Synapse Consulting
EN · FR
Test access Book a demo
NIS2 COMPLIANCE

NIS2, from obligation to evidence

Who the directive covers, the ten measures Article 21 actually names, the reporting clock in Article 23, and what a supervisor asks you to produce. Written by the consultants who run these assessments.

Book a demo Request a test

LAST UPDATED · SYNAPSE CONSULTING, BRUSSELS

NIS2 (Directive (EU) 2022/2555) does not prescribe tools. It prescribes outcomes, and it prescribes evidence. Almost every practical difficulty organisations run into comes from that second word: they have done the work, and they cannot show it.

Am I in scope, and as what?

Two questions, in order. First, is your sector listed in Annex I (sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space) or Annex II (other critical sectors: postal and courier, waste management, chemicals, food, manufacturing, digital providers, research)? Second, how large are you?

The size test uses the standard EU definition. A large entity has 250 employees or more, or a turnover above €50m together with a balance-sheet total above €43m. A medium entity has at least 50 employees, or a turnover and balance-sheet total above €10m.

  ANNEX I ANNEX II
LargeEssentialImportant
MediumImportantImportant
Small / microOut, unless an exception appliesOut, unless an exception applies

The exceptions matter more than the table. Some entities are in scope whatever their size: DNS service providers, TLD name registries, qualified trust service providers, providers of public electronic communications networks, certain public administration entities, and any organisation a Member State designates because it is the sole provider of a service critical to societal or economic activity. If you are small and any of those describes you, you are in.

The distinction between essential and important changes how you are supervised, not what you must do. The measures are the same. Essential entities face proactive supervision, meaning inspections and audits can arrive unannounced. Important entities are supervised reactively, after evidence of a problem.

What NIS2 actually requires

  • Article 20, management bodies must approve the risk-management measures, oversee their implementation, and can be held personally liable for failing to do so. They must also follow training, and are expected to offer similar training to staff. Oversight of this kind needs one current view of the risk position, not a quarterly slide.
  • Article 21, appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, covering the ten areas listed below, plus an assessment of whether they actually work.
  • Article 23, notification of significant incidents to the CSIRT on a staged clock, which presupposes a defined and rehearsed incident process.
  • Articles 32–33, supervisory inspections, security audits and requests for information. The authority can require you to demonstrate implementation, and can order an audit at your expense.

The ten measures of Article 21(2)

This is the operative list. Every national transposition builds on it, and every audit question maps back to one of these ten points.

  1. Policies on risk analysis and information system security.
  2. Incident handling.
  3. Business continuity, including backup management, disaster recovery and crisis management.
  4. Supply-chain security, including the security aspects of the relationship with each direct supplier and service provider.
  5. Security in acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure.
  6. Policies and procedures to assess the effectiveness of the risk-management measures.
  7. Basic cyber hygiene practices and cybersecurity training.
  8. Policies on the use of cryptography and, where appropriate, encryption.
  9. Human resources security, access control policies and asset management.
  10. Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications, where appropriate.

Point four is where most programmes are weakest, and it is also where supervisors have been most curious. It requires a view of your direct suppliers, their criticality to you, and what you have actually assessed about each one. Our page on third-party risk management covers what that register looks like in practice.

Point six is the one organisations skip. Having measures is not enough; you must have a documented way of judging whether they are effective, and a record of having done so.

The reporting clock in Article 23

An incident is significant when it has caused or is capable of causing severe operational disruption or financial loss to you, or when it has affected or is capable of affecting others through considerable material or non-material damage. Note the words capable of: the threshold is not realised harm, which is why the assessment itself needs to be written down rather than argued about at 2am.

WHEN WHAT
24 hoursEarly warning to the CSIRT. Flag whether you suspect unlawful or malicious acts, and whether cross-border impact is possible.
72 hoursIncident notification. Update the early warning with an initial assessment of severity, impact and, where available, indicators of compromise.
On requestIntermediate report on status updates, whenever the CSIRT or competent authority asks.
1 monthFinal report: detailed description, type of threat and root cause, mitigation applied, cross-border impact. If the incident is still ongoing, a progress report instead, and the final report within one month of closing it.

The clock starts when you become aware of the incident, not when you finish diagnosing it. In practice this means the significance assessment and the escalation path have to be decided in advance, on paper, with names attached.

Penalties and management liability

Essential entities face administrative fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4%, whichever is higher.

The financial figure is not the part that changes board conversations. Supervisory authorities can also suspend a certification or authorisation covering part of your services, and can temporarily prohibit a named individual from exercising management functions in an essential entity. Combined with Article 20, that is the first time EU cybersecurity law reaches an individual director personally, which is why the board's approval of the risk-management measures needs to be a dated, minuted, traceable act rather than an assumption.

