Abstract network of glowing blue nodes representing recurring NIS2 compliance automation cycles

NIS2 Compliance Automation: 30 Recurring Duties and the 17 Triggers a Calendar Will Miss

Search for NIS2 compliance automation and every result sells you continuous monitoring. The binding text points the other way. Commission Implementing Regulation (EU) 2024/2690 says monitoring shall be automated and carried out "either continuously or in periodic intervals, subject to business capabilities" [1] — and the Directive itself never once tells you to do anything on a schedule.

That gap decides what a workflow tool is actually for. Ongoing NIS2 compliance is not one long stream of telemetry. It is a set of recurring duties, each fired by a trigger, and the Implementing Regulation writes 30 of those triggers in a form no dashboard reads: at planned intervals, with the interval left for you to choose. This guide counts them, splits them by trigger type, and works through six ongoing workflows where automation earns its cost.

Does this apply to you — and who picks your intervals?

In plain terms: the detailed cadence rules bind eleven categories of digital provider. If you are not one of them, no EU instrument sets a review interval for you at all, and the interval you write down becomes the standard you are measured against.

Article 1 of the Implementing Regulation names its subjects exactly: DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers [1]. Every other essential or important entity is bound by Article 21(2) directly [2], and the Annex is an interpretive benchmark, not a checklist.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Your situation Bound by the CIR Annex? Where your cadences actually come from
One of the 11 categories named in CIR Article 1 Yes, directly 30 "at planned intervals" clauses plus three "at least annually" floors. You choose every interval and document it.
Essential or important entity in any other sector No Article 21(2) binds you; no EU-level review cadence applies at all. Your own documented interval is the only benchmark an auditor has.
Any entity, plus national transposition Varies National law can add hard clocks the EU text does not contain. Germany’s BSI, for example, requires registration changes to be submitted "unverzüglich, spätestens nach zwei Wochen" — without undue delay, at the latest after two weeks [4].

The consequence for automation is uncomfortable: for most entities the tool cannot import a compliance calendar from the regulation, because the regulation does not contain one. Somebody decides the intervals first, and that decision is the artefact an auditor asks to see.

NIS2 sets no schedule. The Implementing Regulation sets all of it

These are counts taken over the full text of both instruments as published on EUR-Lex, not estimates.

Phrase Directive (EU) 2022/2555 CIR (EU) 2024/2690
"at planned intervals" 0 30
"at least annually" 0 3
"annually" 0 3 (the same three)
"without undue delay" 23 2

Two instruments, two different clocks. The Directive is written in event time — something happens, and you act without undue delay, or inside 24 hours, 72 hours and one month [2]. The Implementing Regulation is written in interval time. The Directive’s only two uses of "periodic" are not entity duties at all: the Commission reviewing the Directive, and periodic penalty payments under Article 34(6) [2].

The three annual floors are worth naming because they are the only fixed cadence in the entire framework: point 1.1.2 (the security policy, reviewed by management bodies), point 2.1.4 (risk assessment results and the risk treatment plan) and point 10.1.3 (the assignment of personnel to security roles) [1]. Everything else recurs at an interval you set.

Split the 30 by trigger, and half of your automation problem disappears

Reading all 30 clauses in full produces a split that no compliance platform’s onboarding wizard reflects.

Trigger shape Count Annex points Can a scheduler fire it?
Interval only 11 3.5.5, 3.6.3, 6.2.4, 6.5.3, 6.10.2(b), 6.10.4, 8.1.3, 9.3, 10.1.3, 10.2.3, 11.6.4 Yes, completely
Interval + organisational change 2 11.2.3, 11.3.3 Only if wired to HR or identity events
Interval + significant incidents or significant changes to operations or risks 17 1.2.6, 2.1.4, 2.2.3, 2.3.4, 3.1.3, 4.1.4, 5.1.6, 6.1.3, 6.3.3, 6.4.4, 6.7.3, 6.8.3, 7.3, 10.4.2, 11.1.3, 12.2.3, 12.3.3 No — the second limb needs a judgement first

A cron job discharges 11 of the 30 outright. Two more need a feed from your joiner-mover-leaver process. The remaining 17 carry a second limb that fires on an event nobody can schedule, and no tool can classify for you: whether a change to your operations or risks was significant. ENISA’s own guidance is explicit that these events do not fire automatically — the occurrence of an indicative event "does not automatically require a covered entity to update its policy"; it should instead be considered through the risk-assessment process [3]. That is the whole automation boundary in one sentence.

