pair a NIS2 obligations check with a CAF or 62443 assessment: the obligations say what must be true, the control frameworks help demonstrate it.

Can't find what you need? Browse the Resources articles or use the feedback button inside the app.