Regulatory Programme

NIS2, Run As A Programme

NIS2 is a directive transposed into national law, not a certification. There is no certificate to earn. What a competent authority looks for is evidence that your management body owns cyber risk, that your measures are proportionate, and that you can report a significant incident within twenty four hours. Auditara turns that into a programme you can actually run.

What This Is, And What It Is Not

Not Legal Advice

Auditara is a compliance programme platform delivered with a PECB certified Lead Auditor and Lead Implementer. It is not a law firm. NIS2 is transposed differently in each member state, and where a question turns on national law we will tell you to take advice.

Not A Certificate

No one issues a NIS2 certificate. What you get here is a defensible programme, the measures behind it, and the evidence to show a supervisor.

Built On ISO 27001

Most of the NIS2 measures map onto an ISO 27001 control set. If you already run ISO 27001, a large part of the work is done. Run both in the same workspace and the evidence serves both programmes.

What The Programme Covers

Thirty four obligations across the areas a supervisory authority examines, each assessed with your context and evidence guidance in plain English.

Governance And Accountability

Management body approval of the measures, oversight of implementation, and training for the directors themselves, not only the IT team. Under NIS2 accountability sits at the top.

Entity Classification And Registration

Whether you are an essential or an important entity, which member state supervises you, and the registration duties that follow from that.

Risk Management Measures

The ten measure areas the directive names directly: risk analysis, incident handling, business continuity, supply chain, secure acquisition and development, effectiveness assessment, cyber hygiene, cryptography, human resources and access control, and multi factor authentication.

Incident Reporting

The three stage clock: early warning within twenty four hours, notification with an initial assessment within seventy two hours, and a final report within one month. Built into the process before you need it.

Supply Chain Security

Direct suppliers and service providers are explicitly in scope, assessed individually rather than with one blanket questionnaire.

Recipient Communication

When a significant incident or threat affects the people using your service, they have to hear from you. Templates and trigger criteria, ready in advance.

Supervision Readiness

Essential entities face proactive inspection, important entities face supervision when something suggests a problem. Either way the evidence pack stays current.

Effectiveness And Review

The directive asks for policies on assessing whether your measures actually work, reviewed as your risk and your organisation change.

How The Programme Runs

The same guided journey as every framework in Auditara. The content changes; the method does not.

Step 1

Book The Call

Fifteen minutes with a PECB certified Lead Auditor and Lead Implementer. Your sector, your likely classification, the member states you operate in, and what is driving the deadline. Your workspace opens after the call.

Step 2

Answer The Intake

Plain English questions about your organisation. Your answers shape the programme, the measures and the documents that follow.

Step 3

Assess Every Obligation

Work through the obligations one at a time in guided mode, with guidance on each explaining what evidence looks like in practice.

Step 4

Remediate With Owners And Dates

Every gap becomes a tracked item with an owner, a priority and a target date. Recurring duties become tasks with reminders.

Step 5

Build The Reporting Capability

The incident runbook, the notification templates and the authority contacts exist before the clock ever starts, because twenty four hours is not long enough to build them.

Step 6

Stay Supervision Ready

Reviews come round on a schedule. The evidence a supervisor would ask for is a download rather than a fire drill.

Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.

Book A Call

Questions

Are we an essential or an important entity?

It depends on your sector and your size, with some entities included on criticality grounds regardless of size. The intake captures what is needed and we work it through on the call. The classification matters because it determines how you are supervised.

We are outside the EU. Does NIS2 reach us?

It can, where you offer services within the Union. Entities without an establishment in the EU may need to appoint a representative in a member state. The programme covers that assessment.

What actually has to happen in the first twenty four hours?

An early warning to the CSIRT or competent authority, flagging that a significant incident has occurred and whether it looks malicious or cross border. The fuller assessment follows at seventy two hours. The programme builds the runbook so the first hour is not spent deciding who submits it.

Does this cover our suppliers?

Yes. Supply chain security is a named measure, and the directive expects you to consider each direct supplier's own vulnerabilities and security practices rather than relying on a generic questionnaire.

We already have ISO 27001. How much of this is new?

The measures overlap heavily. What is usually new is the governance evidence at management body level, the specific reporting deadlines, and registration with your competent authority.

Who is accountable if we get this wrong?

NIS2 places accountability on the management body, including personal liability in some member states. That is why management approval and management training appear as obligations in their own right.

Ready To Get Started?

Book the call. Fifteen minutes, no obligation, and you leave with a route.

See all frameworks