Six ongoing workflows worth automating

Each of these is a recurring compliance workflow, not a security control. The question is not whether a scanner finds vulnerabilities, but whether reviewing, deciding and recording reaches the right person on the right trigger. The separate question of which of the ten Article 21(2) measures automate well as controls is covered elsewhere.

Workflow Trigger in the text What a tool genuinely does What stays human
1. Evidence collection and retention 3.5.4 record evidence; 6.10.2(b) record scan evidence at planned intervals; 1.1.1(h) list documentation and retention duration Pulls artefacts on a schedule, timestamps them, applies the retention clock you defined Defining the retention periods — the Annex sets none, anywhere
2. Access-rights recertification 11.2.3 and 11.3.3 review at planned intervals and modify on organisational change; 11.5.4 deactivate unneeded identities without delay Generates review campaigns, routes to asset owners, records approvals and revocations Deciding whether an exception is justified; approving shared identities under 11.5.3
3. Policy review and management approval 1.1.2 at least annually and on significant incident or change; 1.2.6 roles and responsibilities Schedules the cycle, tracks versions, chases sign-off, stores the documented result The review and approval itself: 1.1.2 assigns both to management bodies, and under Article 20(1) they can be held liable
4. Supplier register and contract review 5.2 keep the supplier registry up to date; 5.1.6 review at planned intervals and on significant change; 5.1.7 monitor SLA reports Keeps the registry current from procurement data, tracks contract dates, flags SLA breaches Point 5.1.7(c): assessing the need for unscheduled reviews and documenting the finding
5. Risk-treatment tracking 2.1.2(h) continuously monitor implementation of risk treatment measures; 2.1.2(i) who implements and when Tracks each measure to an owner and a due date, escalates slippage, feeds the 2.2.1 report to management bodies Accepting residual risk with documented reasoning, under 2.1.2(j)
6. The "where appropriate" justification register CIR Article 2(2): where a hedged requirement is judged not appropriate, applicable or feasible, the entity "shall in a comprehensible manner document its reasoning" Holds each justification against its Annex point, re-surfaces it for review when the linked risk changes Writing the reasoning, and deciding when it has stopped being true

Two deserve a note. First, ENISA’s 170-page implementation guidance recommends automating a process in exactly two places, and both are access rights: "Establish and follow a process for requesting and approving access, preferably automated", and "Establish and follow a process, preferably automated, for revoking access to assets" [3]. If you automate one workflow this year, the EU agency that wrote the guidance has already told you which one.

Second, the justification register in row 6 is the workflow the tooling market ignores. The Annex uses "where appropriate" 48 times, "where applicable" 10 times and "to the extent feasible" four times [1]. Each is a decision you are entitled to make, and each one you decide against triggers the binding documentation duty in Article 2(2). Those written reasons are artefacts with an expiry date, and no standard control library tracks them.

One thing spans the whole table: under point 3.2.4, one of the examples of evidence ENISA lists is "Existing workflows that trigger event reporting" [3]. The workflow is more than the mechanism that produces evidence — here, EU guidance treats the workflow itself as the evidence.

Three things no workflow engine can do for you

Vendors are rarely wrong about what their software does. They are usually silent about what the text reserves for a person.

The second limb of 17 clauses. A scheduler fires on time. It cannot decide that a cloud migration, a new subsidiary or a near-miss counts as one of the "significant changes to operations or risks" the Annex names 21 times [1]. Get that call wrong and the interval you did honour stops mattering, because the event review never opened.

Independent review. Point 2.3.2 requires reviews by people "with appropriate audit competence", and where they are your own staff, "the persons conducting the reviews shall not be in the line of authority of the personnel of the area under review" [1]. That is an organisational-chart requirement. No integration satisfies it.

Management-body approval. Point 1.1.2 puts the annual policy review in the hands of management bodies, and Article 20(1) of the Directive provides that those same people can be held liable for infringements of Article 21 [1][2]. Software can chase the signature. It cannot supply it, and it cannot transfer the liability that comes with it.

ENISA also anticipates that your automation will fail. Its training guidance says staff should be trained to "verify and report out-of-date software or any failures in automated processes and tools", including notifying IT personnel of such failures [3]. A recurring workflow that silently stops running is worse than a manual one that visibly slips, because the register keeps looking green.

