Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

REGULATION · NIS2

NIS2 compliance you can demonstrate, not just declare.

NIS2 makes management personally accountable for cybersecurity risk management. Mindlapse turns each obligation into controls verified continuously against live evidence, the posture a supervisor actually asks to see.

WHAT IS NIS2?

The EU’s baseline cybersecurity law, with teeth.

NIS2 (Directive (EU) 2022/2555) is the European Union’s framework for the cybersecurity of essential and important entities. It replaces the 2016 NIS Directive, dramatically widening scope to 18 sectors, from energy, transport and health to digital infrastructure, manufacturing and public administration.

It requires in-scope organizations to adopt risk-management measures (governance, incident handling, business continuity, supply-chain security, vulnerability handling, encryption, access control…), to report significant incidents on strict timelines, and it makes management bodies explicitly responsible, with sanctions up to 10 M€ or 2% of worldwide turnover for essential entities.

Transposition was due by 17 October 2024 and is in force in most member states; supervision and enforcement are ramping up across the EU, France among the late transposers (see the FAQ). The practical question is no longer “are we in scope?” but “can we prove our measures actually operate?”

KEY OBLIGATIONS

What NIS2 actually asks of you.

Article 21 defines the minimum risk-management measures; Article 23 the incident-reporting discipline. In practice, five workstreams dominate.

Governance & accountability (Art. 20)

Management bodies must approve risk-management measures, oversee their implementation and be trained on cyber risk. Accountability is personal.

Risk-management measures (Art. 21)

Policies on risk analysis, incident handling, continuity, supply-chain security, secure development, effectiveness assessment, cryptography, access control and MFA.

Incident reporting (Art. 23)

Early warning within 24 hours, incident notification within 72 hours, final report within one month, with intermediate updates on request.

Supply-chain security

Assess and manage the security of direct suppliers and service providers, including their development practices and your contractual leverage.

Proof of effectiveness

Policies must be assessed for effectiveness. A binder of PDFs is not effectiveness. Operating, verifiable controls are.

HOW MINDLAPSE HELPS

From articles to verified controls.

NIS2 obligations are pre-mapped to controls in the platform; Ernest keeps their state verified against live signals.

Art. 20: management accountability

The Cyber Cockpit gives executive bodies a verified, board-readable posture (measures, state, exposure) generated from evidence, not assembled slides.

Art. 21: risk-management measures

Smart Compliance maps NIS2 to your control set (alongside ISO 27001 and others) and monitors each control continuously with sourced verdicts.

Art. 21(2)(d): supply-chain security

TPRM runs proportionate, context-aware vendor assessments with contradiction detection and a living risk network of your dependencies.

Art. 23: incident reporting readiness

Risk Intelligence keeps scenarios, owners and escalation paths current, so the 24h/72h clock starts with context instead of chaos.

Effectiveness assessment

Every control carries dated, verifiable evidence and an audit trail, demonstrating operation over time, exactly what supervisors request.

RESOURCE · NIS2

NIS2 readiness guide

What the directive actually requires, what evidence holds up under scrutiny, and where documented declarations stop being enough.

Get the guide

NIS2 - FAQ

Frequently asked, directly answered.

Who falls under NIS2?

Essential and important entities across 18 sectors (Annexes I & II): energy, transport, banking and financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, space, plus postal services, waste, chemicals, food, manufacturing, digital providers and research. As a rule, entities with 50+ employees or €10M+ turnover in those sectors are in scope; some are included regardless of size.

What are the NIS2 incident-reporting deadlines?

An early warning to your CSIRT/authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month, with progress updates on request.

What sanctions does NIS2 carry?

Up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and up to €7 million or 1.4% for important entities, plus management liability and possible temporary bans on exercising managerial functions.

Is NIS2 applicable in France?

Not yet as national law. NIS2 was due for transposition across the EU by 17 October 2024. As of September 2026 the French transposition law (the projet de loi résilience, which also recasts the OIV regime) is still before Parliament, and the European Commission referred France to the Court of Justice in July 2026. Entities that will be essential or important should already run the Article 21 measures: the directive’s obligations are known, only the national supervision regime is pending.

How does Mindlapse shorten the path to NIS2 compliance?

NIS2 requirements arrive pre-mapped to controls shared with your other frameworks, so existing measures count immediately. Continuous verification then replaces the annual evidence hunt: your NIS2 posture is current every day, with proof attached.

NIS2, UNDER CONTROL

See your NIS2 posture, verified, today.

Bring your scope; we map it live against Article 21 and show you the gaps with evidence.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.