Solutions · NIS2

NIS2 compliance, owned end to end

NIS2 raises the bar on cybersecurity risk management for essential and important entities across the EU, and it puts management bodies on the hook for it. Acuna runs the programme in one place: the risk-management measures, supply chain security, and incident reporting, each tied to a named owner and the evidence that proves it.

Risk measures and supply chain on one systemNIS2 mapped alongside DORA and ISO 2700150+ frameworks on one core

In short

NIS2 (Directive (EU) 2022/2555) requires essential and important entities to put in place cybersecurity risk-management measures, address supply chain security, and report significant incidents, with accountability sitting at management level. Acuna is a multi-framework GRC platform that operationalises those measures: it maps the NIS2 requirements once, keeps supply chain security tied to your vendor inventory, and ties every control to an owner and to evidence.

Turn a directive into a programme management can stand behind

NIS2 makes management bodies responsible for approving and overseeing cybersecurity risk-management measures. That changes the question from "do we have a policy" to "can leadership show the measures are real and maintained." The entities that handle NIS2 well are the ones where the measures, their owners, and their evidence live in one running system that leadership can see, rather than a set of documents that only exist for the audit.

One system for the whole NIS2 programme

NIS2 maps once across the four core panes, then supply chain security is carried by the extension your programme needs.

Map the NIS2 risk-management measures once and crosswalk them to what you already run, so NIS2 reuses the controls you built for ISO 27001 and DORA rather than duplicating them.

Turn the measures into controls with named owners, so the risk-management measures NIS2 requires have accountable people behind them, which is exactly what management-level responsibility depends on.

Keep the programme current with recurring tasks and checks, so the measures stay maintained between reviews rather than decaying after the initial project.

Produce the evidence and incident records a competent authority asks for, and the view leadership needs to sign off, as a live state rather than a scramble.

Framework-specific extension

NIS2 Article 21(2)(d) requires you to address supply chain security as part of your risk-management measures. Supplier Shield operationalises that: third-party assessment, monitoring, and the contractual controls that sit behind supply chain security. See third-party risk management for the full capability.

What it unlocks, and what waiting costs

What a running NIS2 programme unlocks vs What waiting costs
What a running NIS2 programme unlocksWhat waiting costs
Risk-management measures with named owners that leadership can actually oversee.Measures that exist on paper but have no owner and no maintenance cadence.
Supply chain security tied to your live vendor inventory, not a static supplier list.Supply chain security treated as a one-time questionnaire rather than an ongoing control.
NIS2 work that reuses your ISO 27001 and DORA controls rather than duplicating them.Management-level accountability with no running system to back it up.
Incident records and evidence that exist before the authority asks.

We are early, so we will not quote a customer count. The mechanism is the argument: when the measures, their owners, and their evidence live in one system, leadership oversight and a supervisory answer both become a view rather than a project.

The hesitations worth naming

GRC ROI is genuinely hard to prove precisely. Use your own numbers below to build the internal case. These inputs are yours; the output is your estimate, not ours.

Pipeline at risk

Enterprise deal value

typical affected deal, annualised

CHF 200K

CHF 10KCHF 1M

Deals blocked or slowed

per year, your estimate

3 deals

015

Security questionnaires

your team fills out, per month

5 / month

020 / month

Questionnaire overhead

Hours per questionnaire

across all people involved (SIG/CAIQ often run 6–12 hrs)

6 hrs

1 hr40 hrs

All-in hourly cost

fully-loaded: salary + overhead of the person filling it

CHF 125

CHF 25CHF 500
Pipeline at riskCHF 600'000
Questionnaire overhead / year (5×/mo × 6 hrs × CHF 125)CHF 45'000
Total identifiable costCHF 645'000

Acuna starts from

CHF 5'388 / year, all frameworks included

120×

your est. cost

These are your estimates, not ours. GRC ROI is notoriously hard to measure: most of the value is in deals not lost, incidents not escalated, and audits not rebuilt from scratch. Use this to structure the internal conversation, not as a number we stand behind.

Built by people who ran the programmes

Acuna is built and operated by an established Swiss GRC group led by practitioners with decades of combined experience in cybersecurity, audit, and governance. The platform models how a mature risk-management programme actually runs.

