Compliance / NIS2
NIS2 asks essential and important entities to take a set of cybersecurity measures and to report significant incidents in stages. RegNext quotes each measure, tests each incident against the directive’s conditions and dates every report — and if you are under DORA, DORA comes first.
What it asks
NIS2 is a directive: each country writes it into its own law. Here is what the directive itself asks — and what RegNext does about it.
The management body approves the cybersecurity risk-management measures, oversees how they are carried out and follows training.
Article 20The approval the directive expects from your management body is on your list of what to have in writing, quoted from the text.
An all-hazards set of measures: risk analysis, incident handling, business continuity, supply-chain security, secure development, access control, encryption, training and more.
Article 21Each measure quoted, with the document that covers it — plus a starter set of controls and readiness questions drawn from the directive.
Supply-chain security, including the security of your relationships with each direct supplier and service provider.
Article 21(2)(d)A NIS2 section on each ICT supplier — covered, partial, missing or not applicable — on the same record you use for DORA and GDPR.
Significant incidents are reported in stages: an early warning, an incident notification and a final report.
Article 23The directive’s significance test, a verdict a person confirms, and the early warning, the notification and the final report dated. Under DORA, DORA’s reporting applies instead.
Significant incidents
Answer the directive’s two conditions — or, for providers of digital infrastructure, the criteria set for them. RegNext proposes the verdict, a person confirms it, and the early warning, the notification and the final report are dated. A financial entity under DORA reports under DORA instead.
Risk-management measures
Article 21 lists the measures every entity must take, from risk analysis and incident handling to encryption and access control. RegNext quotes each one, you mark the document that covers it, and the gaps stand out — next to the approval the directive expects from your management body.
Supply chain
Each ICT supplier gets a NIS2 section for the supply-chain measure — covered, partial, missing or not applicable — on the same record you use for DORA, GDPR and the AI Act.
Questions
No. You set NIS2 in scope for your firm. Whether you are essential or important depends on your sector, your size and your country’s law.
The requirements come from the directive itself. How your country transposed it — its authority, its forms, any extra rules — is still yours to check.
For a financial entity under DORA, DORA’s rules on ICT risk management and incident reporting apply instead, and RegNext doesn’t ask you to report twice.
No. It dates each stage and shows what is due next. Reporting forms differ from country to country, and you file through your authority’s channel.
Recorded once
A supplier on your NIS2 list may also be a processor under GDPR or an AI provider under the AI Act. RegNext records it once and shows it under every framework that applies.
Major incidents, critical functions and the register of information.
DORA AI ActAn inventory, a risk class you confirm and the duties that follow.
AI Act GDPRRecords of processing, DPIA screening, requests and breaches.
GDPR OverviewRisks, controls, policies, incidents and suppliers, shared across every framework.
Compliance
Explore how RegNext supports regulatory intelligence and compliance execution in your industry.