NIS2
NIS2 applies to essential and important entities as transposed into member-state law. The catalog covers the logging-and-monitoring measure of Art 21(2) and the staged reporting of Art 23: early warning, incident notification, final report.
| Registry id | nis2 |
| Kind | regulation |
| Jurisdiction | EU |
| Instrument | Directive (EU) 2022/2555 (NIS2) |
| Catalog versions | 2026-09 from 2024-10-18 (current) — As transposed from 18 October 2024 |
| Verified against instrument | no — see the banner above |
Roles (frameworks.nis2.entity_type) |
essential_entity, important_entity |
| Incident deadline rules | early_warning: 1 day, notification: 3 days, final: 30 days |
| Retention floors | none at classification level |
| Obligations | 2 |
Transposition differs between member states — check the national law that applies to you.
Deadline rules
Section titled “Deadline rules”Staged rules: every stage applies to a qualifying incident. The earliest stage is the report, satisfied by reported_at; later stages are follow-ups shown on the incident and satisfied by closing it.
| Rule | Deadline from became_aware_at |
|---|---|
early_warning |
1 day |
notification |
3 days |
final |
30 days |
Deadlines are computed and shown, never enforced — see incidents.
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
Cybersecurity risk-management measures — logging and monitoring
Section titled “Cybersecurity risk-management measures — logging and monitoring”art21-2-logging-monitoring · Art 21(2) · applies from 2024-10-18
Essential and important entities take measures including incident handling, logging and monitoring of network and information systems. Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every governed action produced a sealed record, including refusals. | recomputed | records.every_verdict_sealed |
Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately. |
| The tenant log’s tree heads covering the window were countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
Shows the monitoring ran; what a human did with its findings is shown in the inbox trail. |
Reporting obligations
Section titled “Reporting obligations”art23-incident-reporting · Art 23 · applies from 2024-10-18
Significant incidents are notified to the CSIRT or competent authority in stages (early warning 24 h, notification 72 h, final report one month). Written from public summaries of the instrument; check the published text before relying on this. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
Shows incidents someone entered; an incident nobody recorded cannot be counted. |
| Significant incidents received an early warning within 24 hours. | recomputed | incidents.reported_within_deadline {"framework": "nis2"} |
Shows the early-warning stage against the reported time; later stages are shown on the incident, not enforced. National law may set other deadlines. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

