EU Directive 2022/2555 on Network and Information Security
EU-wide cybersecurity legislation requiring essential and important entities to implement risk-management measures, report significant incidents, and submit to supervisory oversight. Covers 10 mandatory security domains under Article 21 including incident handling, business continuity, supply chain security, and cryptography.
AC (25) AT (4) CA (3) CM (6) CP (9) IA (1) IR (9) PL (4) PM (7) PS (9) RA (5) SA (8) SC (8) SI (2) SR (5)
AC Access Control
| Control | Name | NIS2 Directive References |
|---|---|---|
| AC-01 | Policy and Procedures | Art. 21(2)(i) |
| AC-02 | Account Management | Art. 21(2)(i) |
| AC-03 | Access Enforcement | Art. 21(2)(i) |
| AC-04 | Information Flow Enforcement | Art. 21(2)(i) |
| AC-05 | Separation of Duties | Art. 21(2)(i) |
| AC-06 | Least Privilege | Art. 21(2)(i) |
| AC-07 | Unsuccessful Logon Attempts | Art. 21(2)(i) |
| AC-08 | System Use Notification | Art. 21(2)(i) |
| AC-09 | Previous Logon Notification | Art. 21(2)(i) |
| AC-10 | Concurrent Session Control | Art. 21(2)(i) |
| AC-11 | Device Lock | Art. 21(2)(i) |
| AC-12 | Session Termination | Art. 21(2)(i) |
| AC-13 | Supervision and Review — Access Control | Art. 21(2)(i) |
| AC-14 | Permitted Actions Without Identification or Authentication | Art. 21(2)(i) |
| AC-15 | Automated Marking | Art. 21(2)(i) |
| AC-16 | Security and Privacy Attributes | Art. 21(2)(i) |
| AC-17 | Remote Access | Art. 21(2)(i) |
| AC-18 | Wireless Access | Art. 21(2)(i) |
| AC-19 | Access Control for Mobile Devices | Art. 21(2)(i) |
| AC-20 | Use of External Systems | Art. 21(2)(i) |
| AC-21 | Information Sharing | Art. 21(2)(i) |
| AC-22 | Publicly Accessible Content | Art. 21(2)(i) |
| AC-23 | Data Mining Protection | Art. 21(2)(i) |
| AC-24 | Access Control Decisions | Art. 21(2)(i) |
| AC-25 | Reference Monitor | Art. 21(2)(i) |
AT Awareness and Training
CA Security Assessment and Authorization
CM Configuration Management
CP Contingency Planning
| Control | Name | NIS2 Directive References |
|---|---|---|
| CP-01 | Policy and Procedures | Art. 21(2)(c) |
| CP-02 | Contingency Plan | Art. 21(2)(c) |
| CP-03 | Contingency Training | Art. 21(2)(c) |
| CP-04 | Contingency Plan Testing | Art. 21(2)(c) |
| CP-06 | Alternate Storage Site | Art. 21(2)(c) |
| CP-07 | Alternate Processing Site | Art. 21(2)(c) |
| CP-08 | Telecommunications Services | Art. 21(2)(c)Art. 21(2)(j) |
| CP-09 | System Backup | Art. 21(2)(c) |
| CP-10 | System Recovery and Reconstitution | Art. 21(2)(c) |
IA Identification and Authentication
| Control | Name | NIS2 Directive References |
|---|---|---|
| IA-02 | Identification and Authentication (Organizational Users) | Art. 21(2)(j) |
IR Incident Response
| Control | Name | NIS2 Directive References |
|---|---|---|
| IR-01 | Policy and Procedures | Art. 21(2)(b) |
| IR-02 | Incident Response Training | Art. 21(2)(b) |
| IR-03 | Incident Response Testing | Art. 21(2)(b) |
| IR-04 | Incident Handling | Art. 21(2)(b)Art. 21(2)(j) |
| IR-05 | Incident Monitoring | Art. 21(2)(b) |
| IR-06 | Incident Reporting | Art. 21(2)(b)Art. 23Art. 29 |
| IR-07 | Incident Response Assistance | Art. 21(2)(b)Art. 23 |
| IR-08 | Incident Response Plan | Art. 21(2)(b) |
| IR-09 | Information Spillage Response | Art. 21(2)(b)Art. 23 |
PL Planning
PM Program Management
| Control | Name | NIS2 Directive References |
|---|---|---|
| PM-01 | Information Security Program Plan | Art. 21(2)(a) |
| PM-05 | System Inventory | Art. 21(2)(i) |
| PM-06 | Measures of Performance | Art. 21(2)(f)Art. 32 |
| PM-09 | Risk Management Strategy | Art. 21(2)(a) |
| PM-13 | Security and Privacy Workforce | Art. 21(2)(g) |
| PM-15 | Security and Privacy Groups and Associations | Art. 29 |
| PM-16 | Threat Awareness Program | Art. 29 |
PS Personnel Security
| Control | Name | NIS2 Directive References |
|---|---|---|
| PS-01 | Policy and Procedures | Art. 21(2)(i) |
| PS-02 | Position Risk Designation | Art. 21(2)(i) |
| PS-03 | Personnel Screening | Art. 21(2)(i) |
| PS-04 | Personnel Termination | Art. 21(2)(i) |
| PS-05 | Personnel Transfer | Art. 21(2)(i) |
| PS-06 | Access Agreements | Art. 21(2)(i) |
| PS-07 | External Personnel Security | Art. 21(2)(i) |
| PS-08 | Personnel Sanctions | Art. 21(2)(i) |
| PS-09 | Position Descriptions | Art. 21(2)(i) |
RA Risk Assessment
SA System and Services Acquisition
| Control | Name | NIS2 Directive References |
|---|---|---|
| SA-03 | System Development Life Cycle | Art. 21(2)(e) |
| SA-04 | Acquisition Process | Art. 21(2)(d)Art. 21(2)(e)Art. 24 |
| SA-08 | Security and Privacy Engineering Principles | Art. 21(2)(e) |
| SA-09 | External System Services | Art. 21(2)(d) |
| SA-10 | Developer Configuration Management | Art. 21(2)(e) |
| SA-11 | Developer Testing and Evaluation | Art. 21(2)(e) |
| SA-20 | Customized Development of Critical Components | Art. 21(2)(e) |
| SA-21 | Developer Screening | Art. 21(2)(d) |
SC System and Communications Protection
| Control | Name | NIS2 Directive References |
|---|---|---|
| SC-08 | Transmission Confidentiality and Integrity | Art. 21(2)(h)Art. 21(2)(j) |
| SC-12 | Cryptographic Key Establishment and Management | Art. 21(2)(h) |
| SC-13 | Cryptographic Protection | Art. 21(2)(h)Art. 21(2)(j) |
| SC-24 | Fail in Known State | Art. 21(2)(c) |
| SC-28 | Protection of Information at Rest | Art. 21(2)(h) |
| SC-37 | Out-of-band Channels | Art. 21(2)(j) |
| SC-40 | Wireless Link Protection | Art. 21(2)(h) |
| SC-47 | Alternate Communications Paths | Art. 21(2)(j) |
SI System and Information Integrity
SR Supply Chain Risk Management
| Control | Name | NIS2 Directive References |
|---|---|---|
| SR-01 | Policy and Procedures | Art. 21(2)(d) |
| SR-02 | Supply Chain Risk Management Plan | Art. 21(2)(d) |
| SR-03 | Supply Chain Controls and Processes | Art. 21(2)(d) |
| SR-05 | Acquisition Strategies, Tools, and Methods | Art. 21(2)(d) |
| SR-06 | Supplier Assessments and Reviews | Art. 21(2)(d) |