  1. Supply chain security ties to your live vendor inventory.

  2. Controls reuse across NIS2, DORA, and ISO 27001 on one core.

  3. Priced per organisation, so every owner and reviewer is included.

  4. Data hosted in Switzerland and the EU.

NIS2: common questions.

Related answers

Questions practitioners ask.

What is NIS2 and who does it apply to?

NIS2 (Directive (EU) 2022/2555) is the EU directive on cybersecurity for essential and important entities. It expands the scope of NIS1, introduces stricter security requirements under Article 21, and mandates incident reporting within 24 hours (early warning), 72 hours (notification), and one month (final report). Essential entities include energy, transport, banking, health, water, and digital infrastructure. Important entities cover postal, waste, chemicals, food, manufacturing, and digital providers with 50+ employees or EUR 10M+ turnover. Acuna maps NIS2 articles to controls, manages supply chain risk, and tracks incident reporting deadlines.

Who does NIS2 apply to?

NIS2 (Directive (EU) 2022/2555) applies to public and private organisations that operate in one of the sectors listed in its annexes and meet a size threshold, generally medium-sized and larger organisations. In-scope organisations are classified as either essential entities or important entities, a distinction that determines the intensity of their supervision and the penalties they face, not whether the obligations apply. Because NIS2 is a directive, the precise scope is set by each member state's national transposition, so the exact boundaries can vary by country. NIS2 splits in-scope organisations into two tiers. Essential entities are the larger organisations in the highest-criticality sectors; important entities are the rest of those in scope. Both tiers must meet the same core risk-management and reporting obligations. The difference is supervisory: essential entities face proactive, ex-ante supervision, while important entities are supervised reactively, ex-post, typically after an incident or evidence of non-compliance. Penalty ceilings also differ between the tiers. NIS2 organises covered sectors into two annexes. Annex I lists sectors of high criticality such as energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Annex II lists other critical sectors such as postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers, and research. Whether you are essential or important depends on the combination of your sector and your size. As a general rule, NIS2 applies to medium-sized and larger organisations in the covered sectors, using the EU definition of enterprise size. But there are important exceptions where the directive applies regardless of size, for certain types of entity whose disruption would have outsized effect, so the size threshold is a starting point, not a complete test. National transposition can add further specifics. Scope is not a one-time determination. An organisation grows across a threshold, enters a covered sector through an acquisition, or its member state transposes the directive with a wider net than expected. Treating scope as settled is how organisations discover, late, that they were in scope all along.

What is the difference between NIS2 and DORA?

NIS2 and DORA are two EU frameworks for cybersecurity and operational resilience that came into force around the same time and overlap heavily, but they are not interchangeable. NIS2 (Directive (EU) 2022/2555) is a cross-sector cybersecurity directive covering many industries; DORA (Regulation (EU) 2022/2554) is a finance-specific regulation for digital operational resilience. Where both could apply to the same organisation, DORA generally takes precedence for ICT risk in financial services as the more specific law, the lex specialis principle. A financial entity can therefore be in scope for both, with DORA governing its ICT risk and NIS2 relevant to the extent DORA does not cover. The two differ on instrument, scope, and specificity. NIS2 is a directive, so it is transposed into each member state's national law and its details can vary by country. DORA is a regulation, so it applies directly and uniformly across the EU without transposition. NIS2 spans many sectors; DORA is confined to financial entities and their ICT providers. DORA is also more prescriptive on ICT specifics, such as the register of information and threat-led penetration testing, than NIS2's more general risk-management measures. Where a financial entity would fall under both, DORA is treated as the more specific regime for its ICT risk, and it prevails on the matters it covers. NIS2 recognises this relationship, so the two are designed to fit together rather than duplicate. In practice, a bank manages its ICT risk under DORA and does not also apply NIS2's general measures to the same ground. For a financial entity in scope for both: determine your DORA obligations for ICT risk first, since they are the more specific and prescriptive. Then confirm what, if anything, NIS2 adds beyond DORA's coverage for your organisation, which depends partly on your member state's transposition. The efficient path is to map the shared requirements once, as most of the risk-management and supply-chain substance is common, and only maintain the genuinely distinct pieces separately.

How does NIS2 incident reporting work?

