NIS2, in plain terms.
The ten risk-management measures, the reporting clock, and the management accountability nobody mentions until it applies to them.
Wider scope, real accountability
NIS2 widened the net considerably — energy, transport, health, digital infrastructure, public administration, waste, food, manufacturing, postal services and more, split between essential and important entities.
Two things surprise people. The first is the reporting clock: an early warning within 24 hours, an incident notification within 72, and a final report within a month. The second is that management bodies must approve and oversee the measures, and can be held personally accountable.
OpenGRC includes the NIS2 Directive bundle covering the cybersecurity risk-management measures, and national transposition bundles where they exist.
Measures, reporting and oversight.
The 24 / 72 hour clock
Notification deadline tracking runs from the moment an incident is opened, alongside the response playbook, tasks and timeline — so the early warning is not something you remember at hour 23.
Supply chain security
Article 21 puts supply chain security squarely in scope. Vendor management covers questionnaires, risk scoring, tiering and compliance document expiry, with a portal for vendors to respond directly.
Management approval, recorded
Measures must be approved and overseen by the management body. Approval workflows give you configurable multi-stage sign-off on policies and risk assessments, with the record kept where an auditor can find it.
Article 21 risk-management measures
| Measure | In OpenGRC |
|---|---|
| Risk analysis and information system security policies | Risk register and policy management with approval workflows |
| Incident handling | Incident response with playbooks, tasks, timeline and deadline tracking |
| Business continuity and crisis management | ISO 22301 bundle included; remediation projects and playbooks |
| Supply chain security | Vendor risk management with questionnaires and document expiry |
| Security in acquisition, development and maintenance | Control implementations, change management and the OWASP bundles |
| Policies to assess effectiveness of measures | Audit management, with control effectiveness derived from completed audits |
| Cyber hygiene and training | Checklists and recurring campaigns with signature approval |
| Cryptography and encryption policy | Policy management with lifecycle and revision history |
| Human resources security and access control | User access review campaigns and role-based access control |
| Multi-factor authentication and secure communications | Control implementations with test procedures and evidence |
NIS2 questions
Does NIS2 apply to us?
It depends on your sector and size, and on how your member state transposed it. The directive covers essential and important entities across a wide range of sectors. Scope is a legal question — take advice rather than guessing from a software page.
™