NIS2 in Belgium: the CCB and CyberFundamentals

We are based in Brussels, so this is the transposition we know best, and it is one of the more advanced in the Union. Belgium transposed NIS2 through the Law of 26 April 2024, in force since 18 October 2024, together with the Royal Decree of 9 June 2024 which designates the Centre for Cybersecurity Belgium as national cybersecurity authority and national CSIRT.

In-scope entities register through the Safeonweb@Work portal. Alongside ISO/IEC 27001, the Royal Decree recognises the CCB's own framework, CyberFundamentals (CyFun®), as a route to demonstrating conformity. CyFun is tiered, Small, Basic, Important and Essential, with the control set growing at each level, and it has been widely adopted precisely because it is more proportionate than ISO 27001 for a mid-sized Belgian operator.

Two practical consequences. First, if you are an essential entity, conformity has to be demonstrated on the CCB's timetable, not asserted, and a verification against the Essential level is an evidence exercise, not a policy exercise. Second, NIS2 propagates down the supply chain: the CCB encourages organisations that supply in-scope entities to reach at least the Basic level, which means suppliers well below the size thresholds are being asked for proof by their customers.

The Belgian timetable has moved several times. Check the current registration and conformity-assessment deadlines directly on ccb.belgium.be before you plan against them, and talk to us if you want a gap analysis against the CyFun level that applies to you.

From obligation to evidence

Every obligation above resolves to the same practical need: a maintained record of your risks, their owners, their treatment and their history, plus a current view of the suppliers you depend on. That is what a supervisor asks to see. Here is the mapping we use on engagements.

NIS2 OBLIGATION → EVIDENCE DEMANDED → SYNAPSERM MODULE
OBLIGATION WHAT YOU MUST PRODUCE IN SYNAPSERM
Art. 20, board oversightA dated record of the board approving the measures, and one current view of the risk position it approved.Scored risk register with approval trail and review dates
Art. 21(2)(a), risk analysisRisks identified, scored on a defensible scale, with named owners and treatment decisions.Assessment engine, configurable scales
Art. 21(2)(d), supply chainA supplier inventory tiered by criticality, with what you assessed and when.Third-party register and questionnaire workflow
Art. 21(2)(f), effectivenessEvidence that you tested whether the measures work, and what you did about the answer.Control mapping with test results and findings
Art. 23, notificationA defined significance test, an escalation path with names, and a record of what was sent when.Incident register linked to the affected assets and risks
Art. 32–33, inspectionEverything above, on demand, in a form an auditor can read without your help.Immutable history, read-only auditor role, export

The pattern in the middle column is the point. Nothing there is exotic. What makes it hard is keeping it true eighteen months after the consultant leaves, which is the problem SynapseRM was built to solve, we built it for our own engagements first.

Questions we get asked

Does ISO 27001 make me NIS2 compliant?

No, but it covers a large part of the ground. ISO 27001 gives you the management system, the risk process and most of the Article 21 measures. What it does not give you is the incident notification workflow with its 24 and 72 hour deadlines, the management-body approval and training duties of Article 20, or the registration obligation. In Belgium, the Royal Decree recognises both ISO 27001 and CyberFundamentals as reference frameworks.

We are below the size thresholds. Can we ignore NIS2?

Rarely, in practice. Even when you are out of direct scope, your in-scope customers are obliged under Article 21(2)(d) to secure their supply chain, and they discharge that obligation by asking you for evidence. A growing share of the assessments we run are for companies that are not themselves regulated and are being assessed by three of their clients at once.

Is a spreadsheet enough for the risk register?

For the first assessment, often yes. The problem is Article 21(2)(f) and Articles 32–33 together: you have to show effectiveness over time and produce history on demand. A spreadsheet has no history, no owner accountability and no read-only auditor view, so what a supervisor receives is a snapshot you assembled last week rather than a record you maintained.

We operate in several Member States. Which transposition applies?

Generally the law of the Member State where you are established, with specific rules placing certain digital providers under the jurisdiction of their main establishment. The measures converge because they all derive from Article 21, but registration, reporting channels and conformity routes differ by country. Build one control set, then map it to each national framework rather than running parallel programmes.

How long does a first NIS2-aligned risk register take?

On our engagements, four to six weeks for a mid-sized entity, of which most is scoping and interviews rather than tooling. The longer pole is almost always the third-party inventory, because nobody owns the complete supplier list at the start.

Go deeper

The risk register every framework assumes

NIS2, DORA and ISO 27001, article by article.

Third-party risk management

Supplier tiering and the DORA register of information.

SynapseRM platform

The integrated cyber risk and TPRM platform.

See it on your own scope.

Bring one real supplier or one real system. In 45 minutes we run it through the Article 21 mapping and you keep the output.

Book a demo

This page summarises Directive (EU) 2022/2555 and its Belgian transposition for general information. It is not legal advice. Where a national transposition differs from the directive, the national text applies.