Under Article 23 of NIS2, essential and important entities must report significant incidents to their national CSIRT or competent authority in stages: an early warning within 24 hours of becoming aware of the incident, a fuller incident notification within 72 hours, and a final report within one month of that notification. An incident is significant if it has caused or is capable of causing serious operational disruption or financial loss, or has affected other people through considerable material or non-material damage. These windows are fixed in Article 23(4) of the directive, so the 24-hour, 72-hour, and one-month deadlines are the same in every member state. What national transposition changes is the authority or CSIRT you report to and the reporting mechanics, so confirm your reporting route for the country where you operate. The staged structure exists so authorities get an early signal quickly, then a complete picture as the situation resolves. The reporting clock only starts once you determine an incident is significant, which is why fast, accurate classification matters as much as the reporting itself. NIS2 sets out when an incident is significant, based on the disruption or loss it causes or could cause, and the harm to others. National transposition and guidance sharpen these thresholds. Classifying correctly is the gate: misjudge it and you either over-report routine events or, worse, miss the clock on a reportable one. Reporting is a sequence, not a single filing: an early warning within 24 hours of awareness, a notification within 72 hours with a fuller assessment, and a final report within one month of that notification covering root cause and mitigation. If the incident is still open at one month, you file a progress report and a final report once it is resolved. The timeframes come from Article 23(4) of the directive and do not change by member state; national implementation sets the authority you report to and the mechanics, not the windows.

What should be on a NIS2 compliance checklist?

A NIS2 compliance programme comes down to a handful of things done properly: confirm whether you are in scope and as which tier, put in place the Article 21 risk-management measures, stand up incident detection and staged reporting, address supply chain security, and get the management body to approve and oversee it all. The checklist below covers the core areas any programme must address; it is not a substitute for your member state's transposed requirements, which add the specifics. Determine scope and tier: confirm whether you are in scope, in which Annex I or II sector, and whether you are an essential or an important entity. Register with your authority: meet the registration and information obligations your member state's transposition sets for in-scope entities. Implement the Article 21 measures: put in place the ten categories of risk-management measures, covering risk analysis and security policy, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, policies to assess effectiveness, basic cyber hygiene and training, cryptography, human resources and access control, and multi-factor authentication and secured communications. Stand up incident reporting: build the detection, classification, and staged reporting process required under Article 23, and know who your CSIRT or competent authority is. Address supply chain security: assess and manage the security of your direct suppliers and service providers, as Article 21 requires. Secure management-body approval and oversight: under Article 20, the management body approves the risk-management measures, oversees them, and can be held liable. Training for management is part of this. Maintain evidence: keep the records that show the measures are real and operating, because supervision, proactive for essential entities, will look for them.

Why does NIS2 vary by country?

NIS2 is a directive, not a regulation, which means it does not apply directly. Instead, each EU member state must transpose it into national law, and it is that national law you actually comply with. The transposition deadline was 17 October 2024, but member states have transposed at different speeds and with different specifics, so the precise obligations, the designated authority, and some thresholds can vary depending on where you operate. For a multi-country organisation, this is the defining practical feature of NIS2. This is the single biggest difference in character between NIS2 and DORA. DORA, a regulation, is uniform across the EU. NIS2, a directive, is a common baseline that each country implements in its own law, so complying with NIS2 really means complying with the NIS2 transposition in each country where you are in scope. A directive sets the objectives every member state must achieve but leaves the form and method to national governments. That allows NIS2 to fit each country's existing legal and regulatory structures, but it means the operative detail lives in national law. Two organisations in the same sector in different member states can face variations in registration, reporting specifics, and supervisory approach. Member states were required to adopt and publish their transposing measures by 17 October 2024. In practice, transposition has been uneven. Because the position by country changes over time, confirm the current status and the operative national law for each member state where you are in scope rather than relying on a general statement. For a single-country organisation: identify your national transposing law and your competent authority, and comply with that. For a multi-country organisation: map the common NIS2 baseline once, then track the national deltas per member state. The baseline is largely shared; the variation is in the specifics, which is a manageable overlay rather than a separate programme per country.

Get started

Run NIS2 as a programme, not a policy binder

See how the measures, supply chain security, and evidence run in one place.