NIS2, in plain terms.

The ten risk-management measures, the reporting clock, and the management accountability nobody mentions until it applies to them.

Wider scope, real accountability

NIS2 widened the net considerably — energy, transport, health, digital infrastructure, public administration, waste, food, manufacturing, postal services and more, split between essential and important entities.

Two things surprise people. The first is the reporting clock: an early warning within 24 hours, an incident notification within 72, and a final report within a month. The second is that management bodies must approve and oversee the measures, and can be held personally accountable.

OpenGRC includes the NIS2 Directive bundle covering the cybersecurity risk-management measures, and national transposition bundles where they exist.

Built for the obligations

Measures, reporting and oversight.

The 24 / 72 hour clock

The 24 / 72 hour clock

Notification deadline tracking runs from the moment an incident is opened, alongside the response playbook, tasks and timeline — so the early warning is not something you remember at hour 23.

Supply chain security

Supply chain security

Article 21 puts supply chain security squarely in scope. Vendor management covers questionnaires, risk scoring, tiering and compliance document expiry, with a portal for vendors to respond directly.

Management approval, recorded

Management approval, recorded

Measures must be approved and overseen by the management body. Approval workflows give you configurable multi-stage sign-off on policies and risk assessments, with the record kept where an auditor can find it.

Article 21 risk-management measures

MeasureIn OpenGRC
Risk analysis and information system security policiesRisk register and policy management with approval workflows
Incident handlingIncident response with playbooks, tasks, timeline and deadline tracking
Business continuity and crisis managementISO 22301 bundle included; remediation projects and playbooks
Supply chain securityVendor risk management with questionnaires and document expiry
Security in acquisition, development and maintenanceControl implementations, change management and the OWASP bundles
Policies to assess effectiveness of measuresAudit management, with control effectiveness derived from completed audits
Cyber hygiene and trainingChecklists and recurring campaigns with signature approval
Cryptography and encryption policyPolicy management with lifecycle and revision history
Human resources security and access controlUser access review campaigns and role-based access control
Multi-factor authentication and secure communicationsControl implementations with test procedures and evidence

NIS2 questions

Does NIS2 apply to us?

It depends on your sector and size, and on how your member state transposed it. The directive covers essential and important entities across a wide range of sectors. Scope is a legal question — take advice rather than guessing from a software page.

What about national transposition?

How does the reporting timeline work?

Does ISO 27001 cover NIS2?