How to Find the NIS2 Full Text on EUR-Lex (And the 5 Articles That Actually Matter)
The NIS2 full text is free on EUR-Lex — here are the exact links, the 9-chapter structure, and the 5 articles that cover 90% of your compliance obligations.
NIS2 compliance guides and resources
The NIS2 full text is free on EUR-Lex — here are the exact links, the 9-chapter structure, and the 5 articles that cover 90% of your compliance obligations.
How NIS2 classifies essential vs important entities — supervision regimes, fine ceilings, and the Article 32(5) management rules most compliance guides miss.
What does NIS2 Article 21(2)(i) require for access control and HR security? Full breakdown of CIR Annex sections 10, 11, and 12: least privilege, JML process, privileged access, asset management, and the templates you need.
Every software deployment, system acquisition, and configuration change in scope of NIS2 now carries legal weight. Article 21(2)(e) of Directive (EU) 2022/2555 requires essential and important entities to implement security across the complete lifecycle of network and information systems —…
Ireland hosts the EU headquarters of Google, Meta, Microsoft, Apple, and dozens of other technology companies — making the Irish NCSC one of the most consequential NIS2 supervisory authorities in Europe. This guide covers Ireland’s transposition law, competent authorities, the lead-authority jurisdiction rule for multinationals, and what Irish-registered entities must do to comply.
Multi-factor authentication (MFA) is one of the few specific technical controls explicitly named in the NIS2 Directive itself — not just in the implementing regulation. Article 21(2)(j) of Directive 2022/2555 places MFA, continuous authentication, and secured communications at the same…
Commission Implementing Regulation (EU) 2024/2690 specifies exact technical requirements for 11 digital infrastructure entity types. Complete guide: all 13 Annex sections, incident thresholds, and compliance roadmap.
NIS2 Article 20(2) requires every management body member to personally undergo cybersecurity training. Article 21(2)(g) mandates staff awareness programmes. This guide maps both requirements to practical implementation steps.
What does NIS2 require for business continuity? Article 21(2)(c) and CIR 2024/2690 Annex 4 requirements mapped to practical steps for SMEs.
What does NIS2 require for supply chain security? Article 21(2)(d) breakdown, three-tier supplier classification, six mandatory contract clauses from CIR 2024/2690, and a step-by-step monitoring framework.