Platform, ticketing system, or a register — what each actually buys you

Nothing in the Directive or the Implementing Regulation names a product category. ENISA lists SIEM, EDR and XDR as things to consider, and for asset discovery it offers the alternative in plain words: use automated discovery tools, or "Alternatively, consider manual update procedures" [3]. Choose against the trigger split, not against a feature grid.

Option Covers well Leaves open Best fit
GRC / compliance platform All 11 interval-only duties, evidence capture, multi-framework mapping, management reporting under 2.2.2 The 17 event limbs unless you configure the triggers yourself; the Article 2(2) justification register Entities running NIS2 alongside ISO 27001 or DORA, with a named owner for the platform
Existing ITSM or ticketing system Recurring tasks with owners and dates, change-linked triggers, an audit trail you already retain Evidence normalisation and control mapping — you build the structure yourself Entities with a working service desk and no budget for a second system of record
Identity governance tooling Workflows 2 and part of 5 — the two organisational-change triggers at 11.2.3 and 11.3.3, and 11.5.4 deactivation Everything outside access control The narrow, high-payoff first purchase ENISA effectively points at
Interval register plus calendar The legal minimum: a documented interval per duty, a date, an owner, a recorded result Scale, and evidence retrieval speed under supervision Smaller entities, and anyone who has not yet decided their intervals

The fourth row is not a joke option. Until the intervals exist on paper, a platform automates an undecided cadence. For the market side, see our breakdown of NIS2 compliance software; for the frequency question, what "continuous" actually means in the text.

What each role should do next

Role First action Why it lands on you
Compliance officer Write the interval register: one row per recurring duty, the interval chosen, and the reason. Mark which of the 17 dual-trigger duties also needs an event route. "At planned intervals" means your documented plan is the benchmark. Without the register there is nothing to be measured against — or to defend.
CISO / IT security manager Wire the two organisational-change triggers (11.2.3, 11.3.3) to the HR joiner-mover-leaver feed before buying anything else. It is the only automation ENISA calls for by name, and the one most likely to be failing quietly today.
SME owner or non-technical lead Pick intervals for the three annual duties (1.1.2, 2.1.4, 10.1.3), put them in the calendar, and keep the written result of each review. Those three are the only fixed cadences in the framework. Meeting them costs a morning; missing them is visible immediately.
Management body Diarise the annual policy review as a board item and require the compliance report described in point 2.2.1. Point 1.1.2 assigns the review to management bodies, and under Article 20(1) they can be held liable for infringements of Article 21.

Frequently asked questions

Does NIS2 require continuous compliance monitoring?
No. Point 3.2.2 of the Implementing Regulation says monitoring shall be automated "either continuously or in periodic intervals, subject to business capabilities" [1]. Continuous and periodic are offered as alternatives. The Directive itself contains no monitoring cadence for entities at all.

How often do I have to review my policies?
If the CIR Annex binds you, the security policy is reviewed by management bodies at least annually and whenever significant incidents or significant changes to operations or risks occur (point 1.1.2) [1]. If it does not bind you, no EU instrument sets a frequency — you set and document one, and national transposition may add its own deadlines [4].

Can automated evidence satisfy an auditor?
Automated collection is fine. But the Annex names "evidence" only twice, at points 3.5.4 and 6.10.2(b) [1], so most of what auditors look for is inferred from surrounding duties. See our guide to building a NIS2 evidence strategy and to logging and monitoring requirements.

Do I need a dedicated compliance platform?
Nothing in either instrument requires one. The duties are to review at defined intervals, act on defined events, and document the results. A platform makes that cheaper at scale; it does not change what has to be true.

Key takeaways

  • The Directive contains no review cadence at all. All 30 "at planned intervals" clauses and all three annual floors sit in CIR 2024/2690, which binds 11 categories of digital provider [1][2].
  • Of those 30 clauses, 11 are interval-only, two also fire on organisational change, and 17 also fire on a significant incident or a significant change to operations or risks. Only the first 11 automate end to end.
  • ENISA recommends automating a process exactly twice in 170 pages, and both instances are access-rights workflows [3].
  • Article 2(2) of the Implementing Regulation turns every declined "where appropriate" requirement into a written justification — a recurring artefact almost no tooling tracks [1].
  • Before buying anything, write the interval register: "at planned intervals" makes your own documented plan the standard you are held to.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 — EUR-Lex
  2. Directive (EU) 2022/2555 (NIS2) — EUR-Lex
  3. Technical Implementation Guidance on cybersecurity risk-management measures, version 1.0 (26 June 2025) — ENISA
  4. NIS-2-Pflichten — Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: